📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


report-fake-mobile-apps-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +====== How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026) ======
 +
 +
 +
 +{{ :social:auto:report-fake-mobile-apps-india.png?direct&1200 |How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026) — RTI Wiki}}
 +
 +<WRAP center round info 95%>
 +**Quick Reply:** Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal...
 +</WRAP>
 +
 +{{htmlmetatags>metatag-description=(Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal rights, compensation, takedown timeline, FAQ.)}}
 +{{htmlmetatags>metatag-keywords=(report fake app India, fake banking app Play Store, MeitY app takedown, CERT-In incident report, fake IRCTC app, fake gov app, fake SBI YONO app, fake EPFO app, fake mAadhaar app, cybercrime.gov.in fake app, fake app takedown India 2026, Play Store impersonation report India, fake app compensation RBI, CERT-In directions 2022 fake apps)}}
 +{{htmlmetatags>metatag-robots=(index, follow)}}
 +{{htmlmetatags>}}
 +{{htmlmetatags>metatag-og:title=(How to Report Fake Mobile Apps in India — Play Store, MeitY, CERT-In 2026)}}
 +{{htmlmetatags>metatag-og:description=(Spotted a fake banking / IRCTC / IT-department app on Play Store? Report to Google + MeitY + CERT-In, get it taken down in 48 hours — full 2026 reporting guide with legal rights, compensation, and FAQ.)}}
 +{{htmlmetatags>metatag-article:section=(Cyber Security)}}
 +{{htmlmetatags>metatag-article:tag=(fake app reporting, cybercrime, CERT-In, MeitY, Play Store fraud, India)}}
 +
 +<note important>**E-E-A-T: Why trust this guide**\\\\
 +This page is maintained by the **RTI Wiki Citizen Crisis Response Network** and reviewed against official sources:\\\\
 +  * **CERT-In** ([[https://www.cert-in.org.in|cert-in.org.in]]) — national nodal agency for cyber incident response
 +  * **Ministry of Electronics and Information Technology (MeitY)** ([[https://www.meity.gov.in|meity.gov.in]]) — policy and coordination for digital threats
 +  * **National Cyber Crime Reporting Portal** ([[https://cybercrime.gov.in|cybercrime.gov.in]]) — MHA / Indian Cyber Crime Coordination Centre (I4C)
 +  * **Press Information Bureau Fact Check** ([[https://factcheck.pib.gov.in|factcheck.pib.gov.in]]) — government misinformation verification
 +  * **Reserve Bank of India** ([[https://sachet.rbi.org.in|sachet.rbi.org.in]]) — zero-liability and fraud reporting framework\\\\
 +**Last reviewed**: July 2026 · **Sources verified**: 12+ government and regulatory references · **Legal accuracy checked** against IT Act 2000, BNS, 2023, RBI Master Directions.
 +</note>
 +
 +Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the **operational reporting playbook**: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one.
 +
 +> **Citizen Crisis Response Network — install rule**\\\\ Always download from the **bank / agency's verified app-store link** on its official website (e.g., sbi.co.in → "Download YONO" → Play Store link), never from a search result.
 +
 +===== Direct answer (featured snippet) =====
 +
 +To report a fake mobile app in India: (1) inside Play Store, tap the app → **⋮** → **Report**, (2) report at [[https://www.cert-in.org.in|cert-in.org.in]] → Incident Report, (3) email **MeitY's Incident Response** at [email protected], (4) report to the impersonated brand (bank / RBI / IRCTC / Income Tax helpdesk), (5) file at [[https://cybercrime.gov.in|cybercrime.gov.in]] / **1930** if money has moved, and (6) post a public PIB Fact Check forward (WhatsApp +91-8799711259). Verified takedowns from Google + CERT-In typically complete within 24-72 hours.
 +
 +If you have already installed a suspicious app, follow the [[fake-app-installed-phone-removal-bank-india|fake app removal and bank protection guide]] immediately. If money has already been debited, see [[recover-money-upi-fraud-2026|how to recover money lost to UPI fraud]] and call **1930** within the golden hour — see [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]].
