Keep RTI Wiki Free for Every Citizen 🇮🇳

Hosting, servers, and content cost ₹50,000+ per month. Your support keeps this resource alive.

Donate Now
📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026)

How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026) — RTI Wiki

Quick Reply: Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal…

E-E-A-T: Why trust this guide\\
This page is maintained by the RTI Wiki Citizen Crisis Response Network and reviewed against official sources:\\
  • CERT-In (cert-in.org.in) — national nodal agency for cyber incident response
  • Ministry of Electronics and Information Technology (MeitY) (meity.gov.in) — policy and coordination for digital threats
  • National Cyber Crime Reporting Portal (cybercrime.gov.in) — MHA / Indian Cyber Crime Coordination Centre (I4C)
  • Press Information Bureau Fact Check (factcheck.pib.gov.in) — government misinformation verification
  • Reserve Bank of India (sachet.rbi.org.in) — zero-liability and fraud reporting framework\\

Last reviewed: July 2026 · Sources verified: 12+ government and regulatory references · Legal accuracy checked against IT Act 2000, BNS, 2023, RBI Master Directions.

Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the operational reporting playbook: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one.

Citizen Crisis Response Network — install rule\\
Always download from the bank / agency's verified app-store link on its official website (e.g., sbi.co.in → “Download YONO” → Play Store link), never from a search result.

To report a fake mobile app in India: (1) inside Play Store, tap the app → Report, (2) report at cert-in.org.in → Incident Report, (3) email MeitY's Incident Response at [email protected], (4) report to the impersonated brand (bank / RBI / IRCTC / Income Tax helpdesk), (5) file at cybercrime.gov.in / 1930 if money has moved, and (6) post a public PIB Fact Check forward (WhatsApp +91-8799711259). Verified takedowns from Google + CERT-In typically complete within 24-72 hours.

If you have already installed a suspicious app, follow the fake app removal and bank protection guide immediately. If money has already been debited, see how to recover money lost to UPI fraud and call 1930 within the golden hour — see RBI golden hour zero-liability rule.

In this guide

How fake apps reach Play Store

Three routes:

  1. Lookalike upload — A new developer account uploads “SBI YONO Bank Online” / “ITR Tax Filing 2026” / “IRCTC Faster Booking” with cloned UI and a slightly different developer name. Google's automated review misses it for 24-72 hours.
  2. Repackaged genuine app — The developer downloads the real APK, repackages it with a trojan, and uploads under a similar name.
  3. Sideloaded only — Some attackers don't bother with Play Store; the link is shared on WhatsApp / SMS. See fake APK installation scam.

The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing.

Spot a fake app in 30 seconds

Check Real app Fake app
Developer name Exact bank / agency (e.g., “State Bank of India”) Slightly off (“State Bank India Pvt Ltd”, “SBI Limited”)
Install count Crores / lakhs Hundreds / few thousand
Reviews Old, mixed, organic Five-star burst, generic phrasing
Permissions Bank-specific minimum Accessibility, SMS, install other apps
Description language Polished Typos, broken grammar
Update history Years long One or two recent updates
Privacy policy URL Official bank domain Random `.in` / `.online`
Listed website Bank's official site Generic / dead link

If even one check fails, do not install. Verify by visiting the bank's website and clicking their “Download” link — that link goes to the genuine Play Store listing.

What Types of Fake Mobile Apps Are Most Common in India?

