Differences
This shows you the differences between two versions of the page.
| — | report-fake-mobile-apps-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== How to Report Fake Mobile Apps in India (Play Store, MeitY, CERT-In, 2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** Complete 2026 guide to report fake mobile apps in India — fake SBI YONO, IRCTC, Income Tax, EPFO, BHIM, mAadhaar apps. Step-by-step reporting to Google Play, CERT-In, MeitY, cybercrime.gov.in. Legal... | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | |||
| + | <note important> | ||
| + | This page is maintained by the **RTI Wiki Citizen Crisis Response Network** and reviewed against official sources: | ||
| + | * **CERT-In** ([[https:// | ||
| + | * **Ministry of Electronics and Information Technology (MeitY)** ([[https:// | ||
| + | * **National Cyber Crime Reporting Portal** ([[https:// | ||
| + | * **Press Information Bureau Fact Check** ([[https:// | ||
| + | * **Reserve Bank of India** ([[https:// | ||
| + | **Last reviewed**: July 2026 · **Sources verified**: 12+ government and regulatory references · **Legal accuracy checked** against IT Act 2000, BNS, 2023, RBI Master Directions. | ||
| + | </ | ||
| + | |||
| + | Fake clones of SBI YONO, IRCTC Rail Connect, Income Tax Faceless, EPFO Passbook, BHIM, mAadhaar — uploaded to the Play Store under near-identical names — are how millions of Indians lose money in 2026. This page is the **operational reporting playbook**: how to detect a fake app in 30 seconds, how to report to Google + MeitY + CERT-In so it's taken down in 48 hours, and how to recover if you've already installed one. | ||
| + | |||
| + | > **Citizen Crisis Response Network — install rule**\\\\ Always download from the **bank / agency' | ||
| + | |||
| + | ===== Direct answer (featured snippet) ===== | ||
| + | |||
| + | To report a fake mobile app in India: (1) inside Play Store, tap the app → **⋮** → **Report**, (2) report at [[https:// | ||
| + | |||
| + | If you have already installed a suspicious app, follow the [[fake-app-installed-phone-removal-bank-india|fake app removal and bank protection guide]] immediately. If money has already been debited, see [[recover-money-upi-fraud-2026|how to recover money lost to UPI fraud]] and call **1930** within the golden hour — see [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]]. | ||
| + | |||
| + | ===== In this guide ===== | ||
| + | |||
| + | * [[#How fake apps reach Play Store|How fake apps reach Play Store]] | ||
| + | * [[#Spot a fake app in 30 seconds|Spot a fake app in 30 seconds]] | ||
| + | * [[#What Types of Fake Mobile Apps Are Most Common in India|What types of fake apps are most common]] | ||
| + | * [[#How Does Fake App Malware Steal Your Money|How fake app malware steals your money]] | ||
| + | * [[#Report to Google Play|Report to Google Play]] | ||
| + | * [[#Report to CERT-In + MeitY|Report to CERT-In + MeitY]] | ||
| + | * [[#Which Government Authority Should You Report a Fake App To|Which authority should you report to]] | ||
| + | * [[#Report to the impersonated brand|Report to the impersonated brand]] | ||
| + | * [[#The 30-minute drill if you installed|The 30-minute drill if you installed]] | ||
| + | * [[#What Legal Protections Exist Against Fake App Fraud|What legal protections exist]] | ||
| + | * [[#How Can Senior Citizens Stay Safe from Fake Apps|How senior citizens can stay safe]] | ||
| + | * [[#What Happens After You Report a Fake App|What happens after you report]] | ||
| + | * [[#What not to do|What not to do]] | ||
| + | * [[#Sample report email|Sample report email]] | ||
| + | * [[#Can compensation be claimed|Can compensation be claimed]] | ||
| + | * [[# | ||
| + | |||