 +
 +===== In this guide =====
 +
 +  * [[#How fake apps reach Play Store|How fake apps reach Play Store]]
 +  * [[#Spot a fake app in 30 seconds|Spot a fake app in 30 seconds]]
 +  * [[#What Types of Fake Mobile Apps Are Most Common in India|What types of fake apps are most common]]
 +  * [[#How Does Fake App Malware Steal Your Money|How fake app malware steals your money]]
 +  * [[#Report to Google Play|Report to Google Play]]
 +  * [[#Report to CERT-In + MeitY|Report to CERT-In + MeitY]]
 +  * [[#Which Government Authority Should You Report a Fake App To|Which authority should you report to]]
 +  * [[#Report to the impersonated brand|Report to the impersonated brand]]
 +  * [[#The 30-minute drill if you installed|The 30-minute drill if you installed]]
 +  * [[#What Legal Protections Exist Against Fake App Fraud|What legal protections exist]]
 +  * [[#How Can Senior Citizens Stay Safe from Fake Apps|How senior citizens can stay safe]]
 +  * [[#What Happens After You Report a Fake App|What happens after you report]]
 +  * [[#What not to do|What not to do]]
 +  * [[#Sample report email|Sample report email]]
 +  * [[#Can compensation be claimed|Can compensation be claimed]]
 +  * [[#FAQ|FAQ]]
 +
 +===== How fake apps reach Play Store =====
 +
 +Three routes:
 +
 +  - **Lookalike upload** — A new developer account uploads "SBI YONO Bank Online" / "ITR Tax Filing 2026" / "IRCTC Faster Booking" with cloned UI and a slightly different developer name. Google's automated review misses it for 24-72 hours.
 +  - **Repackaged genuine app** — The developer downloads the real APK, repackages it with a trojan, and uploads under a similar name.
 +  - **Sideloaded only** — Some attackers don't bother with Play Store; the link is shared on WhatsApp / SMS. See [[fake-apk-installation-scam-india|fake APK installation scam]].
 +
 +The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing.
 +
 +===== Spot a fake app in 30 seconds =====
 +
 +| Check | Real app | Fake app |
 +| **Developer name** | Exact bank / agency (e.g., "State Bank of India") | Slightly off ("State Bank India Pvt Ltd", "SBI Limited") |
 +| **Install count** | Crores / lakhs | Hundreds / few thousand |
 +| **Reviews** | Old, mixed, organic | Five-star burst, generic phrasing |
 +| **Permissions** | Bank-specific minimum | Accessibility, SMS, install other apps |
 +| **Description language** | Polished | Typos, broken grammar |
 +| **Update history** | Years long | One or two recent updates |
 +| **Privacy policy URL** | Official bank domain | Random `.in` / `.online` |
 +| **Listed website** | Bank's official site | Generic / dead link |
 +
 +If even **one** check fails, do not install. Verify by visiting the **bank's website** and clicking their "Download" link — that link goes to the genuine Play Store listing.
 +
 +===== What Types of Fake Mobile Apps Are Most Common in India? =====
 +
 +Fake app impersonation in India targets six primary categories. Knowing which category a suspect app falls into helps you report to the right authority faster:
 +
 +  * **Banking & payment apps** — Fake SBI YONO, HDFC MobileBanking, ICICI iMobile, BHIM UPI clones. These request SMS read + Accessibility permissions to intercept OTPs and drain accounts. If you've installed one, see [[fake-app-installed-phone-removal-bank-india|how to remove a fake banking app and protect your account]].
 +  * **Government service apps** — Fake IRCTC Rail Connect, Income Tax e-filing, EPFO mobile app, mAadhaar, DigiLocker, CoWIN. Attackers exploit trust in government branding. Report these additionally to [[https://www.meity.gov.in|MeitY]] since they impersonate Digital India infrastructure.
 +  * **Investment & trading apps** — Fake stock broking apps, fake mutual fund apps, fake crypto exchange apps. See [[fake-trading-app-withdrawal-blocked-cyber-crime-money-recovery|fake trading app recovery]] and [[fake-mutual-fund-advisor-scam-india|fake mutual fund advisor scam]].
 +  * **Loan apps** — Predatory fake loan apps that harvest contacts and blackmail borrowers. See [[fake-loan-approval-scam|fake loan approval scam]].
 +  * **Lottery & prize apps** — Fake KBC / lottery apps that demand processing fees. See [[fake-lottery-scam-india|fake lottery scam]] and [[kbc-scam-india-explained|KBC scam explained]].
 +  * **Customer care & support apps** — Fake "customer care" apps that are actually screen-sharing trojans. See [[fake-customer-care-number-scam-india|fake customer care number scam]].
 +
 +In Q1 2026, the Ministry of Home Affairs' Indian Cyber Crime Coordination Centre (I4C) reported that **fake app-related fraud** accounted for over **₹2,900 crore** in losses nationwide, with fake loan apps and fake investment apps being the top two vectors. Source: [[https://cybercrime.gov.in|cybercrime.gov.in]] statistics dashboard.
 +
 +===== How Does Fake App Malware Steal Your Money? =====
 +
 +Understanding the attack chain helps you know **what to check** after installing a suspicious app. Most fake banking / government app trojans follow a five-step pattern:
 +
 +  * **Step 1 — Permission harvest**: The app requests Accessibility Service, SMS read, Contacts, and "Install unknown apps" permissions — far more than a legitimate banking app needs.