Fake app impersonation in India targets six primary categories. Knowing which category a suspect app falls into helps you report to the right authority faster:

  • Banking & payment apps — Fake SBI YONO, HDFC MobileBanking, ICICI iMobile, BHIM UPI clones. These request SMS read + Accessibility permissions to intercept OTPs and drain accounts. If you've installed one, see how to remove a fake banking app and protect your account.
  • Government service apps — Fake IRCTC Rail Connect, Income Tax e-filing, EPFO mobile app, mAadhaar, DigiLocker, CoWIN. Attackers exploit trust in government branding. Report these additionally to MeitY since they impersonate Digital India infrastructure.
  • Investment & trading apps — Fake stock broking apps, fake mutual fund apps, fake crypto exchange apps. See fake trading app recovery and fake mutual fund advisor scam.
  • Loan apps — Predatory fake loan apps that harvest contacts and blackmail borrowers. See fake loan approval scam.
  • Lottery & prize apps — Fake KBC / lottery apps that demand processing fees. See fake lottery scam and KBC scam explained.
  • Customer care & support apps — Fake “customer care” apps that are actually screen-sharing trojans. See fake customer care number scam.

In Q1 2026, the Ministry of Home Affairs' Indian Cyber Crime Coordination Centre (I4C) reported that fake app-related fraud accounted for over ₹2,900 crore in losses nationwide, with fake loan apps and fake investment apps being the top two vectors. Source: cybercrime.gov.in statistics dashboard.

How Does Fake App Malware Steal Your Money?

Understanding the attack chain helps you know what to check after installing a suspicious app. Most fake banking / government app trojans follow a five-step pattern:

  • Step 1 — Permission harvest: The app requests Accessibility Service, SMS read, Contacts, and “Install unknown apps” permissions — far more than a legitimate banking app needs.
  • Step 2 — OTP interception: With SMS read permission, the trojan reads incoming OTPs and forwards them to the attacker's server in real time. The user never sees the OTP flash.
  • Step 3 — Screen overlay: Accessibility Service lets the trojan draw invisible overlays on top of legitimate banking apps, capturing login credentials as the user types them.
  • Step 4 — Credential exfiltration: Captured User ID, password, and OTPs are sent to a command-and-control server, often hosted offshore.
  • Step 5 — Fund transfer: The attacker logs into the victim's net-banking or initiates UPI transactions using intercepted OTPs. Money is layered through multiple mule accounts within minutes.

This is why airplane mode + password change from another device within the first 30 minutes is critical. If SMS permission was already granted, assume every OTP sent in the last 48 hours was intercepted. For the full response, see UPI fraud recovery steps and how to freeze your bank account after fraud.

SIM swap risk — Some fake apps also attempt SIM swap fraud by harvesting your telecom KYC details. If your SIM suddenly loses signal, see SIM swap fraud recovery immediately.

Report to Google Play

  1. Open the suspect app's listing in Play Store (Android device or play.google.com on web)
  2. Tap ⋮ More optionsFlag as inappropriate
  3. Choose category: “Copycat or impersonation” or “Sexual content / harmful behaviour / malware” → as applicable
  4. Add a short description with reasons + screenshots
  5. For deeper reports: support.google.com → developer takedown (DMCA / impersonation)
  6. Trademark holders (i.e., the real bank) get faster takedown via Google's brand-protection form

Google generally responds within 24-48 hours for clear impersonation.

Report to CERT-In + MeitY

  1. CERT-In Incident Reporting: cert-in.org.in → “Incident Reporting Form”
  2. Email: [email protected] (PGP key on site)
  3. Phone: +91-1800-11-4949 (toll-free)
  4. Include: Play Store URL, developer name, date of detection, screenshots, hashes of APK if you can extract
  5. Cite CERT-In Cyber Security Directions, 2022 which obligates Indian platforms to retain logs for 180 days — available at cert-in.org.in and referenced at meity.gov.in
  6. MeitY Cyber Coordination Centre (I4C): cybercrime.gov.in → cyber-crime → impersonation
  7. For sustained / large-scale impersonation, a Section 69A (IT Act) blocking order can be requested by the brand — flag this to the affected bank / agency

CERT-In confirms incident receipt + ticket number; coordinates takedown with platform.

Which Government Authority Should You Report a Fake App To?

