A 70-year-old college trustee in Khar, Mumbai, who’s been at the receiving end of a sophisticated cyber fraud scheme has been badly affected with a total loss of ₹6.7 lakh, when he was contacted by the elderly gentleman who claimed to be a bank’s credit card department representative in person.

The man was introduced as a representative of a bank’s credit card department to the victim and offered him a premium credit card which was too good to be rejected, the police said.
The fraud was active when KM Raju received a call from the unknown person on WhatsApp. The fraudulent contact was from a tele-caller working in the bank's credit card division and he explained the benefits of the so-called super-premium credit card. This was only available by invitation and was ₹12,500 with a charge of joining and taxes. Raju was genuinely interested in everything he was told as described by the complaint against him filed with the police.
After establishing what appeared to be a credible rapport, the fraudster instructed Raju to download an APK file, which he said was required to complete the credit card application process. This file was sent directly to Raju's WhatsApp account with the name of the bank so that the request would be recognized as valid.
But believing the caller’s assertions and assuming that the APK file was an authentic part of the application, Raju downloaded and installed it on his phone and thus the fraudsters were able to take advantage of his personal information.
Later on, investigators found out that this was key to the scam. Android Application Package or APK is a format for distributing and installing apps to Android devices. While many legitimate apps are distributed in this way, downloading and installing an unknown APK file from an unverified source poses significant security risks. Raju’s action of installing the file finally compromised his phone, that was the way in which the criminals were able to gain access to his phone and start a series of fraudulent transactions from his family’s bank accounts.
Just a few hours after installing the file, police reports indicated that several unauthorized financial transactions had occurred. All in all, eight fraudulent transactions were done in a short span of around one hour targeting accounts of Raju's wife, sister, and daughter, and joint family accounts.
The number of linked accounts increased the total losses from the fraudulent activities to around ₹6.7 lakh.
Raju was worried when his phone suddenly shut down during all the unauthorized transactions. That sudden shutdown and the alarming financial activity he had not authorized made him realize that something was wrong. Raju was worried and anxious and immediately called the cybercrime support line at 1930.
The police immediately notified the nodal officers of the banks involved and tried to close the accounts where the stolen money had been transferred. In cases of cyber fraud, it is important to report the incident on time as authorities will hold onto money that has not yet been integrated into the system.
Following Raju’s complaint, the Khar police officially registered a case and conducted a thorough investigation. They searched the victim’s mobile phone, traced the location of the fake call, and looked at the WhatsApp account used by the caller and bank accounts of the transactions. The police are also closely following the money trail to find out where the money was taken and who actually received or transferred them.
As the investigation proceeds, authorities want to know if the culprits did so independently or as part of a larger cybercrime network. Fraudsters often employ multi-layered schemes with different individuals who function in different areas, such as calling or sending malware to another person, controlling bank accounts, or transferring funds when the fraud is done. Tracking the financial trail will allow investigators to find out who is behind this cyber fraud.
The APK scam is still spreading and it is a very real threat. Cybercrooks often impersonate bank employees, credit card representatives, government officials, or customer service representatives to convince people to install harmful applications. They may depict the installation of the application as part of a Know Your Customer (KYC) process, account verification, credit card application, reward claim, and/or service activation process.
In Raju’s case, the alluring offer of a premium credit card probably instilled trust in him and thus made him more susceptible to the fraudster’s manipulation. The promise of an exclusive financial product and detailed explanation of fees and card benefits also lent credibility to the call in the eyes of the victim.
People should always resist the temptation to download APK files from unverified sources and should not install apps from unverified sites or apps that are sent through unofficial channels, cybersecurity experts and law enforcement officials often tell us. Individuals must be very careful when someone asks them to download APK files through WhatsApp, SMS, or email.
They should use the official banking service (e.g., official, verified websites or a service provider) to get the app to work and not be easily involved in scams.
In addition, this is a case where mobile device security is closely linked to financial security. Mobile phones are often linked to banking services, payment applications, email accounts, and various authentication services. If a malicious app gets into a mobile device, the damage to the device will be huge in the long run.
For seniors and those who are not familiar with technology, it is very important to check any unexpected calls that come in for financial products independently before any action is taken. Instead of following the advice of the unsolicited phone call, customers should contact their bank directly, either via phone or in person, to verify the legitimacy of any offer.
As the police continue to investigate the alleged ₹6.7 lakh fraud, they are investigating the caller and the other accounts that benefited from the fraudulent transactions. Similar scams have also been reported in the past involving other victims, and continued investigations will provide a picture of the true extent of the criminal activity.
The above incident is yet another cautionary tale when you look at social engineering and fake applications together. A premium credit card offer that was accompanied by high rates of fraud led to unauthorized transactions and a significant financial loss for the victim. Law enforcement is investigating the money trail, identifying the culprits, and tracing the fraudsters' access to Raju's mobile device. Have someone notice suspicious transactions and report it immediately to their bank, and then report cyber fraud through the 1930 phone number.
That’s where the fraud is detected so a person who is suspicious must also report it to their bank and be sure to report it through the 1930 helpline. It is also critical for victims to save any relevant messages, phone numbers, transaction records and other evidence. A quick report can be very useful for investigators to get them to locate and identify all these funds and to have them frozen before they can be transferred to other accounts so more victims can avoid the same financial loss.
Comments
Please to leave a comment on this article.