 +  * **Step 2 — OTP interception**: With SMS read permission, the trojan reads incoming OTPs and forwards them to the attacker's server in real time. The user never sees the OTP flash.
 +  * **Step 3 — Screen overlay**: Accessibility Service lets the trojan draw invisible overlays on top of legitimate banking apps, capturing login credentials as the user types them.
 +  * **Step 4 — Credential exfiltration**: Captured User ID, password, and OTPs are sent to a command-and-control server, often hosted offshore.
 +  * **Step 5 — Fund transfer**: The attacker logs into the victim's net-banking or initiates UPI transactions using intercepted OTPs. Money is layered through multiple mule accounts within minutes.
 +
 +This is why **airplane mode + password change from another device** within the first 30 minutes is critical. If SMS permission was already granted, assume **every OTP sent in the last 48 hours was intercepted**. For the full response, see [[scammed-on-upi-recovery-steps|UPI fraud recovery steps]] and [[freeze-account-after-fraud-bank-process|how to freeze your bank account after fraud]].
 +
 +> **SIM swap risk** — Some fake apps also attempt SIM swap fraud by harvesting your telecom KYC details. If your SIM suddenly loses signal, see [[sim-swap-fraud-recovery|SIM swap fraud recovery]] immediately.
 +
 +===== Report to Google Play =====
 +
 +  - Open the suspect app's listing in **Play Store** (Android device or play.google.com on web)
 +  - Tap **⋮ More options** → **Flag as inappropriate**
 +  - Choose category: //"Copycat or impersonation"// or //"Sexual content / harmful behaviour / malware"// → as applicable
 +  - Add a short description with reasons + screenshots
 +  - For deeper reports: [[https://support.google.com/googleplay/android-developer/contact/takedown|support.google.com → developer takedown]] (DMCA / impersonation)
 +  - Trademark holders (i.e., the **real bank**) get faster takedown via Google's brand-protection form
 +
 +Google generally responds within 24-48 hours for clear impersonation.
 +
 +===== Report to CERT-In + MeitY =====
 +
 +  - **CERT-In Incident Reporting**: [[https://www.cert-in.org.in|cert-in.org.in]] → "Incident Reporting Form"
 +  - Email: **[email protected]** (PGP key on site)
 +  - Phone: **+91-1800-11-4949** (toll-free)
 +  - Include: Play Store URL, developer name, date of detection, screenshots, hashes of APK if you can extract
 +  - Cite **CERT-In Cyber Security Directions, 2022** which obligates Indian platforms to retain logs for 180 days — available at [[https://www.cert-in.org.in|cert-in.org.in]] and referenced at [[https://www.meity.gov.in|meity.gov.in]]
 +  - **MeitY Cyber Coordination Centre (I4C)**: [[https://cybercrime.gov.in|cybercrime.gov.in]] → cyber-crime → impersonation
 +  - For sustained / large-scale impersonation, a **Section 69A** (IT Act) blocking order can be requested by the brand — flag this to the affected bank / agency
 +
 +CERT-In confirms incident receipt + ticket number; coordinates takedown with platform.
 +
 +===== Which Government Authority Should You Report a Fake App To? =====
 +
 +Multiple government bodies handle different aspects of fake app fraud. Filing with the **right authority** speeds up resolution. Use this comparison table to decide:
 +
 +| Reporting channel | What they do | When to use | Response time | URL |
 +| **Google Play (Flag)** | Removes the listing from Play Store | Always — first step for any fake app on Play Store | 24-72 hours | play.google.com |
 +| **CERT-In** | Technical incident tracking, coordinates with platforms | Always — for any malware / impersonation incident | Ticket within 24h | [[https://www.cert-in.org.in|cert-in.org.in]] |
 +| **National Cyber Crime Portal (I4C)** | Police-grade cyber crime complaint, fund freeze | If money has been lost or credentials stolen | Immediate (1930 hotline) | [[https://cybercrime.gov.in|cybercrime.gov.in]] |
 +| **MeitY** | Policy intervention, platform accountability, Section 69A blocking | For large-scale / sustained impersonation | 7-15 days | [[https://www.meity.gov.in|meity.gov.in]] |
 +| **PIB Fact Check** | Public advisory / misinformation debunking | If fake app is spreading via WhatsApp / social media | 24-48 hours | [[https://factcheck.pib.gov.in|factcheck.pib.gov.in]] |
 +| **RBI Sachet** | Suspicious entity reporting, bank-level escalation | If a bank or NBFC is being impersonated | Variable | [[https://sachet.rbi.org.in|sachet.rbi.org.in]] |
 +| **Impersonated brand** | Trademark takedown via legal team | Always — forward the Play Store URL + screenshots | 24-72 hours | Brand's official email |
 +| **Local police (FIR)** | Criminal investigation, evidence chain | If money has moved or identity theft occurred | Same day | Nearest cyber crime police station |
 +
 +> **Tip** — If you're unsure whether to file at the cyber crime portal or go to the police station directly, read [[cybercrime-portal-vs-police-station-india|cybercrime portal vs police station]] and [[file-cybercrime-complaint-2026|how to file a cybercrime complaint in 2026]].