| + | ===== How fake apps reach Play Store ===== | ||
| + | |||
| + | Three routes: | ||
| + | |||
| + | - **Lookalike upload** — A new developer account uploads "SBI YONO Bank Online" | ||
| + | - **Repackaged genuine app** — The developer downloads the real APK, repackages it with a trojan, and uploads under a similar name. | ||
| + | - **Sideloaded only** — Some attackers don't bother with Play Store; the link is shared on WhatsApp / SMS. See [[fake-apk-installation-scam-india|fake APK installation scam]]. | ||
| + | |||
| + | The two ways to defeat all three: (a) install only via the bank's website link to the store, and (b) verify the developer name on the store listing. | ||
| + | |||
| + | ===== Spot a fake app in 30 seconds ===== | ||
| + | |||
| + | | Check | Real app | Fake app | | ||
| + | | **Developer name** | Exact bank / agency (e.g., "State Bank of India" | ||
| + | | **Install count** | Crores / lakhs | Hundreds / few thousand | | ||
| + | | **Reviews** | Old, mixed, organic | Five-star burst, generic phrasing | | ||
| + | | **Permissions** | Bank-specific minimum | Accessibility, | ||
| + | | **Description language** | Polished | Typos, broken grammar | | ||
| + | | **Update history** | Years long | One or two recent updates | | ||
| + | | **Privacy policy URL** | Official bank domain | Random `.in` / `.online` | | ||
| + | | **Listed website** | Bank's official site | Generic / dead link | | ||
| + | |||
| + | If even **one** check fails, do not install. Verify by visiting the **bank' | ||
| + | |||
| + | ===== What Types of Fake Mobile Apps Are Most Common in India? ===== | ||
| + | |||
| + | Fake app impersonation in India targets six primary categories. Knowing which category a suspect app falls into helps you report to the right authority faster: | ||
| + | |||
| + | * **Banking & payment apps** — Fake SBI YONO, HDFC MobileBanking, | ||
| + | * **Government service apps** — Fake IRCTC Rail Connect, Income Tax e-filing, EPFO mobile app, mAadhaar, DigiLocker, CoWIN. Attackers exploit trust in government branding. Report these additionally to [[https:// | ||
| + | * **Investment & trading apps** — Fake stock broking apps, fake mutual fund apps, fake crypto exchange apps. See [[fake-trading-app-withdrawal-blocked-cyber-crime-money-recovery|fake trading app recovery]] and [[fake-mutual-fund-advisor-scam-india|fake mutual fund advisor scam]]. | ||
| + | * **Loan apps** — Predatory fake loan apps that harvest contacts and blackmail borrowers. See [[fake-loan-approval-scam|fake loan approval scam]]. | ||
| + | * **Lottery & prize apps** — Fake KBC / lottery apps that demand processing fees. See [[fake-lottery-scam-india|fake lottery scam]] and [[kbc-scam-india-explained|KBC scam explained]]. | ||
| + | * **Customer care & support apps** — Fake " | ||
| + | |||
| + | In Q1 2026, the Ministry of Home Affairs' | ||
| + | |||
| + | ===== How Does Fake App Malware Steal Your Money? ===== | ||
| + | |||
| + | Understanding the attack chain helps you know **what to check** after installing a suspicious app. Most fake banking / government app trojans follow a five-step pattern: | ||
| + | |||
| + | * **Step 1 — Permission harvest**: The app requests Accessibility Service, SMS read, Contacts, and " | ||
| + | * **Step 2 — OTP interception**: | ||
| + | * **Step 3 — Screen overlay**: Accessibility Service lets the trojan draw invisible overlays on top of legitimate banking apps, capturing login credentials as the user types them. | ||
| + | * **Step 4 — Credential exfiltration**: | ||
| + | * **Step 5 — Fund transfer**: The attacker logs into the victim' | ||
| + | |||
