HomeLatest NewsCyber SecurityFake hospital booking apps threaten UPI accounts, Kerala Police warn

Fake hospital booking apps threaten UPI accounts, Kerala Police warn

Kerala Police say fraudsters posing as hospital staff are sending malicious Android apps through WhatsApp, putting patients’ bank accounts and UPI payments at serious risk.

Preferred Source of Google

Key Points

  • Fraudsters are using fake hospital contact numbers and WhatsApp messages to persuade people to install malicious Android applications.
  • Compromised phones may expose confidential information and enable unauthorised UPI transactions, including small-value payments.
  • Verify hospital numbers through official sources, avoid unfamiliar APK files and report suspected financial fraud immediately on 1930.

People searching online for hospital appointments or contact numbers are being targeted by fraudsters who impersonate hospital staff and persuade them to install malicious mobile applications, warned on Sunday.

The fraud begins when a person calls a fake hospital contact number found through a Google search. The caller is then contacted by someone posing as a hospital employee and sent an Android application file through WhatsApp, purportedly to book an outpatient appointment.

Advertisement
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

Once installed, the application can compromise the user’s phone, expose confidential information and enable unauthorised financial transactions, police said.

The warning concerns Android application package (APK) files distributed outside official app stores. Such files can be installed directly on Android phones, but applications obtained from unknown sources can expose users to malware and data theft, according to Google’s guidance.

How the hospital booking scam works

According to police, fraudsters use misleading contact information in Google search results to attract people looking for outpatient appointments at leading hospitals.

Advertisement

After establishing contact, they send an application file through WhatsApp under the pretext of completing an appointment booking or providing a hospital-related service. The application may appear to be connected to a legitimate hospital, but installing it can allow attackers to access sensitive information on the device.

Police warned that one-time passwords (OTPs) and information associated with Unified Payments Interface (UPI) applications could be exposed. Fraudsters may also misuse payment applications such as PhonePe and Google Pay or install additional payment applications without the user’s knowledge.

The warning does not identify the hospitals whose names have been misused or specify how many people have lost money through the scam.

Advertisement

Why UPI Lite users face an additional risk

Police have particularly cautioned people who use UPI Lite, which allows small-value payments without requiring a UPI PIN for every transaction. Under the Reserve Bank of ‘s framework, UPI Lite permits transactions of up to ₹1,000, with a maximum balance of ₹5,000.

The facility does not require additional authentication for individual payments within the applicable limits, although replenishing the balance requires authentication. Police warned users not to ignore repeated unauthorised transactions involving small amounts, particularly those below ₹1,000.

A series of such payments could result in financial losses before the account holder notices suspicious activity. The absence of a PIN requirement for individual UPI Lite payments does not mean that installing a malicious application automatically gives criminals access to the funds. The risk arises when a compromised device or payment application can be misused.

What should users do?

Kerala Police advised people to verify hospital contact numbers through the institution’s official website or verified accounts rather than relying solely on numbers appearing in search results.

“Do not install app files received through WhatsApp for purposes such as appointment booking, KYC or refunds under any circumstances,” police said.

Users should install applications from trusted sources such as the Google Play Store and avoid granting unfamiliar applications access to SMS messages, notifications, contacts or phone functions.

If a suspicious application has already been installed, police advised users to disconnect the phone from the internet and immediately contact their bank or UPI service provider to secure their accounts.

Victims of financial fraud should report the incident through the national cybercrime helpline, 1930, or the
National Cyber Crime Reporting Portal.

The government operates the helpline round the clock for reporting cyber financial fraud. Prompt reporting can help authorities and financial institutions act on suspicious transactions, although recovery of stolen money is not guaranteed.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

RBI eases KYC documentation for foreign portfolio investors across six banking categories

Foreign portfolio investors can now submit documents certified by authorised overseas institutions for KYC verification, extending a facility previously available to NRIs and persons of Indian origin.

RELATED ARTICLES