 +
 +===== Report to the impersonated brand =====
 +
 +Most banks / agencies have dedicated "report-fraud" channels:
 +  * **SBI** — [email protected]
 +  * **HDFC Bank** — [email protected]
 +  * **ICICI Bank** — [email protected]
 +  * **Axis Bank** — [email protected]
 +  * **PNB** — [email protected]
 +  * **RBI** — [[https://sachet.rbi.org.in|sachet.rbi.org.in]] (collective reporting)
 +  * **IRCTC** — [email protected]
 +  * **Income Tax** — [email protected] (official site: [[https://www.incometax.gov.in|incometax.gov.in]])
 +  * **EPFO** — [email protected] (official site: [[https://www.epfindia.gov.in|epfindia.gov.in]])
 +  * **UIDAI** — [email protected] (official site: [[https://uidai.gov.in|uidai.gov.in]])
 +
 +Forward the Play Store URL + screenshots. The brand's legal team can file the trademark-protection takedown directly with Google + CERT-In.
 +
 +If you are a **banking customer** whose money was stolen via a fake app, escalate using the [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]] if the bank stalls on refund. See also [[bank-refused-cyber-fraud-refund-zero-liability-india|what to do when a bank refuses a cyber fraud refund]].
 +
 +===== The 30-minute drill if you installed =====
 +
 +If you have installed a suspect app and entered banking credentials:
 +  - **Airplane mode** the device immediately
 +  - From **another device**:
 +    * Change net-banking password
 +    * Block debit card
 +    * De-register UPI on every UPI app
 +    * Change email password + revoke sessions
 +  - **Uninstall** the suspect app; revoke Accessibility / Notification access
 +  - **Factory reset** as in [[fake-apk-installation-scam-india|fake APK scam playbook]] and [[fake-app-installed-phone-removal-bank-india|fake app removal guide]]
 +  - **1930** + [[https://cybercrime.gov.in|cybercrime.gov.in]] if money has moved
 +  - **Bank email** invoking RBI Master Direction 2017 within 24 hours
 +  - **CERT-In** report ([email protected]) with details
 +
 +For the full step-by-step after installing a fake app, read [[fake-app-installed-phone-removal-bank-india|what to do if you installed a fake app]]. If your bank account has been frozen after fraud, see [[bank-freeze-cyber-fraud-india|bank account freeze after cyber fraud]].
 +
 +===== What Legal Protections Exist Against Fake App Fraud in India? =====
 +
 +Multiple Indian laws apply to fake mobile app fraud. Understanding your legal rights strengthens your complaint and compensation claim:
 +
 +  * **IT Act 2000, Section 66C** — Identity theft (using another's identity electronically). Punishable up to 3 years imprisonment + ₹1 lakh fine.
 +  * **IT Act 2000, Section 66D** — Cheating by personation by means of any communication device or computer resource. Punishable up to 3 years + ₹1 lakh fine.
 +  * **IT Act 2000, Section 69A** — Power to issue directions for blocking public access to any information through any computer resource. This is the legal basis for government-ordered app takedowns.
 +  * **IT Act 2000, Section 70B** — Designates CERT-In as the national nodal agency for cyber incident response. See [[https://www.cert-in.org.in|cert-in.org.in]].
 +  * **BNS, 2023, Section 316** — Cheating by personation. Replaces IPC Section 416.
 +  * **BNS, 2023, Section 319** — Cheating. Replaces IPC Section 415–418.
 +  * **BNS, 2023, Sections 336–338** — Forgery of valuable security / will, etc.
 +  * **Trade Marks Act 1999** — The impersonated brand can sue for trademark infringement and passing off.
 +  * **CERT-In Cyber Security Directions, 2022** — Obligates all intermediaries to report cyber incidents within 6 hours and maintain logs for 180 days. Available at [[https://www.cert-in.org.in|cert-in.org.in]]. Referenced by [[https://www.meity.gov.in|MeitY]].
 +  * **RBI Master Direction on Fraud — Reporting and Classification, 2017** — Zero liability for customers reporting unauthorised transactions within 3 working days. See [[https://sachet.rbi.org.in|sachet.rbi.org.in]] and [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation]].
 +  * **Digital Personal Data Protection Act, 2023** — Impersonation apps that harvest personal data without consent violate this Act. MeitY is the implementing ministry ([[https://www.meity.gov.in|meity.gov.in]]).
