Kerala Police Alert: Fake Hospital Apps Draining UPI Funds

OTHER
Whalesbook Logo
AuthorRiya Kapoor|Published at:
Kerala Police Alert: Fake Hospital Apps Draining UPI Funds

The Kerala Police have issued an urgent advisory regarding fraudulent mobile apps masquerading as hospital booking services. Attackers are using manipulated Google search results to trick users into installing malware that steals OTPs and drains linked UPI accounts. Users should exercise extreme caution with app downloads and device permissions.

The Kerala Police have issued a critical warning to the public about a rising cybercrime trend involving fake hospital appointment booking applications. These malicious apps are being used to target individuals seeking healthcare services, resulting in unauthorized access to bank accounts and financial loss via UPI payment systems.

The scam typically begins with manipulated Google search results. Fraudsters often populate these results with fake customer support numbers for various hospitals. When an unsuspecting user calls these numbers, the attackers, posing as hospital administrative staff, persuade the caller to download a specific mobile application file, which is usually sent via WhatsApp. Users are led to believe this is a necessary step for booking their appointment.

Once installed, these files are designed to gain extensive control over the smartphone. The malware is capable of monitoring incoming SMS messages, which allows attackers to intercept one-time passwords, or OTPs, required for financial transactions. A specific focus of this operation is the exploitation of UPI Lite and other low-value transaction services. Because these transactions are often smaller in amount, they frequently bypass standard two-factor authentication measures. This allows scammers to systematically siphon funds from linked bank accounts without triggering immediate bank alerts, making the fraud difficult for victims to detect until significant amounts are missing.

For users and investors, this highlights the necessity of strict digital safety habits. Legitimate medical institutions do not distribute appointment booking software through messaging platforms or unofficial links. To protect financial assets, users should only download applications from official sources like the Google Play Store and avoid clicking on external links from unknown numbers. Furthermore, it is important to deny any request by an application for excessive permissions, particularly access to SMS, notifications, or contact lists.

If a user suspects that a fraudulent application has been installed, they must take immediate action to mitigate the damage. This includes severing the device's internet connection to stop the malware from communicating, contacting their bank immediately to freeze the account, and reporting the incident through the national cybercrime portal by dialing 1930.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.