Quick Reply: Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal…
Last reviewed: July 2026 · Sources verified: 12+ government and regulatory references · Legal accuracy checked against IT Act 2000, BNS, 2023, RBI Master Directions.
Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the operational reporting playbook: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one.
Citizen Crisis Response Network — install rule\\
Always download from the bank / agency's verified app-store link on its official website (e.g., sbi.co.in → “Download YONO” → Play Store link), never from a search result.
To report a fake mobile app in India: (1) inside Play Store, tap the app → ⋮ → Report, (2) report at cert-in.org.in → Incident Report, (3) email MeitY's Incident Response at [email protected], (4) report to the impersonated brand (bank / RBI / IRCTC / Income Tax helpdesk), (5) file at cybercrime.gov.in / 1930 if money has moved, and (6) post a public PIB Fact Check forward (WhatsApp +91-8799711259). Verified takedowns from Google + CERT-In typically complete within 24-72 hours.
If you have already installed a suspicious app, follow the fake app removal and bank protection guide immediately. If money has already been debited, see how to recover money lost to UPI fraud and call 1930 within the golden hour — see RBI golden hour zero-liability rule.
Three routes:
The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing.
| Check | Real app | Fake app |
| Developer name | Exact bank / agency (e.g., “State Bank of India”) | Slightly off (“State Bank India Pvt Ltd”, “SBI Limited”) |
| Install count | Crores / lakhs | Hundreds / few thousand |
| Reviews | Old, mixed, organic | Five-star burst, generic phrasing |
| Permissions | Bank-specific minimum | Accessibility, SMS, install other apps |
| Description language | Polished | Typos, broken grammar |
| Update history | Years long | One or two recent updates |
| Privacy policy URL | Official bank domain | Random `.in` / `.online` |
| Listed website | Bank's official site | Generic / dead link |
If even one check fails, do not install. Verify by visiting the bank's website and clicking their “Download” link — that link goes to the genuine Play Store listing.
Fake app impersonation in India targets six primary categories. Knowing which category a suspect app falls into helps you report to the right authority faster:
In Q1 2026, the Ministry of Home Affairs' Indian Cyber Crime Coordination Centre (I4C) reported that fake app-related fraud accounted for over ₹2,900 crore in losses nationwide, with fake loan apps and fake investment apps being the top two vectors. Source: cybercrime.gov.in statistics dashboard.
Understanding the attack chain helps you know what to check after installing a suspicious app. Most fake banking / government app trojans follow a five-step pattern:
This is why airplane mode + password change from another device within the first 30 minutes is critical. If SMS permission was already granted, assume every OTP sent in the last 48 hours was intercepted. For the full response, see UPI fraud recovery steps and how to freeze your bank account after fraud.
SIM swap risk — Some fake apps also attempt SIM swap fraud by harvesting your telecom KYC details. If your SIM suddenly loses signal, see SIM swap fraud recovery immediately.
Google generally responds within 24-48 hours for clear impersonation.
CERT-In confirms incident receipt + ticket number; coordinates takedown with platform.
Multiple government bodies handle different aspects of fake app fraud. Filing with the right authority speeds up resolution. Use this comparison table to decide:
| Reporting channel | What they do | When to use | Response time | URL |
| Google Play (Flag) | Removes the listing from Play Store | Always — first step for any fake app on Play Store | 24-72 hours | play.google.com |
| CERT-In | Technical incident tracking, coordinates with platforms | Always — for any malware / impersonation incident | Ticket within 24h | cert-in.org.in |
| National Cyber Crime Portal (I4C) | Police-grade cyber crime complaint, fund freeze | If money has been lost or credentials stolen | Immediate (1930 hotline) | cybercrime.gov.in |
| MeitY | Policy intervention, platform accountability, Section 69A blocking | For large-scale / sustained impersonation | 7-15 days | meity.gov.in |
| PIB Fact Check | Public advisory / misinformation debunking | If fake app is spreading via WhatsApp / social media | 24-48 hours | factcheck.pib.gov.in |
| RBI Sachet | Suspicious entity reporting, bank-level escalation | If a bank or NBFC is being impersonated | Variable | sachet.rbi.org.in |
| Impersonated brand | Trademark takedown via legal team | Always — forward the Play Store URL + screenshots | 24-72 hours | Brand's official email |
| Local police (FIR) | Criminal investigation, evidence chain | If money has moved or identity theft occurred | Same day | Nearest cyber crime police station |
Tip — If you're unsure whether to file at the cyber crime portal or go to the police station directly, read cybercrime portal vs police station and how to file a cybercrime complaint in 2026.
Most banks / agencies have dedicated “report-fraud” channels:
Forward the Play Store URL + screenshots. The brand's legal team can file the trademark-protection takedown directly with Google + CERT-In.
If you are a banking customer whose money was stolen via a fake app, escalate using the Banking Ombudsman complaint guide if the bank stalls on refund. See also what to do when a bank refuses a cyber fraud refund.
If you have installed a suspect app and entered banking credentials:
For the full step-by-step after installing a fake app, read what to do if you installed a fake app. If your bank account has been frozen after fraud, see bank account freeze after cyber fraud.
Multiple Indian laws apply to fake mobile app fraud. Understanding your legal rights strengthens your complaint and compensation claim:
Reporting tip — When filing at cybercrime.gov.in, cite the specific sections above. This helps the investigating officer classify the complaint correctly and speeds up processing. See also complete cyber crime complaint guide and how to use RTI to check cybercrime complaint status.
