Table of Contents

How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026)

How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026) — RTI Wiki

Quick Reply: Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal…

E-E-A-T: Why trust this guide\\
This page is maintained by the RTI Wiki Citizen Crisis Response Network and reviewed against official sources:\\
  • CERT-In (cert-in.org.in) — national nodal agency for cyber incident response
  • Ministry of Electronics and Information Technology (MeitY) (meity.gov.in) — policy and coordination for digital threats
  • National Cyber Crime Reporting Portal (cybercrime.gov.in) — MHA / Indian Cyber Crime Coordination Centre (I4C)
  • Press Information Bureau Fact Check (factcheck.pib.gov.in) — government misinformation verification
  • Reserve Bank of India (sachet.rbi.org.in) — zero-liability and fraud reporting framework\\

Last reviewed: July 2026 · Sources verified: 12+ government and regulatory references · Legal accuracy checked against IT Act 2000, BNS, 2023, RBI Master Directions.

Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the operational reporting playbook: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one.

Citizen Crisis Response Network — install rule\\
Always download from the bank / agency's verified app-store link on its official website (e.g., sbi.co.in → “Download YONO” → Play Store link), never from a search result.

To report a fake mobile app in India: (1) inside Play Store, tap the app → Report, (2) report at cert-in.org.in → Incident Report, (3) email MeitY's Incident Response at [email protected], (4) report to the impersonated brand (bank / RBI / IRCTC / Income Tax helpdesk), (5) file at cybercrime.gov.in / 1930 if money has moved, and (6) post a public PIB Fact Check forward (WhatsApp +91-8799711259). Verified takedowns from Google + CERT-In typically complete within 24-72 hours.

If you have already installed a suspicious app, follow the fake app removal and bank protection guide immediately. If money has already been debited, see how to recover money lost to UPI fraud and call 1930 within the golden hour — see RBI golden hour zero-liability rule.

In this guide

How fake apps reach Play Store

Three routes:

  1. Lookalike upload — A new developer account uploads “SBI YONO Bank Online” / “ITR Tax Filing 2026” / “IRCTC Faster Booking” with cloned UI and a slightly different developer name. Google's automated review misses it for 24-72 hours.
  2. Repackaged genuine app — The developer downloads the real APK, repackages it with a trojan, and uploads under a similar name.
  3. Sideloaded only — Some attackers don't bother with Play Store; the link is shared on WhatsApp / SMS. See fake APK installation scam.

The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing.

Spot a fake app in 30 seconds

Check Real app Fake app
Developer name Exact bank / agency (e.g., “State Bank of India”) Slightly off (“State Bank India Pvt Ltd”, “SBI Limited”)
Install count Crores / lakhs Hundreds / few thousand
Reviews Old, mixed, organic Five-star burst, generic phrasing
Permissions Bank-specific minimum Accessibility, SMS, install other apps
Description language Polished Typos, broken grammar
Update history Years long One or two recent updates
Privacy policy URL Official bank domain Random `.in` / `.online`
Listed website Bank's official site Generic / dead link

If even one check fails, do not install. Verify by visiting the bank's website and clicking their “Download” link — that link goes to the genuine Play Store listing.

What Types of Fake Mobile Apps Are Most Common in India?

Fake app impersonation in India targets six primary categories. Knowing which category a suspect app falls into helps you report to the right authority faster:

In Q1 2026, the Ministry of Home Affairs' Indian Cyber Crime Coordination Centre (I4C) reported that fake app-related fraud accounted for over ₹2,900 crore in losses nationwide, with fake loan apps and fake investment apps being the top two vectors. Source: cybercrime.gov.in statistics dashboard.

How Does Fake App Malware Steal Your Money?

Understanding the attack chain helps you know what to check after installing a suspicious app. Most fake banking / government app trojans follow a five-step pattern:

This is why airplane mode + password change from another device within the first 30 minutes is critical. If SMS permission was already granted, assume every OTP sent in the last 48 hours was intercepted. For the full response, see UPI fraud recovery steps and how to freeze your bank account after fraud.