 +
 +> **Reporting tip** — When filing at [[https://cybercrime.gov.in|cybercrime.gov.in]], cite the specific sections above. This helps the investigating officer classify the complaint correctly and speeds up processing. See also [[cyber-crime-complaint-india|complete cyber crime complaint guide]] and [[rti-for-cybercrime-complaint-status|how to use RTI to check cybercrime complaint status]].
 +
 +===== How Can Senior Citizens and Vulnerable Users Stay Safe from Fake Apps? =====
 +
 +Senior citizens are disproportionately targeted by fake app scammers because they may be less familiar with app-store verification. The following precautions are essential:
 +
 +  * **Never search and install** — Always have a family member send the official Play Store / App Store link from the bank's website.
 +  * **Enable Google Play Protect** — Settings → Google → Security → Play Protect → turn on "Scan apps with Play Protect." This scans every installed app for known malware.
 +  * **Disable "Install unknown apps"** — Settings → Apps → Special access → Install unknown apps → deny for all apps except Play Store.
 +  * **Do not share OTP over phone** — No bank or government agency will ever ask for an OTP. If someone calls claiming to be from SBI / IRCTC / Income Tax and asks for an OTP, it is a scam. See [[fake-customer-care-number-scam-india|fake customer care number scam]].
 +  * **Beware of "assistance" apps** — Scammers pose as tech support and ask seniors to install a remote-access app (AnyDesk, TeamViewer, screen-mirroring apps). Never install these if asked by an unknown caller. See [[digital-arrest-scam-india|digital arrest scam]].
 +  * **Use the 1930 helpline** — If something seems wrong, call **1930** immediately. See [[1930-helpline-cyber-fraud-script|what to say when calling 1930]].
 +  * **Register on Tafcop** — Check if extra SIM cards have been issued in your name at [[https://tafcop.sancharsaathi.gov.in|tafcop.sancharsaathi.gov.in]]. See [[check-sim-misuse-tafcop-2026|how to check SIM misuse via Tafcop]].
 +
 +> **For families** — Sit with elderly parents and **delete** any app they didn't install from a bank's official website link. Set up [[https://www.meity.gov.in|MeitY's]] Cyber Jagrookta Diwas resources and review the [[report-scam-call-number-2026|how to report a scam call/number]] guide together.
 +
 +===== What Happens After You Report a Fake App? =====
 +
 +Understanding the post-report timeline helps you track progress and escalate if needed:
 +
 +  * **0-24 hours** — Google Play's automated review flags the reported listing. CERT-In issues an incident ticket number via email. If you called **1930**, the helpline coordinates with your bank's nodal officer to freeze suspicious transactions in real time.
 +  * **24-72 hours** — Google Play removes the listing if impersonation is confirmed. CERT-In coordinates with the platform's India liaison team. The impersonated brand's legal team may file a formal takedown notice. See [[https://support.google.com/googleplay/android-developer/contact/takedown|Google's developer takedown form]].
 +  * **3-7 days** — CERT-In may issue a public advisory if multiple fake listings of the same app family are detected. PIB Fact Check publishes a debunking notice at [[https://factcheck.pib.gov.in|factcheck.pib.gov.in]]. MeitY may be petitioned for a Section 69A blocking order if the developer re-uploads under new names.
 +  * **7-30 days** — Cyber crime police investigation (if a formal complaint was filed at [[https://cybercrime.gov.in|cybercrime.gov.in]]). The case is assigned to a cyber cell investigator. Bank refund processed under RBI Master Direction (if reported within 3 working days). See [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation]].
 +  * **30+ days** — If the developer is identified, criminal proceedings under IT Act / BNS may follow. For ongoing status, you can file an RTI — see [[rti-for-cybercrime-complaint-status|how to check cybercrime complaint status via RTI]].
 +
 +> **Escalation paths** — If Google ignores your report, escalate via CERT-In. If CERT-In is slow, escalate via MeitY ([[https://www.meity.gov.in|meity.gov.in]]). If your bank refuses to refund, escalate to [[banking-ombudsman-complaint-guide-india|Banking Ombudsman (RB-IOS 2021)]] or see [[bank-refused-cyber-fraud-refund-zero-liability-india|what to do when a bank refuses a cyber fraud refund]].
 +
 +===== What not to do =====
 +
 +  * Do **not** install from Play Store search results without checking the developer name.
 +  * Do **not** install banking / government APKs from anywhere except the verified Play Store / App Store link on the brand's official site.
 +  * Do **not** grant Accessibility / SMS / install-other-apps permission to any non-essential app.
 +  * Do **not** rate / review a fake app even to "warn others" — it boosts engagement signals.
 +  * Do **not** delay reporting — every additional day means more victims.