| + | This is why **airplane mode + password change from another device** within the first 30 minutes is critical. If SMS permission was already granted, assume **every OTP sent in the last 48 hours was intercepted**. For the full response, see [[scammed-on-upi-recovery-steps|UPI fraud recovery steps]] and [[freeze-account-after-fraud-bank-process|how to freeze your bank account after fraud]]. | ||
| + | |||
| + | > **SIM swap risk** — Some fake apps also attempt SIM swap fraud by harvesting your telecom KYC details. If your SIM suddenly loses signal, see [[sim-swap-fraud-recovery|SIM swap fraud recovery]] immediately. | ||
| + | |||
| + | ===== Report to Google Play ===== | ||
| + | |||
| + | - Open the suspect app's listing in **Play Store** (Android device or play.google.com on web) | ||
| + | - Tap **⋮ More options** → **Flag as inappropriate** | ||
| + | - Choose category: //" | ||
| + | - Add a short description with reasons + screenshots | ||
| + | - For deeper reports: [[https:// | ||
| + | - Trademark holders (i.e., the **real bank**) get faster takedown via Google' | ||
| + | |||
| + | Google generally responds within 24-48 hours for clear impersonation. | ||
| + | |||
| + | ===== Report to CERT-In + MeitY ===== | ||
| + | |||
| + | - **CERT-In Incident Reporting**: | ||
| + | - Email: **[email protected]** (PGP key on site) | ||
| + | - Phone: **+91-1800-11-4949** (toll-free) | ||
| + | - Include: Play Store URL, developer name, date of detection, screenshots, | ||
| + | - Cite **CERT-In Cyber Security Directions, 2022** which obligates Indian platforms to retain logs for 180 days — available at [[https:// | ||
| + | - **MeitY Cyber Coordination Centre (I4C)**: [[https:// | ||
| + | - For sustained / large-scale impersonation, | ||
| + | |||
| + | CERT-In confirms incident receipt + ticket number; coordinates takedown with platform. | ||
| + | |||
| + | ===== Which Government Authority Should You Report a Fake App To? ===== | ||
| + | |||
| + | Multiple government bodies handle different aspects of fake app fraud. Filing with the **right authority** speeds up resolution. Use this comparison table to decide: | ||
| + | |||
| + | | Reporting channel | What they do | When to use | Response time | URL | | ||
| + | | **Google Play (Flag)** | Removes the listing from Play Store | Always — first step for any fake app on Play Store | 24-72 hours | play.google.com | | ||
| + | | **CERT-In** | Technical incident tracking, coordinates with platforms | Always — for any malware / impersonation incident | Ticket within 24h | [[https:// | ||
| + | | **National Cyber Crime Portal (I4C)** | Police-grade cyber crime complaint, fund freeze | If money has been lost or credentials stolen | Immediate (1930 hotline) | [[https:// | ||
| + | | **MeitY** | Policy intervention, | ||
| + | | **PIB Fact Check** | Public advisory / misinformation debunking | If fake app is spreading via WhatsApp / social media | 24-48 hours | [[https:// | ||
| + | | **RBI Sachet** | Suspicious entity reporting, bank-level escalation | If a bank or NBFC is being impersonated | Variable | [[https:// | ||
| + | | **Impersonated brand** | Trademark takedown via legal team | Always — forward the Play Store URL + screenshots | 24-72 hours | Brand' | ||
| + | | **Local police (FIR)** | Criminal investigation, | ||
| + | |||
| + | > **Tip** — If you're unsure whether to file at the cyber crime portal or go to the police station directly, read [[cybercrime-portal-vs-police-station-india|cybercrime portal vs police station]] and [[file-cybercrime-complaint-2026|how to file a cybercrime complaint in 2026]]. | ||
| + | |||
| + | ===== Report to the impersonated brand ===== | ||
| + | |||
| + | Most banks / agencies have dedicated " | ||
| + | * **SBI** — [email protected] | ||