Multiple government bodies handle different aspects of fake app fraud. Filing with the right authority speeds up resolution. Use this comparison table to decide:

Reporting channel What they do When to use Response time URL
Google Play (Flag) Removes the listing from Play Store Always — first step for any fake app on Play Store 24-72 hours play.google.com
CERT-In Technical incident tracking, coordinates with platforms Always — for any malware / impersonation incident Ticket within 24h cert-in.org.in
National Cyber Crime Portal (I4C) Police-grade cyber crime complaint, fund freeze If money has been lost or credentials stolen Immediate (1930 hotline) cybercrime.gov.in
MeitY Policy intervention, platform accountability, Section 69A blocking For large-scale / sustained impersonation 7-15 days meity.gov.in
PIB Fact Check Public advisory / misinformation debunking If fake app is spreading via WhatsApp / social media 24-48 hours factcheck.pib.gov.in
RBI Sachet Suspicious entity reporting, bank-level escalation If a bank or NBFC is being impersonated Variable sachet.rbi.org.in
Impersonated brand Trademark takedown via legal team Always — forward the Play Store URL + screenshots 24-72 hours Brand's official email
Local police (FIR) Criminal investigation, evidence chain If money has moved or identity theft occurred Same day Nearest cyber crime police station
Tip — If you're unsure whether to file at the cyber crime portal or go to the police station directly, read cybercrime portal vs police station and how to file a cybercrime complaint in 2026.

Report to the impersonated brand

Most banks / agencies have dedicated “report-fraud” channels:

Forward the Play Store URL + screenshots. The brand's legal team can file the trademark-protection takedown directly with Google + CERT-In.

If you are a banking customer whose money was stolen via a fake app, escalate using the Banking Ombudsman complaint guide if the bank stalls on refund. See also what to do when a bank refuses a cyber fraud refund.

The 30-minute drill if you installed

If you have installed a suspect app and entered banking credentials:

  1. Airplane mode the device immediately
  2. From another device:
    • Change net-banking password
    • Block debit card
    • De-register UPI on every UPI app
    • Change email password + revoke sessions
  3. Uninstall the suspect app; revoke Accessibility / Notification access
  4. 1930 + cybercrime.gov.in if money has moved
  5. Bank email invoking RBI Master Direction 2017 within 24 hours
  6. CERT-In report ([email protected]) with details

For the full step-by-step after installing a fake app, read what to do if you installed a fake app. If your bank account has been frozen after fraud, see bank account freeze after cyber fraud.

Multiple Indian laws apply to fake mobile app fraud. Understanding your legal rights strengthens your complaint and compensation claim:

  • IT Act 2000, Section 66C — Identity theft (using another's identity electronically). Punishable up to 3 years imprisonment + ₹1 lakh fine.
  • IT Act 2000, Section 66D — Cheating by personation by means of any communication device or computer resource. Punishable up to 3 years + ₹1 lakh fine.
  • IT Act 2000, Section 69A — Power to issue directions for blocking public access to any information through any computer resource. This is the legal basis for government-ordered app takedowns.
  • IT Act 2000, Section 70B — Designates CERT-In as the national nodal agency for cyber incident response. See cert-in.org.in.
  • BNS, 2023, Section 316 — Cheating by personation. Replaces IPC Section 416.
  • BNS, 2023, Section 319 — Cheating. Replaces IPC Section 415–418.
  • BNS, 2023, Sections 336–338 — Forgery of valuable security / will, etc.
  • Trade Marks Act 1999 — The impersonated brand can sue for trademark infringement and passing off.
  • CERT-In Cyber Security Directions, 2022 — Obligates all intermediaries to report cyber incidents within 6 hours and maintain logs for 180 days. Available at cert-in.org.in. Referenced by MeitY.
  • RBI Master Direction on Fraud — Reporting and Classification, 2017 — Zero liability for customers reporting unauthorised transactions within 3 working days. See sachet.rbi.org.in and RBI ₹25,000 digital fraud compensation.
  • Digital Personal Data Protection Act, 2023 — Impersonation apps that harvest personal data without consent violate this Act. MeitY is the implementing ministry (meity.gov.in).
Reporting tip — When filing at cybercrime.gov.in, cite the specific sections above. This helps the investigating officer classify the complaint correctly and speeds up processing. See also complete cyber crime complaint guide and how to use RTI to check cybercrime complaint status.

