Careful With That Link: HDFC Bank Warns Users About APK Scams
As part of APK fraud schemes, scammers often employ social engineering techniques by pretending to be bank representatives or government officials.

HDFC Bank has released an urgent notice cautioning customers about increasing incidence of cyber fraud related to harmful APK (Android package kit) files. This hazardous scam has resulted in data breaches and financial losses nationwide.
As part of APK fraud schemes, scammers often employ social engineering techniques by pretending to be bank representatives or government officials. Targeted individuals receive a harmful APK file that is purportedly from reliable sources, which results in data theft.
How APK Scam Works
Impersonation: Scammers usually pretend to be bank staff, government representatives, or employees of reputable firms under the guise of conducting a Re-KYC, settling traffic fines, or processing income tax refunds.
Fake Link: The victim receives a message that includes a counterfeit APK link.
Malware Installation: As soon as the user clicks on the link, malware is secretly installed on their mobile device. The malware allows the scammer to gain control over the victim’s device.
Unauthorised Transactions: In a matter of minutes, numerous unauthorised financial transactions occur, resulting in financial drainage for the user. Only when users receive notifications from their bank regarding money being withdrawn from their account do they realise they have been cheated.
Safeguarding Against APK Scams
Below are the steps you can take to stay safe from APK scams:
Avoid clicking on unfamiliar links or installing applications/files sent through SMS, email, or social media that purport to be from organisations such as Income Tax Department, RTO, or banking representatives.
Install antivirus or anti-malware software that can identify and prevent malicious files.
Refrain from downloading apps requested over a phone call from an unfamiliar person. Obtain apps solely from reputable stores or websites.
Ensure the authenticity of the messages/emails by checking the official website.
Report any fraudulent or suspicious calls and messages using the Chakshu portal at https://sancharsaathi.gov.in/ or through the Sanchar Saathi mobile application.