| + | * **HDFC Bank** — [email protected] | ||
| + | * **ICICI Bank** — [email protected] | ||
| + | * **Axis Bank** — [email protected] | ||
| + | * **PNB** — [email protected] | ||
| + | * **RBI** — [[https:// | ||
| + | * **IRCTC** — [email protected] | ||
| + | * **Income Tax** — [email protected] (official site: [[https:// | ||
| + | * **EPFO** — [email protected] (official site: [[https:// | ||
| + | * **UIDAI** — [email protected] (official site: [[https:// | ||
| + | |||
| + | Forward the Play Store URL + screenshots. The brand' | ||
| + | |||
| + | If you are a **banking customer** whose money was stolen via a fake app, escalate using the [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]] if the bank stalls on refund. See also [[bank-refused-cyber-fraud-refund-zero-liability-india|what to do when a bank refuses a cyber fraud refund]]. | ||
| + | |||
| + | ===== The 30-minute drill if you installed ===== | ||
| + | |||
| + | If you have installed a suspect app and entered banking credentials: | ||
| + | - **Airplane mode** the device immediately | ||
| + | - From **another device**: | ||
| + | * Change net-banking password | ||
| + | * Block debit card | ||
| + | * De-register UPI on every UPI app | ||
| + | * Change email password + revoke sessions | ||
| + | - **Uninstall** the suspect app; revoke Accessibility / Notification access | ||
| + | - **Factory reset** as in [[fake-apk-installation-scam-india|fake APK scam playbook]] and [[fake-app-installed-phone-removal-bank-india|fake app removal guide]] | ||
| + | - **1930** + [[https:// | ||
| + | - **Bank email** invoking RBI Master Direction 2017 within 24 hours | ||
| + | - **CERT-In** report ([email protected]) with details | ||
| + | |||
| + | For the full step-by-step after installing a fake app, read [[fake-app-installed-phone-removal-bank-india|what to do if you installed a fake app]]. If your bank account has been frozen after fraud, see [[bank-freeze-cyber-fraud-india|bank account freeze after cyber fraud]]. | ||
| + | |||
| + | ===== What Legal Protections Exist Against Fake App Fraud in India? ===== | ||
| + | |||
| + | Multiple Indian laws apply to fake mobile app fraud. Understanding your legal rights strengthens your complaint and compensation claim: | ||
| + | |||
| + | * **IT Act 2000, Section 66C** — Identity theft (using another' | ||
| + | * **IT Act 2000, Section 66D** — Cheating by personation by means of any communication device or computer resource. Punishable up to 3 years + ₹1 lakh fine. | ||
| + | * **IT Act 2000, Section 69A** — Power to issue directions for blocking public access to any information through any computer resource. This is the legal basis for government-ordered app takedowns. | ||
| + | * **IT Act 2000, Section 70B** — Designates CERT-In as the national nodal agency for cyber incident response. See [[https:// | ||
| + | * **BNS, 2023, Section 316** — Cheating by personation. Replaces IPC Section 416. | ||
| + | * **BNS, 2023, Section 319** — Cheating. Replaces IPC Section 415–418. | ||
| + | * **BNS, 2023, Sections 336–338** — Forgery of valuable security / will, etc. | ||
| + | * **Trade Marks Act 1999** — The impersonated brand can sue for trademark infringement and passing off. | ||
| + | * **CERT-In Cyber Security Directions, 2022** — Obligates all intermediaries to report cyber incidents within 6 hours and maintain logs for 180 days. Available at [[https:// | ||
| + | * **RBI Master Direction on Fraud — Reporting and Classification, | ||
| + | * **Digital Personal Data Protection Act, 2023** — Impersonation apps that harvest personal data without consent violate this Act. MeitY is the implementing ministry ([[https:// | ||
| + | |||