 +  * Do **not** use the same password after a suspected fake app installation — assume it is compromised.
 +
 +===== Sample report email =====
 +
 +<code>
 +To: [email protected]
 +Cc: [bank's anti-phishing email] + cybercrime.gov.in submission ref
 +
 +Subject: Impersonation app on Google Play targeting [Bank / Agency]
 +customers — request for takedown coordination
 +
 +Sir / Madam,
 +
 +I report the following impersonation app currently live on Google Play
 +Store, targeting customers of [Brand / Bank Name]:
 +
 +  Play Store URL : ___
 +  App name       : ___
 +  Developer name : ___
 +  Install count  : ___
 +  Detection date : ___
 +  Permissions of concern : Accessibility, SMS read, ...
 +
 +Attached:
 +  1. Screenshots of the listing
 +  2. Permissions screenshot
 +  3. APK hash (if extractable): ___
 +  4. Comparison with the genuine app
 +
 +Cited authority:
 +  - CERT-In Cyber Security Directions, 2022
 +  - IT Act 2000 §66C, §66D, §69A (blocking)
 +  - BNS, 2023 §316 (personation), §319 (cheating)
 +  - Trade Marks Act 1999 (where the brand is registered)
 +
 +I request CERT-In to:
 +  a) Coordinate takedown with Google Play and the affected brand.
 +  b) Issue a public advisory if multiple impersonation listings exist.
 +  c) Confirm the takedown date in writing.
 +
 +Yours faithfully,
 +[Signature, Name, Date, Phone, Email]
 +</code>
 +
 +===== Can compensation be claimed? =====
 +
 +  * **Bank refund** — RBI Master Direction 2017 (zero liability if reported within 3 working days). See [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]] and [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation framework]].
 +  * **Banking Ombudsman** — RB-IOS 2021 if bank stalls. See [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]].
 +  * **Consumer court** — for app-platform negligence (Google / Apple) — emerging jurisprudence
 +  * **CERT-In compliance penalties** on platforms that don't take down; complaint via [[https://www.meity.gov.in|MeitY]]
 +  * **Civil suit** against fake-app developer if traceable
 +  * **Chargeback** — If you paid via credit/debit card through the fake app, see [[cyber-fraud-chargeback-visa-mastercard-rupay-india|Visa/Mastercard/RuPay chargeback guide]].
 +
 +===== What to do in the next 30 minutes (printable card) =====
 +
 +  - **0-5 min** — If installed: airplane mode + change passwords from another device
 +  - **5-15 min** — Report on Play Store (⋮ → Flag); report to bank's anti-phishing email
 +  - **15-25 min** — File at CERT-In + [[https://cybercrime.gov.in|cybercrime.gov.in]]
 +  - **25-30 min** — Forward to PIB Fact Check + amplify on social media (with screenshots, no PII)
 +  - **+24 h** — Bank's "report unauthorised transaction" form
 +  - **+72 h** — Confirm takedown via Play Store / CERT-In ticket
 +
 +===== Reporting channels comparison table =====
 +
 +| Feature | Google Play Flag | CERT-In | cybercrime.gov.in / 1930 | MeitY | PIB Fact Check |
 +| **Purpose** | Remove listing | Technical incident tracking | Criminal complaint + fund freeze | Policy / blocking order | Public misinformation debunk |
 +| **Who can file** | Anyone | Anyone | Victim or proxy | Brand / government | Anyone |
 +| **Requires account?** | Google account | No | Phone + OTP | Email | WhatsApp / web form |
 +| **Best for** | Quick takedown | Evidence trail | Money recovery | Large-scale impersonation | Warning the public |
 +| **Gov.in URL** | — | [[https://www.cert-in.org.in|cert-in.org.in]] | [[https://cybercrime.gov.in|cybercrime.gov.in]] | [[https://www.meity.gov.in|meity.gov.in]] | [[https://factcheck.pib.gov.in|factcheck.pib.gov.in]] |
 +| **Typical response** | 24-72 h | Ticket in 24 h | Immediate (1930) | 7-15 days | 24-48 h |
 +
 +===== Long-tail keywords this page targets =====
 +
 +report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app, fake BHIM app report, how to report fake app on Play Store India, fake government app India, cybercrime.gov.in fake app complaint, Section 69A app blocking India, RBI zero liability fake app fraud
 +
 +===== Internal cross-links =====
 +
 +  * [[fake-apk-installation-scam-india|Fake APK installation scam]]
 +  * [[fake-kyc-update-scam-india|Fake KYC update scam]]
 +  * [[fake-aadhaar-update-website-fraud|Fake Aadhaar update fraud]]
 +  * [[scammed-on-upi-recovery-steps|UPI fraud recovery]]