SIM swap risk — Some fake apps also attempt SIM swap fraud by harvesting your telecom KYC details. If your SIM suddenly loses signal, see SIM swap fraud recovery immediately.

Report to Google Play

  1. Open the suspect app's listing in Play Store (Android device or play.google.com on web)
  2. Tap ⋮ More optionsFlag as inappropriate
  3. Choose category: “Copycat or impersonation” or “Sexual content / harmful behaviour / malware” → as applicable
  4. Add a short description with reasons + screenshots
  5. For deeper reports: support.google.com → developer takedown (DMCA / impersonation)
  6. Trademark holders (i.e., the real bank) get faster takedown via Google's brand-protection form

Google generally responds within 24-48 hours for clear impersonation.

Report to CERT-In + MeitY

  1. CERT-In Incident Reporting: cert-in.org.in → “Incident Reporting Form”
  2. Email: [email protected] (PGP key on site)
  3. Phone: +91-1800-11-4949 (toll-free)
  4. Include: Play Store URL, developer name, date of detection, screenshots, hashes of APK if you can extract
  5. Cite CERT-In Cyber Security Directions, 2022 which obligates Indian platforms to retain logs for 180 days — available at cert-in.org.in and referenced at meity.gov.in
  6. MeitY Cyber Coordination Centre (I4C): cybercrime.gov.in → cyber-crime → impersonation
  7. For sustained / large-scale impersonation, a Section 69A (IT Act) blocking order can be requested by the brand — flag this to the affected bank / agency

CERT-In confirms incident receipt + ticket number; coordinates takedown with platform.

Which Government Authority Should You Report a Fake App To?

Multiple government bodies handle different aspects of fake app fraud. Filing with the right authority speeds up resolution. Use this comparison table to decide:

Reporting channel What they do When to use Response time URL
Google Play (Flag) Removes the listing from Play Store Always — first step for any fake app on Play Store 24-72 hours play.google.com
CERT-In Technical incident tracking, coordinates with platforms Always — for any malware / impersonation incident Ticket within 24h cert-in.org.in
National Cyber Crime Portal (I4C) Police-grade cyber crime complaint, fund freeze If money has been lost or credentials stolen Immediate (1930 hotline) cybercrime.gov.in
MeitY Policy intervention, platform accountability, Section 69A blocking For large-scale / sustained impersonation 7-15 days meity.gov.in
PIB Fact Check Public advisory / misinformation debunking If fake app is spreading via WhatsApp / social media 24-48 hours factcheck.pib.gov.in
RBI Sachet Suspicious entity reporting, bank-level escalation If a bank or NBFC is being impersonated Variable sachet.rbi.org.in
Impersonated brand Trademark takedown via legal team Always — forward the Play Store URL + screenshots 24-72 hours Brand's official email
Local police (FIR) Criminal investigation, evidence chain If money has moved or identity theft occurred Same day Nearest cyber crime police station
Tip — If you're unsure whether to file at the cyber crime portal or go to the police station directly, read cybercrime portal vs police station and how to file a cybercrime complaint in 2026.

Report to the impersonated brand

Most banks / agencies have dedicated “report-fraud” channels:

Forward the Play Store URL + screenshots. The brand's legal team can file the trademark-protection takedown directly with Google + CERT-In.

If you are a banking customer whose money was stolen via a fake app, escalate using the Banking Ombudsman complaint guide if the bank stalls on refund. See also what to do when a bank refuses a cyber fraud refund.