| + | > **Reporting tip** — When filing at [[https:// | ||
| + | |||
| + | ===== How Can Senior Citizens and Vulnerable Users Stay Safe from Fake Apps? ===== | ||
| + | |||
| + | Senior citizens are disproportionately targeted by fake app scammers because they may be less familiar with app-store verification. The following precautions are essential: | ||
| + | |||
| + | * **Never search and install** — Always have a family member send the official Play Store / App Store link from the bank's website. | ||
| + | * **Enable Google Play Protect** — Settings → Google → Security → Play Protect → turn on "Scan apps with Play Protect." | ||
| + | * **Disable " | ||
| + | * **Do not share OTP over phone** — No bank or government agency will ever ask for an OTP. If someone calls claiming to be from SBI / IRCTC / Income Tax and asks for an OTP, it is a scam. See [[fake-customer-care-number-scam-india|fake customer care number scam]]. | ||
| + | * **Beware of " | ||
| + | * **Use the 1930 helpline** — If something seems wrong, call **1930** immediately. See [[1930-helpline-cyber-fraud-script|what to say when calling 1930]]. | ||
| + | * **Register on Tafcop** — Check if extra SIM cards have been issued in your name at [[https:// | ||
| + | |||
| + | > **For families** — Sit with elderly parents and **delete** any app they didn't install from a bank's official website link. Set up [[https:// | ||
| + | |||
| + | ===== What Happens After You Report a Fake App? ===== | ||
| + | |||
| + | Understanding the post-report timeline helps you track progress and escalate if needed: | ||
| + | |||
| + | * **0-24 hours** — Google Play's automated review flags the reported listing. CERT-In issues an incident ticket number via email. If you called **1930**, the helpline coordinates with your bank's nodal officer to freeze suspicious transactions in real time. | ||
| + | * **24-72 hours** — Google Play removes the listing if impersonation is confirmed. CERT-In coordinates with the platform' | ||
| + | * **3-7 days** — CERT-In may issue a public advisory if multiple fake listings of the same app family are detected. PIB Fact Check publishes a debunking notice at [[https:// | ||
| + | * **7-30 days** — Cyber crime police investigation (if a formal complaint was filed at [[https:// | ||
| + | * **30+ days** — If the developer is identified, criminal proceedings under IT Act / BNS may follow. For ongoing status, you can file an RTI — see [[rti-for-cybercrime-complaint-status|how to check cybercrime complaint status via RTI]]. | ||
| + | |||
| + | > **Escalation paths** — If Google ignores your report, escalate via CERT-In. If CERT-In is slow, escalate via MeitY ([[https:// | ||
| + | |||
| + | ===== What not to do ===== | ||
| + | |||
| + | * Do **not** install from Play Store search results without checking the developer name. | ||
| + | * Do **not** install banking / government APKs from anywhere except the verified Play Store / App Store link on the brand' | ||
| + | * Do **not** grant Accessibility / SMS / install-other-apps permission to any non-essential app. | ||
| + | * Do **not** rate / review a fake app even to "warn others" | ||
| + | * Do **not** delay reporting — every additional day means more victims. | ||
| + | * Do **not** use the same password after a suspected fake app installation — assume it is compromised. | ||
| + | |||
| + | ===== Sample report email ===== | ||
| + | |||
| + | < | ||
| + | To: [email protected] | ||
| + | Cc: [bank' | ||
| + | |||
| + | Subject: Impersonation app on Google Play targeting [Bank / Agency] | ||
| + | customers — request for takedown coordination | ||
| + | |||
| + | Sir / Madam, | ||
| + | |||
| + | I report the following impersonation app currently live on Google Play | ||