How Can Senior Citizens and Vulnerable Users Stay Safe from Fake Apps?

Senior citizens are disproportionately targeted by fake app scammers because they may be less familiar with app-store verification. The following precautions are essential:

  • Never search and install — Always have a family member send the official Play Store / App Store link from the bank's website.
  • Enable Google Play Protect — Settings → Google → Security → Play Protect → turn on “Scan apps with Play Protect.” This scans every installed app for known malware.
  • Disable “Install unknown apps” — Settings → Apps → Special access → Install unknown apps → deny for all apps except Play Store.
  • Do not share OTP over phone — No bank or government agency will ever ask for an OTP. If someone calls claiming to be from SBI / IRCTC / Income Tax and asks for an OTP, it is a scam. See fake customer care number scam.
  • Beware of “assistance” apps — Scammers pose as tech support and ask seniors to install a remote-access app (AnyDesk, TeamViewer, screen-mirroring apps). Never install these if asked by an unknown caller. See digital arrest scam.
  • Use the 1930 helpline — If something seems wrong, call 1930 immediately. See what to say when calling 1930.
  • Register on Tafcop — Check if extra SIM cards have been issued in your name at tafcop.sancharsaathi.gov.in. See how to check SIM misuse via Tafcop.
For families — Sit with elderly parents and delete any app they didn't install from a bank's official website link. Set up MeitY's Cyber Jagrookta Diwas resources and review the how to report a scam call/number guide together.

What Happens After You Report a Fake App?

Understanding the post-report timeline helps you track progress and escalate if needed:

  • 0-24 hours — Google Play's automated review flags the reported listing. CERT-In issues an incident ticket number via email. If you called 1930, the helpline coordinates with your bank's nodal officer to freeze suspicious transactions in real time.
  • 24-72 hours — Google Play removes the listing if impersonation is confirmed. CERT-In coordinates with the platform's India liaison team. The impersonated brand's legal team may file a formal takedown notice. See Google's developer takedown form.
  • 3-7 days — CERT-In may issue a public advisory if multiple fake listings of the same app family are detected. PIB Fact Check publishes a debunking notice at factcheck.pib.gov.in. MeitY may be petitioned for a Section 69A blocking order if the developer re-uploads under new names.
  • 7-30 days — Cyber crime police investigation (if a formal complaint was filed at cybercrime.gov.in). The case is assigned to a cyber cell investigator. Bank refund processed under RBI Master Direction (if reported within 3 working days). See RBI ₹25,000 digital fraud compensation.
  • 30+ days — If the developer is identified, criminal proceedings under IT Act / BNS may follow. For ongoing status, you can file an RTI — see how to check cybercrime complaint status via RTI.
Escalation paths — If Google ignores your report, escalate via CERT-In. If CERT-In is slow, escalate via MeitY (meity.gov.in). If your bank refuses to refund, escalate to Banking Ombudsman (RB-IOS 2021) or see what to do when a bank refuses a cyber fraud refund.

What not to do

  • Do not install from Play Store search results without checking the developer name.
  • Do not install banking / government APKs from anywhere except the verified Play Store / App Store link on the brand's official site.
  • Do not grant Accessibility / SMS / install-other-apps permission to any non-essential app.
  • Do not rate / review a fake app even to “warn others” — it boosts engagement signals.
  • Do not delay reporting — every additional day means more victims.
  • Do not use the same password after a suspected fake app installation — assume it is compromised.

