A late night spent watching Instagram Reels turned costly for a 27-year-old Hyderabad resident, who woke up the next morning to find ₹99,018 missing from his bank account across four unauthorised transactions he never approved. The victim insists he shared no OTP, password or banking credential with anyone, leaving investigators at Banjara Hills Police to focus their inquiry on a single unusual detail, a software update that installed itself on his phone the night before the money disappeared.
An Update the Victim Never Actually Requested
According to his complaint, the incident began on the night of August 2 while he was scrolling through Instagram Reels near his home in Banjara Hills. During that session, a software update installed itself automatically on his device. Assuming it was a routine system update, he continued using his phone without a second thought.
It was only the following morning, when he checked his bank balance, that he discovered the four unauthorised transactions totalling ₹99,018. He immediately contacted his bank before approaching Banjara Hills Police, who have since registered a cyber fraud case and opened a formal investigation into how the breach occurred.
A Familiar Disguise for an Increasingly Common Attack
What makes this case notable is not the amount lost but the vector investigators suspect was used. Fake software update prompts, often mimicking a legitimate Chrome or system update notification, have become one of the more effective disguises cybercriminals use to get malicious code onto a victim’s phone, precisely because the request feels routine rather than alarming. Once installed, such malware can quietly harvest banking credentials, intercept OTPs and even take near-total control of a device through abused accessibility permissions, all while the phone continues to function normally enough that the victim has no reason to suspect anything is wrong.
This pattern has grown considerably more sophisticated in India over the past year. Cybersecurity researchers have flagged campaigns such as “Android God Mode,” malware distributed through fake APK files that exploits accessibility services to seize near-complete control of infected devices, enabling silent banking fraud that victims typically discover only after money has already left their account. Kaspersky’s own research found Android threat detections grew by nearly half in 2025, with banking trojans specifically showing an even steeper rise, underscoring how quickly this category of attack has scaled.
Police in Hyderabad have not yet confirmed whether the update in this case was genuinely malicious, a compromised legitimate update, or something else entirely, and have said the exact cause will only be established once the technical investigation concludes.
A Forensic Trail Still Being Pieced Together
The victim’s phone is now set to undergo detailed forensic examination, with digital experts expected to analyse the software update itself alongside any suspicious applications, background processes or other digital artefacts that might explain how unauthorised access to his bank account was obtained. Investigators are simultaneously examining banking transaction records, IP logs and device activity logs to trace where the stolen funds ultimately went.
At this stage, police have been careful not to prematurely characterise the incident as malware, a fake update or another form of cyberattack, noting that only the completed technical investigation will clarify the actual mechanism behind the fraud. That caution reflects a broader reality in cases like this, that pinpointing exactly how a device was compromised, whether through a malicious payload embedded in what looked like a routine update, a background app already present on the phone, or some other vector, can take considerably longer than establishing that a compromise occurred at all.
Cybercrime expert and former IPS officer Prof. Triveni Singh said cybercriminals are increasingly relying on fake software updates, malware and malicious applications to compromise mobile devices and gain access to financial information, a shift that reduces their dependence on tricking victims into directly revealing passwords or OTPs. He advised users to install updates only through authorised sources such as official app stores, avoid clicking on suspicious links or downloading unverified applications, and report any unauthorised banking activity immediately, stressing that prompt reporting significantly improves the odds of freezing fraudulent transactions before the funds move beyond reach. Police have echoed that advice, urging citizens to stay alert to unusual update prompts and unfamiliar applications, and to report suspected fraud without delay through the National Cyber Crime Helpline at 1930 or the Cyber Crime Reporting Portal.