The 30-minute drill if you installed

If you have installed a suspect app and entered banking credentials:

  1. Airplane mode the device immediately
  2. From another device:
    • Change net-banking password
    • Block debit card
    • De-register UPI on every UPI app
    • Change email password + revoke sessions
  3. Uninstall the suspect app; revoke Accessibility / Notification access
  4. 1930 + cybercrime.gov.in if money has moved
  5. Bank email invoking RBI Master Direction 2017 within 24 hours
  6. CERT-In report ([email protected]) with details

For the full step-by-step after installing a fake app, read what to do if you installed a fake app. If your bank account has been frozen after fraud, see bank account freeze after cyber fraud.

Multiple Indian laws apply to fake mobile app fraud. Understanding your legal rights strengthens your complaint and compensation claim:

Reporting tip — When filing at cybercrime.gov.in, cite the specific sections above. This helps the investigating officer classify the complaint correctly and speeds up processing. See also complete cyber crime complaint guide and how to use RTI to check cybercrime complaint status.

How Can Senior Citizens and Vulnerable Users Stay Safe from Fake Apps?

Senior citizens are disproportionately targeted by fake app scammers because they may be less familiar with app-store verification. The following precautions are essential:

For families — Sit with elderly parents and delete any app they didn't install from a bank's official website link. Set up MeitY's Cyber Jagrookta Diwas resources and review the how to report a scam call/number guide together.

What Happens After You Report a Fake App?

Understanding the post-report timeline helps you track progress and escalate if needed:

Escalation paths — If Google ignores your report, escalate via CERT-In. If CERT-In is slow, escalate via MeitY (meity.gov.in). If your bank refuses to refund, escalate to Banking Ombudsman (RB-IOS 2021) or see what to do when a bank refuses a cyber fraud refund.

What not to do

Sample report email

To: [email protected]
Cc: [bank's anti-phishing email] + cybercrime.gov.in submission ref

Subject: Impersonation app on Google Play targeting [Bank / Agency]
customers — request for takedown coordination

Sir / Madam,

I report the following impersonation app currently live on Google Play
Store, targeting customers of [Brand / Bank Name]:

  Play Store URL : ___
  App name       : ___
  Developer name : ___
  Install count  : ___
  Detection date : ___
  Permissions of concern : Accessibility, SMS read, ...

Attached:
  1. Screenshots of the listing
  2. Permissions screenshot
  3. APK hash (if extractable): ___
  4. Comparison with the genuine app

Cited authority:
  - CERT-In Cyber Security Directions, 2022
  - IT Act 2000 §66C, §66D, §69A (blocking)
  - BNS, 2023 §316 (personation), §319 (cheating)
  - Trade Marks Act 1999 (where the brand is registered)

I request CERT-In to:
  a) Coordinate takedown with Google Play and the affected brand.
  b) Issue a public advisory if multiple impersonation listings exist.
  c) Confirm the takedown date in writing.

Yours faithfully,
[Signature, Name, Date, Phone, Email]

Can compensation be claimed?

What to do in the next 30 minutes (printable card)

  1. 0-5 min — If installed: airplane mode + change passwords from another device
  2. 5-15 min — Report on Play Store (⋮ → Flag); report to bank's anti-phishing email
  3. 15-25 min — File at CERT-In + cybercrime.gov.in
  4. 25-30 min — Forward to PIB Fact Check + amplify on social media (with screenshots, no PII)
  5. +24 h — Bank's “report unauthorised transaction” form
  6. +72 h — Confirm takedown via Play Store / CERT-In ticket

Reporting channels comparison table

Feature Google Play Flag CERT-In cybercrime.gov.in / 1930 MeitY PIB Fact Check
Purpose Remove listing Technical incident tracking Criminal complaint + fund freeze Policy / blocking order Public misinformation debunk
Who can file Anyone Anyone Victim or proxy Brand / government Anyone
Requires account? Google account No Phone + OTP Email WhatsApp / web form
Best for Quick takedown Evidence trail Money recovery Large-scale impersonation Warning the public
Gov.in URL cert-in.org.in cybercrime.gov.in meity.gov.in factcheck.pib.gov.in
Typical response 24-72 h Ticket in 24 h Immediate (1930) 7-15 days 24-48 h

Long-tail keywords this page targets

report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app, fake BHIM app report, how to report fake app on Play Store India, fake government app India, cybercrime.gov.in fake app complaint, Section 69A app blocking India, RBI zero liability fake app fraud

Government & authority references

FAQ

How do I find the genuine app's developer name?