| + | Store, targeting customers of [Brand / Bank Name]: | ||
| + | |||
| + | Play Store URL : ___ | ||
| + | App name : ___ | ||
| + | Developer name : ___ | ||
| + | Install count : ___ | ||
| + | Detection date : ___ | ||
| + | Permissions of concern : Accessibility, | ||
| + | |||
| + | Attached: | ||
| + | 1. Screenshots of the listing | ||
| + | 2. Permissions screenshot | ||
| + | 3. APK hash (if extractable): | ||
| + | 4. Comparison with the genuine app | ||
| + | |||
| + | Cited authority: | ||
| + | - CERT-In Cyber Security Directions, 2022 | ||
| + | - IT Act 2000 §66C, §66D, §69A (blocking) | ||
| + | - BNS, 2023 §316 (personation), | ||
| + | - Trade Marks Act 1999 (where the brand is registered) | ||
| + | |||
| + | I request CERT-In to: | ||
| + | a) Coordinate takedown with Google Play and the affected brand. | ||
| + | b) Issue a public advisory if multiple impersonation listings exist. | ||
| + | c) Confirm the takedown date in writing. | ||
| + | |||
| + | Yours faithfully, | ||
| + | [Signature, Name, Date, Phone, Email] | ||
| + | </ | ||
| + | |||
| + | ===== Can compensation be claimed? ===== | ||
| + | |||
| + | * **Bank refund** — RBI Master Direction 2017 (zero liability if reported within 3 working days). See [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]] and [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation framework]]. | ||
| + | * **Banking Ombudsman** — RB-IOS 2021 if bank stalls. See [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]]. | ||
| + | * **Consumer court** — for app-platform negligence (Google / Apple) — emerging jurisprudence | ||
| + | * **CERT-In compliance penalties** on platforms that don't take down; complaint via [[https:// | ||
| + | * **Civil suit** against fake-app developer if traceable | ||
| + | * **Chargeback** — If you paid via credit/ | ||
| + | |||
| + | ===== What to do in the next 30 minutes (printable card) ===== | ||
| + | |||
| + | - **0-5 min** — If installed: airplane mode + change passwords from another device | ||
| + | - **5-15 min** — Report on Play Store (⋮ → Flag); report to bank's anti-phishing email | ||
| + | - **15-25 min** — File at CERT-In + [[https:// | ||
| + | - **25-30 min** — Forward to PIB Fact Check + amplify on social media (with screenshots, | ||
| + | - **+24 h** — Bank's " | ||
| + | - **+72 h** — Confirm takedown via Play Store / CERT-In ticket | ||
| + | |||
| + | ===== Reporting channels comparison table ===== | ||
| + | |||
| + | | Feature | Google Play Flag | CERT-In | cybercrime.gov.in / 1930 | MeitY | PIB Fact Check | | ||
| + | | **Purpose** | Remove listing | Technical incident tracking | Criminal complaint + fund freeze | Policy / blocking order | Public misinformation debunk | | ||
| + | | **Who can file** | Anyone | Anyone | Victim or proxy | Brand / government | Anyone | | ||
| + | | **Requires account?** | Google account | No | Phone + OTP | Email | WhatsApp / web form | | ||
| + | | **Best for** | Quick takedown | Evidence trail | Money recovery | Large-scale impersonation | Warning the public | | ||
| + | | **Gov.in URL** | — | [[https:// | ||
| + | | **Typical response** | 24-72 h | Ticket in 24 h | Immediate (1930) | 7-15 days | 24-48 h | | ||
| + | |||
| + | ===== Long-tail keywords this page targets ===== | ||
| + | |||
| + | report fake app India 2026, fake SBI YONO Play Store, fake IRCTC app takedown, fake Income Tax app report, CERT-In incident reporting, MeitY app takedown, fake EPFO Play Store, lookalike app Play Store, fake banking app trojan, fake mAadhaar app, fake BHIM app report, how to report fake app on Play Store India, fake government app India, cybercrime.gov.in fake app complaint, Section 69A app blocking India, RBI zero liability fake app fraud | ||
