Blogs

Fake hospital booking apps threaten UPI accounts, Kerala Police warn


Key Points

  • Fraudsters are using fake hospital contact numbers and WhatsApp messages to persuade people to install malicious Android applications.
  • Compromised phones may expose confidential information and enable unauthorised UPI transactions, including small-value payments.
  • Verify hospital numbers through official sources, avoid unfamiliar APK files and report suspected financial fraud immediately on 1930.

People searching online for hospital appointments or contact numbers are being targeted by fraudsters who impersonate hospital staff and persuade them to install malicious mobile applications, warned on Sunday.

The fraud begins when a person calls a fake hospital contact number found through a Google search. The caller is then contacted by someone posing as a hospital employee and sent an Android application file through WhatsApp, purportedly to book an outpatient appointment.

Advertisement

SUMMIT

National DefTech Summit

National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.

Register Now →

CONFERENCE

Infosec ReimaginedInfosec Reimagined

Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.

Register Now →

CONFERENCE

Digital SenateDigital Senate

Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.

Register Now →

CONFERENCE

CIO PrismCIO Prism

CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.

Register Now →

Once installed, the application can compromise the user’s phone, expose confidential information and enable unauthorised financial transactions, police said.

The warning concerns Android application package (APK) files distributed outside official app stores. Such files can be installed directly on Android phones, but applications obtained from unknown sources can expose users to malware and data theft, according to Google’s guidance.

How the hospital booking scam works

According to police, fraudsters use misleading contact information in Google search results to attract people looking for outpatient appointments at leading hospitals.

After establishing contact, they send an application file through WhatsApp under the pretext of completing an appointment booking or providing a hospital-related service. The application may appear to be connected to a legitimate hospital, but installing it can allow attackers to access sensitive information on the device.

Police warned that one-time passwords (OTPs) and information associated with Unified Payments Interface (UPI) applications could be exposed. Fraudsters may also misuse payment applications such as PhonePe and Google Pay or install additional payment applications without the user’s knowledge.

The warning does not identify the hospitals whose names have been misused or specify how many people have lost money through the scam.

Advertisement

Why UPI Lite users face an additional risk

Police have particularly cautioned people who use UPI Lite, which allows small-value payments without requiring a UPI PIN for every transaction. Under the Reserve Bank of ‘s framework, UPI Lite permits transactions of up to ₹1,000, with a maximum balance of ₹5,000.

The facility does not require additional authentication for individual payments within the applicable limits, although replenishing the balance requires authentication. Police warned users not to ignore repeated unauthorised transactions involving small amounts, particularly those below ₹1,000.

A series of such payments could result in financial losses before the account holder notices suspicious activity. The absence of a PIN requirement for individual UPI Lite payments does not mean that installing a malicious application automatically gives criminals access to the funds. The risk arises when a compromised device or payment application can be misused.

What should users do?

Kerala Police advised people to verify hospital contact numbers through the institution’s official website or verified accounts rather than relying solely on numbers appearing in search results.

“Do not install app files received through WhatsApp for purposes such as appointment booking, KYC or refunds under any circumstances,” police said.

Users should install applications from trusted sources such as the Google Play Store and avoid granting unfamiliar applications access to SMS messages, notifications, contacts or phone functions.

If a suspicious application has already been installed, police advised users to disconnect the phone from the internet and immediately contact their bank or UPI service provider to secure their accounts.

Victims of financial fraud should report the incident through the national cybercrime helpline, 1930, or the
National Cyber Crime Reporting Portal.

The government operates the helpline round the clock for reporting cyber financial fraud. Prompt reporting can help authorities and financial institutions act on suspicious transactions, although recovery of stolen money is not guaranteed.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *