Lucknow: A Lucknow resident says he lost ₹2 lakh after opening a fake traffic challan APK that reached him on WhatsApp. Police suspect the fraudsters may have had access to his phone for several days.
The victim, Uttam, who lives in Chaudhary Tola in Aliganj, told police the file came from an unknown number on September 6. The sender claimed a challan had been issued in both their names and asked him to open the attachment to check the details. That detail likely made the message feel more genuine. An FIR has been registered at Aliganj police station, and the cyber cell is looking into the APK, the sender’s number and where the money went.

After Uttam opened the file, his phone kept working normally and he noticed nothing wrong. The next day, ₹2 was deducted from one of his credit cards. Because the amount was so small, he didn’t think much of it. Fraudsters sometimes use tiny transactions to test whether a card is active before going for something bigger, though police haven’t said whether that was the case here.
The real trouble came on September 10, when his phone suddenly switched off and wouldn’t restart. He assumed it had developed a fault. It came back on by itself the next day, and that’s when he found four messages showing ₹2 lakh had been withdrawn from his account. He went straight to the Aliganj police. Investigators are now trying to work out how the transactions were authorised, and whether the malicious app interfered with SMS alerts, notifications or other phone functions.
Why APK files are risky
APK, short for Android Package Kit, is simply the format Android uses to install apps, and plenty of legitimate apps use it. The danger begins when people install APKs sent over WhatsApp, SMS or unfamiliar websites without knowing what’s inside. Indian Bank has warned about fake e-challan messages that push users to install unofficial APKs. Such apps can ask for access to contacts, messages and storage, which could expose OTPs or let attackers meddle with banking activity. Police will need forensic evidence to say exactly what this particular file could do.
Not an isolated case

Similar scams have been reported across Uttar Pradesh this month. In Budaun, several people installed an APK posing as an RTO challan file, and more than ₹20,000 was reportedly siphoned off through UPI across four victims. In Varanasi, a man allegedly lost ₹8.50 lakh after downloading a fake e-challan APK. In Sambhal, a political worker’s phone was compromised after he opened a fake e-challan link, and the fraudsters then used his WhatsApp to ask his contacts for money. These are separate cases, and there’s no public evidence they’re linked to one group. What they do show is that fake traffic notices are becoming a favourite bait.
The trick works because it creates urgency and doubt at the same time. Most people can’t immediately tell whether a camera or officer actually recorded a violation, and scammers play on that.
What police are doing
The cyber cell is trying to freeze the stolen amount. Time matters here, since stolen money is often moved quickly through several mule accounts. Investigators are tracing the four transactions and studying the WhatsApp number and the APK itself. If the file contains server details, that could help connect the case to a wider malware network. For now, only the victim’s complaint and the ongoing investigation are confirmed, and neither the exact malware mechanism nor the identities of the fraudsters have been made public.
What you should do
Never install a challan APK that arrives on WhatsApp or SMS, even if it mentions your name or vehicle details. Check any fine only on the official e-challan portal, since genuine traffic authorities don’t ask you to install files sent over WhatsApp. If you notice suspicious activity in your account, tell your bank immediately and report it on 1930.