| + | |||
| + | ===== Internal cross-links ===== | ||
| + | |||
| + | * [[fake-apk-installation-scam-india|Fake APK installation scam]] | ||
| + | * [[fake-kyc-update-scam-india|Fake KYC update scam]] | ||
| + | * [[fake-aadhaar-update-website-fraud|Fake Aadhaar update fraud]] | ||
| + | * [[scammed-on-upi-recovery-steps|UPI fraud recovery]] | ||
| + | * [[block-lost-stolen-sim-card-india|Block lost / stolen SIM]] | ||
| + | * [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]] | ||
| + | * [[fake-app-installed-phone-removal-bank-india|Fake app installed — removal and bank protection]] | ||
| + | * [[recover-money-upi-fraud-2026|Recover money lost to UPI fraud (2026)]] | ||
| + | * [[golden-hour-zero-liability-cyber-fraud-rbi-india|RBI golden hour zero-liability rule]] | ||
| + | * [[cyber-crime-complaint-india|Complete cyber crime complaint guide]] | ||
| + | * [[file-cybercrime-complaint-2026|File a cybercrime complaint in 2026]] | ||
| + | * [[cybercrime-portal-vs-police-station-india|Cybercrime portal vs police station]] | ||
| + | * [[1930-helpline-cyber-fraud-script|What to say when calling 1930]] | ||
| + | * [[fake-customer-care-number-scam-india|Fake customer care number scam]] | ||
| + | * [[bank-refused-cyber-fraud-refund-zero-liability-india|Bank refused cyber fraud refund]] | ||
| + | * [[bank-freeze-cyber-fraud-india|Bank account freeze after cyber fraud]] | ||
| + | * [[freeze-account-after-fraud-bank-process|Freeze account after fraud — bank process]] | ||
| + | * [[digital-arrest-scam-india|Digital arrest scam]] | ||
| + | * [[sim-swap-fraud-recovery|SIM swap fraud recovery]] | ||
| + | * [[rbi-digital-fraud-compensation-25000-2026|RBI ₹25,000 digital fraud compensation]] | ||
| + | * [[rti-for-cybercrime-complaint-status|RTI for cybercrime complaint status]] | ||
| + | * [[fake-trading-app-withdrawal-blocked-cyber-crime-money-recovery|Fake trading app recovery]] | ||
| + | * [[fake-mutual-fund-advisor-scam-india|Fake mutual fund advisor scam]] | ||
| + | * [[fake-loan-approval-scam|Fake loan approval scam]] | ||
| + | * [[fake-lottery-scam-india|Fake lottery scam]] | ||
| + | * [[cyber-fraud-chargeback-visa-mastercard-rupay-india|Visa/ | ||
| + | * [[check-sim-misuse-tafcop-2026|Check SIM misuse via Tafcop]] | ||
| + | * [[report-scam-call-number-2026|How to report a scam call/ | ||
| + | * [[how-to-report-fake-social-media-profiles-india|Report fake social media profiles]] | ||
| + | * [[ai-deepfake-content-labelling-rules-india-2026|AI deepfake content labelling rules]] | ||
| + | |||
| + | ===== Government & authority references ===== | ||
| + | |||
| + | * **CERT-In** — [[https:// | ||
| + | * **MHA — Indian Cyber Crime Coordination Centre (I4C)** — [[https:// | ||
| + | * **MeitY — Ministry of Electronics and Information Technology** — [[https:// | ||
| + | * **PIB Fact Check** — [[https:// | ||
| + | * **RBI Sachet** — [[https:// | ||
| + | * **UIDAI** — [[https:// | ||
| + | * **Income Tax Department** — [[https:// | ||
| + | * **EPFO** — [[https:// | ||
| + | * **Tafcop (Sanchar Saathi)** — [[https:// | ||
| + | * **IT Act 2000** §66C, §66D, §69A (blocking), §70B (CERT-In powers) | ||
| + | * **BNS, 2023** §316 (personation), | ||
| + | * **Trade Marks Act 1999** — for branded-app impersonation | ||
| + | * **CERT-In Cyber Security Directions, 2022** — incident reporting within 6 hours, 180-day log retention | ||
| + | * **Digital Personal Data Protection Act, 2023** — consent and data protection for impersonation apps | ||
| + | * **RBI Master Direction on Fraud, 2017** — zero-liability framework for unauthorised electronic transactions | ||
| + | |||
| + | ===== FAQ ===== | ||