Senior citizens are disproportionately targeted by fake app scammers because they may be less familiar with app-store verification. The following precautions are essential:
For families — Sit with elderly parents and delete any app they didn't install from a bank's official website link. Set up MeitY's Cyber Jagrookta Diwas resources and review the how to report a scam call/number guide together.
Understanding the post-report timeline helps you track progress and escalate if needed:
Escalation paths — If Google ignores your report, escalate via CERT-In. If CERT-In is slow, escalate via MeitY (meity.gov.in). If your bank refuses to refund, escalate to Banking Ombudsman (RB-IOS 2021) or see what to do when a bank refuses a cyber fraud refund.
To: [email protected] Cc: [bank's anti-phishing email] + cybercrime.gov.in submission ref Subject: Impersonation app on Google Play targeting [Bank / Agency] customers — request for takedown coordination Sir / Madam, I report the following impersonation app currently live on Google Play Store, targeting customers of [Brand / Bank Name]: Play Store URL : ___ App name : ___ Developer name : ___ Install count : ___ Detection date : ___ Permissions of concern : Accessibility, SMS read, ... Attached: 1. Screenshots of the listing 2. Permissions screenshot 3. APK hash (if extractable): ___ 4. Comparison with the genuine app Cited authority: - CERT-In Cyber Security Directions, 2022 - IT Act 2000 §66C, §66D, §69A (blocking) - BNS, 2023 §316 (personation), §319 (cheating) - Trade Marks Act 1999 (where the brand is registered) I request CERT-In to: a) Coordinate takedown with Google Play and the affected brand. b) Issue a public advisory if multiple impersonation listings exist. c) Confirm the takedown date in writing. Yours faithfully, [Signature, Name, Date, Phone, Email]
| Feature | Google Play Flag | CERT-In | cybercrime.gov.in / 1930 | MeitY | PIB Fact Check |
| Purpose | Remove listing | Technical incident tracking | Criminal complaint + fund freeze | Policy / blocking order | Public misinformation debunk |
| Who can file | Anyone | Anyone | Victim or proxy | Brand / government | Anyone |
| Requires account? | Google account | No | Phone + OTP | WhatsApp / web form | |
| Best for | Quick takedown | Evidence trail | Money recovery | Large-scale impersonation | Warning the public |
| Gov.in URL | — | cert-in.org.in | cybercrime.gov.in | meity.gov.in | factcheck.pib.gov.in |
| Typical response | 24-72 h | Ticket in 24 h | Immediate (1930) | 7-15 days | 24-48 h |
report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app, fake BHIM app report, how to report fake app on Play Store India, fake government app India, cybercrime.gov.in fake app complaint, Section 69A app blocking India, RBI zero liability fake app fraud
Visit the bank / agency's website; their “Download our app” page links to the genuine Play Store listing. The developer name there is authoritative. For example:
No — engagement signals (any rating) help the listing rank. Just report and silently move on.
Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings.
Report directly to the store's abuse channel; also email CERT-In at [email protected]. These stores' takedowns are slower but possible. Always prefer the official Play Store / App Store.
Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. You can file online at cybercrime.gov.in or at your nearest cyber crime police station. See complete cyber crime complaint guide and how to file a cybercrime complaint in 2026.
Escalate in this order: (1) bank's internal grievance redressal, (2) Banking Ombudsman under RB-IOS 2021 — see Banking Ombudsman guide, (3) what to do when bank refuses cyber fraud refund. Cite RBI Master Direction 2017 zero-liability provision if you reported within 3 working days.
Yes — fake loan apps are a major category. They harvest contacts, access gallery, and blackmail borrowers. Report them the same way (Play Store flag + CERT-In + cybercrime.gov.in). See fake loan approval scam for specific guidance.
Yes. Fake apps can harvest contacts, SMS history, call logs, location, photos, and clipboard data. This data is sold on the dark web or used for targeted phishing. Uninstall immediately and change passwords for all accounts that shared the same credentials. See fake app removal guide.
Google Play Protect is Google's built-in malware scanner that scans all installed apps daily. It catches known malware signatures but may miss brand-new lookalike apps for 24-72 hours. Enable it at Settings → Google → Security → Play Protect. It is a safety net, not a replacement for manual developer-name verification.
Forward the message (without clicking any links) to PIB Fact Check at WhatsApp +91-8799711259 or submit at factcheck.pib.gov.in. Also report the WhatsApp number to cybercrime.gov.in. See also WhatsApp OTP fraud explained and how to report scam calls/numbers.
Yes — visit tafcop.sancharsaathi.gov.in to check all mobile connections issued in your name. See how to check SIM misuse via Tafcop and 9 SIM card limit under Telecom Act.
| Myth | Reality |
|---|---|
| “Play Store apps are safe.” | Lookalike apps occasionally pass review; the safe path is the bank's website link. |
| “Five-star ratings = real.” | Burst five-star ratings are a fake-app signal, not authenticity. |
| “Only banking apps are cloned.” | IRCTC, Income Tax, EPFO, UIDAI, RBI, scholarship portals are all impersonated. |
| “Reporting won't matter; Google ignores it.” | Google's brand-protection takedown is among the fastest in tech — typically 24-48 h. |
| “If I don't install, I'm safe.” | True for you; but the listing is harvesting other victims — report it. |
| “Google Play Protect catches all fake apps.” | Play Protect catches known malware; brand-new lookalike apps may slip through for 24-72 hours. |
| “Only tech-illiterate people fall for fake apps.” | Even savvy users have been fooled by near-perfect clones; the verification habit matters more than tech skill. |
| “If I uninstall the fake app, the danger is over.” | Not necessarily — credentials may already be exfiltrated. Change all passwords from another device and monitor bank statements for 30 days. |