Sample report email

To: [email protected]
Cc: [bank's anti-phishing email] + cybercrime.gov.in submission ref

Subject: Impersonation app on Google Play targeting [Bank / Agency]
customers — request for takedown coordination

Sir / Madam,

I report the following impersonation app currently live on Google Play
Store, targeting customers of [Brand / Bank Name]:

  Play Store URL : ___
  App name       : ___
  Developer name : ___
  Install count  : ___
  Detection date : ___
  Permissions of concern : Accessibility, SMS read, ...

Attached:
  1. Screenshots of the listing
  2. Permissions screenshot
  3. APK hash (if extractable): ___
  4. Comparison with the genuine app

Cited authority:
  - CERT-In Cyber Security Directions, 2022
  - IT Act 2000 §66C, §66D, §69A (blocking)
  - BNS, 2023 §316 (personation), §319 (cheating)
  - Trade Marks Act 1999 (where the brand is registered)

I request CERT-In to:
  a) Coordinate takedown with Google Play and the affected brand.
  b) Issue a public advisory if multiple impersonation listings exist.
  c) Confirm the takedown date in writing.

Yours faithfully,
[Signature, Name, Date, Phone, Email]

Can compensation be claimed?

What to do in the next 30 minutes (printable card)

  1. 0-5 min — If installed: airplane mode + change passwords from another device
  2. 5-15 min — Report on Play Store (⋮ → Flag); report to bank's anti-phishing email
  3. 15-25 min — File at CERT-In + cybercrime.gov.in
  4. 25-30 min — Forward to PIB Fact Check + amplify on social media (with screenshots, no PII)
  5. +24 h — Bank's “report unauthorised transaction” form
  6. +72 h — Confirm takedown via Play Store / CERT-In ticket

Reporting channels comparison table

Feature Google Play Flag CERT-In cybercrime.gov.in / 1930 MeitY PIB Fact Check
Purpose Remove listing Technical incident tracking Criminal complaint + fund freeze Policy / blocking order Public misinformation debunk
Who can file Anyone Anyone Victim or proxy Brand / government Anyone
Requires account? Google account No Phone + OTP Email WhatsApp / web form
Best for Quick takedown Evidence trail Money recovery Large-scale impersonation Warning the public
Gov.in URL cert-in.org.in cybercrime.gov.in meity.gov.in factcheck.pib.gov.in
Typical response 24-72 h Ticket in 24 h Immediate (1930) 7-15 days 24-48 h

Long-tail keywords this page targets

report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app, fake BHIM app report, how to report fake app on Play Store India, fake government app India, cybercrime.gov.in fake app complaint, Section 69A app blocking India, RBI zero liability fake app fraud

Government & authority references

  • CERT-Incert-in.org.in · [email protected] · +91-1800-11-4949 (toll-free)
  • MHA — Indian Cyber Crime Coordination Centre (I4C)cybercrime.gov.in · 1930
  • MeitY — Ministry of Electronics and Information Technologymeity.gov.in — policy coordination, Digital India infrastructure protection, DPDP Act implementation
  • PIB Fact Checkfactcheck.pib.gov.in · WhatsApp +91-8799711259
  • RBI Sachetsachet.rbi.org.in (suspicious entity reporting)
  • Income Tax Departmentincometax.gov.in · [email protected]
  • Tafcop (Sanchar Saathi)tafcop.sancharsaathi.gov.in — SIM misuse check
  • IT Act 2000 §66C, §66D, §69A (blocking), §70B (CERT-In powers)
  • BNS, 2023 §316 (personation), §319 (cheating), §336–§338 (forgery)
  • Trade Marks Act 1999 — for branded-app impersonation
  • CERT-In Cyber Security Directions, 2022 — incident reporting within 6 hours, 180-day log retention
  • Digital Personal Data Protection Act, 2023 — consent and data protection for impersonation apps
  • RBI Master Direction on Fraud, 2017 — zero-liability framework for unauthorised electronic transactions

FAQ

How do I find the genuine app's developer name?