| + | |||
| + | ==== How do I find the genuine app's developer name? ==== | ||
| + | |||
| + | Visit the **bank / agency' | ||
| + | * SBI YONO → developer: "State Bank of India" → listed at sbi.co.in | ||
| + | * IRCTC Rail Connect → developer: "IRCTC Official" | ||
| + | * mAadhaar → developer: " | ||
| + | |||
| + | ==== Should I rate the fake app 1-star to warn others? ==== | ||
| + | |||
| + | No — engagement signals (any rating) help the listing rank. Just report and silently move on. | ||
| + | |||
| + | ==== Can I report multiple fake apps in one email to CERT-In? ==== | ||
| + | |||
| + | Yes — list each with its Play Store URL and developer. CERT-In assigns one ticket but coordinates takedown of all listings. | ||
| + | |||
| + | ==== What about fake apps in third-party stores (APKPure / Aptoide)? ==== | ||
| + | |||
| + | Report directly to the store' | ||
| + | |||
| + | ==== Do I need to file a police FIR? ==== | ||
| + | |||
| + | Recommended if money has moved. The FIR strengthens the bank's refund case and the takedown record. You can file online at [[https:// | ||
| + | |||
| + | ==== What if the bank refuses to refund after a fake app fraud? ==== | ||
| + | |||
| + | Escalate in this order: (1) bank's internal grievance redressal, (2) Banking Ombudsman under RB-IOS 2021 — see [[banking-ombudsman-complaint-guide-india|Banking Ombudsman guide]], (3) [[bank-refused-cyber-fraud-refund-zero-liability-india|what to do when bank refuses cyber fraud refund]]. Cite RBI Master Direction 2017 zero-liability provision if you reported within 3 working days. | ||
| + | |||
| + | ==== Are fake loan apps also covered here? ==== | ||
| + | |||
| + | Yes — fake loan apps are a major category. They harvest contacts, access gallery, and blackmail borrowers. Report them the same way (Play Store flag + CERT-In + cybercrime.gov.in). See [[fake-loan-approval-scam|fake loan approval scam]] for specific guidance. | ||
| + | |||
| + | ==== Can fake apps steal my data even without banking access? ==== | ||
| + | |||
| + | Yes. Fake apps can harvest contacts, SMS history, call logs, location, photos, and clipboard data. This data is sold on the dark web or used for targeted phishing. Uninstall immediately and change passwords for all accounts that shared the same credentials. See [[fake-app-installed-phone-removal-bank-india|fake app removal guide]]. | ||
| + | |||
| + | ==== What is Google Play Protect and does it help? ==== | ||
| + | |||
| + | Google Play Protect is Google' | ||
| + | |||
| + | ==== How do I report a fake app that is spreading via WhatsApp? ==== | ||
| + | |||
| + | Forward the message (without clicking any links) to PIB Fact Check at WhatsApp **+91-8799711259** or submit at [[https:// | ||
| + | |||
| + | ==== Can I check if my SIM is being misused after a fake app installation? | ||
| + | |||
| + | Yes — visit [[https:// | ||
| + | |||
| + | ===== Myth vs reality ===== | ||
| + | |||
| + | ^ Myth ^ Reality ^ | ||
| + | | "Play Store apps are safe." | Lookalike apps occasionally pass review; the safe path is the bank's website link. | | ||
| + | | " | ||
| + | | "Only banking apps are cloned." | ||
| + | | " | ||
| + | | "If I don't install, I'm safe." | True for you; but the listing is harvesting other victims — report it. | | ||
| + | | " | ||
| + | | "Only tech-illiterate people fall for fake apps." | Even savvy users have been fooled by near-perfect clones; the verification habit matters more than tech skill. | | ||
| + | | "If I uninstall the fake app, the danger is over." | Not necessarily — credentials may already be exfiltrated. Change all passwords from another device and monitor bank statements for 30 days. | | ||
| + | |||
| + | {{tag> | ||