A new banking scam is putting a fresh warning in front of Indian smartphone users. Cybercriminals are reportedly using fake banking websites and malicious Android apps to impersonate trusted banks, collect sensitive information and potentially gain access to victims’ phones.
The Indian Cyber Crime Coordination Centre (I4C) has now taken action against this growing threat and directed Google to remove at least 57 websites and databases hosted on Firebase in August alone. Some of the flagged websites reportedly mimicked major banks including SBI, ICICI Bank and Axis Bank.
How Does This Scam Work?
The scam usually starts with a message, link or attractive offer.
You may receive a message claiming:
Your credit card limit has been increased
Your bank reward points are expiring
You can redeem cashback or rewards
You need to update your banking app
You are eligible for a government payment or benefit
The message then directs you to a website or asks you to download an app.
The website may look almost identical to a genuine banking platform. The fake app may also use the bank's name, logo and branding to appear legitimate.
Once installed, malicious software can potentially access sensitive information from the device and send it to criminals. Government notices reportedly identified attempts to collect information such as credit-card details and OTPs.
Why Is This Scam Different?
The biggest problem is that scammers are not always using obviously suspicious websites.
Authorities found that criminals were allegedly misusing Google Firebase, a legitimate platform used by developers to build and host applications and websites.
The issue is not that Firebase itself is fraudulent. Instead, cybercriminals are allegedly abusing legitimate digital infrastructure to support phishing pages, malicious apps and databases used to collect stolen information.
This makes the scam harder for ordinary users to identify.
Even Government Schemes Can Be Used as Bait
The scam is not limited to banking.
One reported campaign allegedly used PM-KISAN as bait, telling users they could claim or receive their payment by downloading an application.
Once installed, the malicious app could allegedly transmit information from the victim's phone to infrastructure controlled by scammers.
This shows why you should never assume a message is genuine simply because it mentions a government scheme, bank or financial benefit.
What Is the Government Doing?
The I4C, under the Ministry of Home Affairs, has been working with technology platforms to identify and remove digital infrastructure linked to cybercrime.
In August 2026, authorities directed Google to take down at least 57 Firebase-hosted websites and databases linked to the reported scam activity. Google has said it has policies prohibiting phishing, malware and financial fraud and works with law-enforcement agencies on such cases.
The action highlights an important shift: authorities are increasingly targeting not only scammers and bank accounts, but also the online infrastructure used to operate scams.
7 Things You Should Never Do
1. Never download a banking app from a message link
Use your bank's official website or your phone's trusted app store instead.
2. Don't click “reward” or “limit upgrade” links blindly
An offer that sounds too good to be true may be designed to make you act quickly.
3. Never share your OTP
Your OTP is meant to authorise a transaction or login. No genuine bank employee should ask you to reveal it.
4. Don't install unknown APK files
A file sent through WhatsApp, SMS, Telegram or email can potentially contain malicious software.
5. Check the website carefully
Look for suspicious spellings, unusual domains and unexpected login pages.
6. Don't give unnecessary permissions
Be especially careful if an unfamiliar app asks for access to SMS, contacts, accessibility features, notifications or other sensitive phone functions.
7. Verify before you act
If a message claims to be from your bank, open the bank's official app yourself and check there. Don't use the link provided in the message.
What If You Already Installed a Suspicious App?
Don't ignore it.
Disconnect the phone from the internet if you suspect malicious activity, remove the suspicious application where possible, and contact your bank through its official customer-service channel.
Also change important passwords from a clean, trusted device and monitor your bank and card accounts for unusual activity.
If money has already been lost, report the incident to the appropriate cybercrime authorities and your bank as quickly as possible.
Why This Matters to Every Indian
India's rapid shift toward digital banking and payments has made everyday financial transactions easier, but it has also created a larger target for cybercriminals.
The government has reported significant cyber-fraud losses in recent years, while authorities are increasingly using technology and financial-sector coordination to disrupt fraud networks.
The important lesson is simple:
A website can look real. An app can look real. A message can look real. That does not make it genuine.
Before entering your bank details, OTP, card information or personal information, take a few seconds to verify where the request actually came from.
Stay Alert. Verify First. Pay Later.
In the digital age, your biggest financial-security tool may not be another app or feature.
It may simply be pausing before you click “Install” or “Login.”
Source: Reuters, Business Standard, Ministry of Home Affairs/I4C reporting, August 2026.