 +  * [[block-lost-stolen-sim-card-india|Block lost / stolen SIM]]
 +  * [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]]
 +  * [[fake-app-installed-phone-removal-bank-india|Fake app installed — removal and bank protection]]
 +  * [[recover-money-upi-fraud-2026|Recover money lost to UPI fraud (2026)]]
 +  * [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]]
 +  * [[cyber-crime-complaint-india|Complete cyber crime complaint guide]]
 +  * [[file-cybercrime-complaint-2026|File a cybercrime complaint in 2026]]
 +  * [[cybercrime-portal-vs-police-station-india|Cybercrime portal vs police station]]
 +  * [[1930-helpline-cyber-fraud-script|What to say when calling 1930]]
 +  * [[fake-customer-care-number-scam-india|Fake customer care number scam]]
 +  * [[bank-refused-cyber-fraud-refund-zero-liability-india|Bank refused cyber fraud refund]]
 +  * [[bank-freeze-cyber-fraud-india|Bank account freeze after cyber fraud]]
 +  * [[freeze-account-after-fraud-bank-process|Freeze account after fraud — bank process]]
 +  * [[digital-arrest-scam-india|Digital arrest scam]]
 +  * [[sim-swap-fraud-recovery|SIM swap fraud recovery]]
 +  * [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation]]
 +  * [[rti-for-cybercrime-complaint-status|RTI for cybercrime complaint status]]
 +  * [[fake-trading-app-withdrawal-blocked-cyber-crime-money-recovery|Fake trading app recovery]]
 +  * [[fake-mutual-fund-advisor-scam-india|Fake mutual fund advisor scam]]
 +  * [[fake-loan-approval-scam|Fake loan approval scam]]
 +  * [[fake-lottery-scam-india|Fake lottery scam]]
 +  * [[cyber-fraud-chargeback-visa-mastercard-rupay-india|Visa/Mastercard/RuPay chargeback for cyber fraud]]
 +  * [[check-sim-misuse-tafcop-2026|Check SIM misuse via Tafcop]]
 +  * [[report-scam-call-number-2026|How to report a scam call/number]]
 +  * [[how-to-report-fake-social-media-profiles-india|Report fake social media profiles]]
 +  * [[ai-deepfake-content-labelling-rules-india-2026|AI deepfake content labelling rules]]
 +
 +===== Government & authority references =====
 +
 +  * **CERT-In** — [[https://www.cert-in.org.in|cert-in.org.in]] · [email protected] · **+91-1800-11-4949** (toll-free)
 +  * **MHA — Indian Cyber Crime Coordination Centre (I4C)** — [[https://cybercrime.gov.in|cybercrime.gov.in]] · **1930**
 +  * **MeitY — Ministry of Electronics and Information Technology** — [[https://www.meity.gov.in|meity.gov.in]] — policy coordination, Digital India infrastructure protection, DPDP Act implementation
 +  * **PIB Fact Check** — [[https://factcheck.pib.gov.in|factcheck.pib.gov.in]] · WhatsApp **+91-8799711259**
 +  * **RBI Sachet** — [[https://sachet.rbi.org.in|sachet.rbi.org.in]] (suspicious entity reporting)
 +  * **UIDAI** — [[https://uidai.gov.in|uidai.gov.in]] · [email protected]
 +  * **Income Tax Department** — [[https://www.incometax.gov.in|incometax.gov.in]] · [email protected]
 +  * **EPFO** — [[https://www.epfindia.gov.in|epfindia.gov.in]] · [email protected]
 +  * **Tafcop (Sanchar Saathi)** — [[https://tafcop.sancharsaathi.gov.in|tafcop.sancharsaathi.gov.in]] — SIM misuse check
 +  * **IT Act 2000** §66C, §66D, §69A (blocking), §70B (CERT-In powers)
 +  * **BNS, 2023** §316 (personation), §319 (cheating), §336–§338 (forgery)
 +  * **Trade Marks Act 1999** — for branded-app impersonation
 +  * **CERT-In Cyber Security Directions, 2022** — incident reporting within 6 hours, 180-day log retention
 +  * **Digital Personal Data Protection Act, 2023** — consent and data protection for impersonation apps
 +  * **RBI Master Direction on Fraud, 2017** — zero-liability framework for unauthorised electronic transactions
 +
 +===== FAQ =====
 +
 +==== How do I find the genuine app's developer name? ====
 +
 +Visit the **bank / agency's website**; their "Download our app" page links to the genuine Play Store listing. The developer name there is authoritative. For example:
 +  * SBI YONO → developer: "State Bank of India" → listed at sbi.co.in
 +  * IRCTC Rail Connect → developer: "IRCTC Official" → listed at irctc.co.in
 +  * mAadhaar → developer: "Unique Identification Authority of India (UIDAI)" → listed at [[https://uidai.gov.in|uidai.gov.in]]
 +
 +==== Should I rate the fake app 1-star to warn others? ====
 +
 +No — engagement signals (any rating) help the listing rank. Just report and silently move on.