Visit the bank / agency's website; their “Download our app” page links to the genuine Play Store listing. The developer name there is authoritative. For example:

Should I rate the fake app 1-star to warn others?

No — engagement signals (any rating) help the listing rank. Just report and silently move on.

Can I report multiple fake apps in one email to CERT-In?

Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings.

What about fake apps in third-party stores (APKPure / Aptoide)?

Report directly to the store's abuse channel; also email CERT-In at [email protected]. These stores' takedowns are slower but possible. Always prefer the official Play Store / App Store.

Do I need to file a police FIR?

Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. You can file online at cybercrime.gov.in or at your nearest cyber crime police station. See complete cyber crime complaint guide and how to file a cybercrime complaint in 2026.

What if the bank refuses to refund after a fake app fraud?

Escalate in this order: (1) bank's internal grievance redressal, (2) Banking Ombudsman under RB-IOS 2021 — see Banking Ombudsman guide, (3) what to do when bank refuses cyber fraud refund. Cite RBI Master Direction 2017 zero-liability provision if you reported within 3 working days.

Are fake loan apps also covered here?

Yes — fake loan apps are a major category. They harvest contacts, access gallery, and blackmail borrowers. Report them the same way (Play Store flag + CERT-In + cybercrime.gov.in). See fake loan approval scam for specific guidance.

Can fake apps steal my data even without banking access?

Yes. Fake apps can harvest contacts, SMS history, call logs, location, photos, and clipboard data. This data is sold on the dark web or used for targeted phishing. Uninstall immediately and change passwords for all accounts that shared the same credentials. See fake app removal guide.

What is Google Play Protect and does it help?

Google Play Protect is Google's built-in malware scanner that scans all installed apps daily. It catches known malware signatures but may miss brand-new lookalike apps for 24-72 hours. Enable it at Settings → Google → Security → Play Protect. It is a safety net, not a replacement for manual developer-name verification.

How do I report a fake app that is spreading via WhatsApp?

Forward the message (without clicking any links) to PIB Fact Check at WhatsApp +91-8799711259 or submit at factcheck.pib.gov.in. Also report the WhatsApp number to cybercrime.gov.in. See also WhatsApp OTP fraud explained and how to report scam calls/numbers.

Can I check if my SIM is being misused after a fake app installation?

Yes — visit tafcop.sancharsaathi.gov.in to check all mobile connections issued in your name. See how to check SIM misuse via Tafcop and 9 SIM card limit under Telecom Act.

Myth vs reality

Myth Reality
“Play Store apps are safe.” Lookalike apps occasionally pass review; the safe path is the bank's website link.
“Five-star ratings = real.” Burst five-star ratings are a fake-app signal, not authenticity.
“Only banking apps are cloned.” IRCTC, Income Tax, EPFO, UIDAI, RBI, scholarship portals are all impersonated.
“Reporting won't matter; Google ignores it.” Google's brand-protection takedown is among the fastest in tech — typically 24-48 h.
“If I don't install, I'm safe.” True for you; but the listing is harvesting other victims — report it.
“Google Play Protect catches all fake apps.” Play Protect catches known malware; brand-new lookalike apps may slip through for 24-72 hours.
“Only tech-illiterate people fall for fake apps.” Even savvy users have been fooled by near-perfect clones; the verification habit matters more than tech skill.
“If I uninstall the fake app, the danger is over.” Not necessarily — credentials may already be exfiltrated. Change all passwords from another device and monitor bank statements for 30 days.