Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the operational reporting playbook: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one.
Citizen Crisis Response Network — install rule
Always download from the bank / agency's verified app-store link on its official website (e.g., sbi.co.in → “Download YONO” → Play Store link), never from a search result.
To report a fake mobile app in India: (1) inside Play Store, tap the app → ⋮ → Report, (2) report at cert-in.org.in → Incident Report, (3) email MeitY's Incident Response at incident@cert-in.org.in, (4) report to the impersonated brand (bank / RBI / IRCTC / Income Tax helpdesk), (5) file at cybercrime.gov.in / 1930 if money has moved, and (6) post a public PIB Fact Check forward (WhatsApp +91-8799711259). Verified takedowns from Google + CERT-In typically complete within 24-72 hours.
Three routes:
The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing.
| Check | Real app | Fake app |
| Developer name | Exact bank / agency (e.g., “State Bank of India”) | Slightly off (“State Bank India Pvt Ltd”, “SBI Limited”) |
| Install count | Crores / lakhs | Hundreds / few thousand |
| Reviews | Old, mixed, organic | Five-star burst, generic phrasing |
| Permissions | Bank-specific minimum | Accessibility, SMS, install other apps |
| Description language | Polished | Typos, broken grammar |
| Update history | Years long | One or two recent updates |
| Privacy policy URL | Official bank domain | Random ``.in`` / ``.online`` |
| Listed website | Bank's official site | Generic / dead link |
If even one check fails, do not install. Verify by visiting the bank's website and clicking their “Download” link — that link goes to the genuine Play Store listing.
Google generally responds within 24-48 hours for clear impersonation.
CERT-In confirms incident receipt + ticket number; coordinates takedown with platform.
Most banks / agencies have dedicated “report-fraud” channels:
Forward the Play Store URL + screenshots. The brand's legal team can file the trademark-protection takedown directly with Google + CERT-In.
If you have installed a suspect app and entered banking credentials:
To: incident@cert-in.org.in Cc: [bank's anti-phishing email] + cybercrime.gov.in submission ref Subject: Impersonation app on Google Play targeting [Bank / Agency] customers — request for takedown coordination Sir / Madam, I report the following impersonation app currently live on Google Play Store, targeting customers of [Brand / Bank Name]: Play Store URL : ___ App name : ___ Developer name : ___ Install count : ___ Detection date : ___ Permissions of concern : Accessibility, SMS read, ... Attached: 1. Screenshots of the listing 2. Permissions screenshot 3. APK hash (if extractable): ___ 4. Comparison with the genuine app Cited authority: - CERT-In Cyber Security Directions, 2022 - IT Act 2000 §66C, §66D, §69A (blocking) - BNS 2024 §316 (personation), §319 (cheating) - Trade Marks Act 1999 (where the brand is registered) I request CERT-In to: a) Coordinate takedown with Google Play and the affected brand. b) Issue a public advisory if multiple impersonation listings exist. c) Confirm the takedown date in writing. Yours faithfully, [Signature, Name, Date, Phone, Email]
report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app
“How to report a fake app on Play Store?” · “CERT-In incident report India.” · “Fake SBI app on Play Store.” · “MeitY app takedown India.” · “Play Store impersonation report.”
[Decision tree] "Is this app fake?"
Developer name matches bank / agency exactly? → likely real
Install count > 10 lakh + years of updates? → likely real
Anything else? → suspect → don't install → report
[Reporting ladder]
Play Store flag → bank's anti-phishing email → CERT-In incident
→ MeitY / I4C → 1930 (if money moved)
[Comparison table] "Real app vs fake app"
Developer : exact official name | slight variation
Permissions : minimum bank-specific | accessibility / SMS
Reviews : organic, mixed | five-star burst
Update history : years long | one to two recent
++++ How do I find the genuine app's developer name? | Visit the bank / agency's website; their “Download our app” page links to the genuine Play Store listing. The developer name there is authoritative. ++++
++++ Should I rate the fake app 1-star to warn others? | No — engagement signals (any rating) help the listing rank. Just report and silently move on. ++++
++++ Can I report multiple fake apps in one email to CERT-In? | Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings. ++++
++++ What about fake apps in third-party stores (APKPure / Aptoide)? | Report directly to the store's abuse channel; also email CERT-In. These stores' takedowns are slower but possible. ++++
++++ Do I need to file a police FIR? | Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. ++++
| Myth | Reality |
|---|---|
| “Play Store apps are safe.” | Lookalike apps occasionally pass review; the safe path is the bank's website link. |
| “Five-star ratings = real.” | Burst five-star ratings are a fake-app signal, not authenticity. |
| “Only banking apps are cloned.” | IRCTC, Income Tax, EPFO, UIDAI, RBI, scholarship portals are all impersonated. |
| “Reporting won't matter; Google ignores it.” | Google's brand-protection takedown is among the fastest in tech — typically 24-48 h. |
| “If I don't install, I'm safe.” | True for you; but the listing is harvesting other victims — report it. |
Fake mobile apps are the cheapest, fastest impersonation channel in India. The defence is two-step: install only from your bank or agency's website link, and report any lookalike you spot to Play Store + CERT-In + the brand. Each report shortens the listing's life by hundreds of hours of victim exposure. Five minutes of reporting is the most public-spirited thing you can do this week.
This page is part of RTI Wiki's Citizen Crisis Response Network. Updates tracked through CERT-In bulletins, MeitY advisories, and Google Play transparency reports.