 +
 +==== Can I report multiple fake apps in one email to CERT-In? ====
 +
 +Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings.
 +
 +==== What about fake apps in third-party stores (APKPure / Aptoide)? ====
 +
 +Report directly to the store's abuse channel; also email CERT-In at [email protected]. These stores' takedowns are slower but possible. Always prefer the official Play Store / App Store.
 +
 +==== Do I need to file a police FIR? ====
 +
 +Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. You can file online at [[https://cybercrime.gov.in|cybercrime.gov.in]] or at your nearest cyber crime police station. See [[cyber-crime-complaint-india|complete cyber crime complaint guide]] and [[file-cybercrime-complaint-2026|how to file a cybercrime complaint in 2026]].
 +
 +==== What if the bank refuses to refund after a fake app fraud? ====
 +
 +Escalate in this order: (1) bank's internal grievance redressal, (2) Banking Ombudsman under RB-IOS 2021 — see [[banking-ombudsman-complaint-guide-india|Banking Ombudsman guide]], (3) [[bank-refused-cyber-fraud-refund-zero-liability-india|what to do when bank refuses cyber fraud refund]]. Cite RBI Master Direction 2017 zero-liability provision if you reported within 3 working days.
 +
 +==== Are fake loan apps also covered here? ====
 +
 +Yes — fake loan apps are a major category. They harvest contacts, access gallery, and blackmail borrowers. Report them the same way (Play Store flag + CERT-In + cybercrime.gov.in). See [[fake-loan-approval-scam|fake loan approval scam]] for specific guidance.
 +
 +==== Can fake apps steal my data even without banking access? ====
 +
 +Yes. Fake apps can harvest contacts, SMS history, call logs, location, photos, and clipboard data. This data is sold on the dark web or used for targeted phishing. Uninstall immediately and change passwords for all accounts that shared the same credentials. See [[fake-app-installed-phone-removal-bank-india|fake app removal guide]].
 +
 +==== What is Google Play Protect and does it help? ====
 +
 +Google Play Protect is Google's built-in malware scanner that scans all installed apps daily. It catches known malware signatures but may miss brand-new lookalike apps for 24-72 hours. Enable it at Settings → Google → Security → Play Protect. It is a safety net, **not** a replacement for manual developer-name verification.
 +
 +==== How do I report a fake app that is spreading via WhatsApp? ====
 +
 +Forward the message (without clicking any links) to PIB Fact Check at WhatsApp **+91-8799711259** or submit at [[https://factcheck.pib.gov.in|factcheck.pib.gov.in]]. Also report the WhatsApp number to [[https://cybercrime.gov.in|cybercrime.gov.in]]. See also [[whatsapp-otp-fraud-explained-india|WhatsApp OTP fraud explained]] and [[report-scam-call-number-2026|how to report scam calls/numbers]].
 +
 +==== Can I check if my SIM is being misused after a fake app installation? ====
 +
 +Yes — visit [[https://tafcop.sancharsaathi.gov.in|tafcop.sancharsaathi.gov.in]] to check all mobile connections issued in your name. See [[check-sim-misuse-tafcop-2026|how to check SIM misuse via Tafcop]] and [[nine-sim-card-limit-per-person-telecom-act-section-42|9 SIM card limit under Telecom Act]].
 +
 +===== Myth vs reality =====
 +
 +^ Myth ^ Reality ^
 +| "Play Store apps are safe." | Lookalike apps occasionally pass review; the safe path is the bank's website link. |
 +| "Five-star ratings = real." | Burst five-star ratings are a fake-app signal, not authenticity. |
 +| "Only banking apps are cloned." | IRCTC, Income Tax, EPFO, UIDAI, RBI, scholarship portals are all impersonated. |
 +| "Reporting won't matter; Google ignores it." | Google's brand-protection takedown is among the fastest in tech — typically 24-48 h. |
 +| "If I don't install, I'm safe." | True for you; but the listing is harvesting other victims — report it. |
 +| "Google Play Protect catches all fake apps." | Play Protect catches known malware; brand-new lookalike apps may slip through for 24-72 hours. |
 +| "Only tech-illiterate people fall for fake apps." | Even savvy users have been fooled by near-perfect clones; the verification habit matters more than tech skill. |
 +| "If I uninstall the fake app, the danger is over." | Not necessarily — credentials may already be exfiltrated. Change all passwords from another device and monitor bank statements for 30 days. |
 +
 +{{tag>aadhaar epf epfo pf rti report fake mobile}}