Mumbai. Three men have been arrested in Gujarat for allegedly defrauding two Kandivali residents of ₹6.25 lakh by posing as Mahanagar Gas officials and sending them a fake APK file under the pretext of updating their gas-meter readings.
Police allege that the accused gained access to the victims’ mobile phones and subsequently transferred money from their bank accounts. Investigators suspect that the fraud proceeds were used to repay a gold loan and recover jewellery that had been pledged as security.
The arrested accused have been identified as Urvishkumar Rajeshbhai Patel, Janikumar Pradipbhai Patel and Ankitkumar Sanjaybhai Patel. Kandivali police traced the financial transactions linked to the alleged fraud to Olpad village in Surat district, Gujarat, where the trio was arrested. They were subsequently brought to Mumbai for further investigation.
In the first case, complainant Bakul Kantilal Desai was allegedly contacted by unidentified persons who told him that his gas-meter reading needed to be uploaded. The accused allegedly sent him an APK file claiming it was associated with Mahanagar Gas and instructed him to download it on his mobile phone. After Desai downloaded the file, the accused allegedly gained access to his device.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
According to police, the accused subsequently transferred ₹2.70 lakh from Desai’s bank account. He approached Kandivali police after discovering the unauthorised transaction. An FIR was registered under Sections 316(2), 318(4) and 3(5) of the Bharatiya Nyaya Sanhita (BNS), along with Sections 66(C) and 66(D) of the Information Technology Act.
A similar method was allegedly used against another victim, Shailesh Jaikishan Parmar. On May 7, 2025, Parmar was allegedly contacted and told that he needed to pay ₹12 for his Mahanagar Gas meter reading. He was then instructed to download an APK file purportedly sent by the gas company.
Police said the file allegedly enabled the accused to gain access to Parmar’s mobile phone. Following this, ₹4.17 lakh was allegedly transferred from his savings account. A separate case was registered at Kandivali police station under the relevant provisions of the BNS and Information Technology Act.
As investigators followed the financial trail in both cases, they allegedly found that the accused had taken a gold loan from Bajaj Finserv. Police suspect that money taken from the victims’ accounts was used to repay the loan, after which the accused recovered gold jewellery that had been pledged against it.
Investigators are now examining the financial transactions to determine how much of the alleged fraud proceeds was used to repay the gold loan and whether the remaining money was transferred to other accounts or channels.
The financial trail eventually led the police team to Olpad village in Surat district. A Kandivali police team reached the location on Friday and apprehended the three accused. The suspects were arrested in connection with both cases and brought to Mumbai on the same day.
The case highlights a growing cyber fraud tactic in which criminals impersonate officials of trusted utility companies and use routine services such as meter readings, bill payments or connection updates as a pretext to persuade victims to install malicious APK files. Once installed, such files can potentially give attackers unauthorised access to devices and sensitive information.
Cybercrime expert and former IPS officer Prof. Triveni Singh said fraudsters often create urgency around utility services to persuade victims to install unauthorised applications. People should verify the source of any APK file before installing it and should use only official customer-care channels provided by the service provider. Files or links received from unknown numbers can expose both personal information and banking credentials to serious risks.
Kandivali police are now investigating whether the arrested trio was involved in similar cyber frauds against other victims. Investigators are examining their previous financial transactions, mobile records and digital activities to determine the extent of the alleged network.