Visit the bank / agency's website; their “Download our app” page links to the genuine Play Store listing. The developer name there is authoritative. For example:

  • SBI YONO → developer: “State Bank of India” → listed at sbi.co.in
  • IRCTC Rail Connect → developer: “IRCTC Official” → listed at irctc.co.in
  • mAadhaar → developer: “Unique Identification Authority of India (UIDAI)” → listed at uidai.gov.in

Should I rate the fake app 1-star to warn others?

No — engagement signals (any rating) help the listing rank. Just report and silently move on.

Can I report multiple fake apps in one email to CERT-In?

Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings.

What about fake apps in third-party stores (APKPure / Aptoide)?

Report directly to the store's abuse channel; also email CERT-In at [email protected]. These stores' takedowns are slower but possible. Always prefer the official Play Store / App Store.

Do I need to file a police FIR?

Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. You can file online at cybercrime.gov.in or at your nearest cyber crime police station. See complete cyber crime complaint guide and how to file a cybercrime complaint in 2026.

What if the bank refuses to refund after a fake app fraud?

Escalate in this order: (1) bank's internal grievance redressal, (2) Banking Ombudsman under RB-IOS 2021 — see Banking Ombudsman guide, (3) what to do when bank refuses cyber fraud refund. Cite RBI Master Direction 2017 zero-liability provision if you reported within 3 working days.

Are fake loan apps also covered here?

Yes — fake loan apps are a major category. They harvest contacts, access gallery, and blackmail borrowers. Report them the same way (Play Store flag + CERT-In + cybercrime.gov.in). See fake loan approval scam for specific guidance.

Can fake apps steal my data even without banking access?

Yes. Fake apps can harvest contacts, SMS history, call logs, location, photos, and clipboard data. This data is sold on the dark web or used for targeted phishing. Uninstall immediately and change passwords for all accounts that shared the same credentials. See fake app removal guide.

What is Google Play Protect and does it help?

Google Play Protect is Google's built-in malware scanner that scans all installed apps daily. It catches known malware signatures but may miss brand-new lookalike apps for 24-72 hours. Enable it at Settings → Google → Security → Play Protect. It is a safety net, not a replacement for manual developer-name verification.

How do I report a fake app that is spreading via WhatsApp?

Forward the message (without clicking any links) to PIB Fact Check at WhatsApp +91-8799711259 or submit at factcheck.pib.gov.in. Also report the WhatsApp number to cybercrime.gov.in. See also WhatsApp OTP fraud explained and how to report scam calls/numbers.

Can I check if my SIM is being misused after a fake app installation?

Yes — visit tafcop.sancharsaathi.gov.in to check all mobile connections issued in your name. See how to check SIM misuse via Tafcop and 9 SIM card limit under Telecom Act.

Myth vs reality

Myth Reality
“Play Store apps are safe.” Lookalike apps occasionally pass review; the safe path is the bank's website link.
“Five-star ratings = real.” Burst five-star ratings are a fake-app signal, not authenticity.
“Only banking apps are cloned.” IRCTC, Income Tax, EPFO, UIDAI, RBI, scholarship portals are all impersonated.
“Reporting won't matter; Google ignores it.” Google's brand-protection takedown is among the fastest in tech — typically 24-48 h.
“If I don't install, I'm safe.” True for you; but the listing is harvesting other victims — report it.
“Google Play Protect catches all fake apps.” Play Protect catches known malware; brand-new lookalike apps may slip through for 24-72 hours.
“Only tech-illiterate people fall for fake apps.” Even savvy users have been fooled by near-perfect clones; the verification habit matters more than tech skill.
“If I uninstall the fake app, the danger is over.” Not necessarily — credentials may already be exfiltrated. Change all passwords from another device and monitor bank statements for 30 days.

Reader signal

Was this article useful?

Tap once if it helped you. These counters show other citizens which pages are worth reading.

- views