Key Points
- Fraudsters are using fake hospital contact numbers and WhatsApp messages to persuade people to install malicious Android applications.
- Compromised phones may expose confidential information and enable unauthorised UPI transactions, including small-value payments.
- Verify hospital numbers through official sources, avoid unfamiliar APK files and report suspected financial fraud immediately on 1930.
People searching online for hospital appointments or contact numbers are being targeted by fraudsters who impersonate hospital staff and persuade them to install malicious mobile applications, Kerala Police warned on Sunday.
The fraud begins when a person calls a fake hospital contact number found through a Google search. The caller is then contacted by someone posing as a hospital employee and sent an Android application file through WhatsApp, purportedly to book an outpatient appointment.
Once installed, the application can compromise the user’s phone, expose confidential information and enable unauthorised financial transactions, police said.
The warning concerns Android application package (APK) files distributed outside official app stores. Such files can be installed directly on Android phones, but applications obtained from unknown sources can expose users to malware and data theft, according to Google’s Android security guidance.
How the hospital booking scam works
According to police, fraudsters use misleading contact information in Google search results to attract people looking for outpatient appointments at leading hospitals.
After establishing contact, they send an application file through WhatsApp under the pretext of completing an appointment booking or providing a hospital-related service. The application may appear to be connected to a legitimate hospital, but installing it can allow attackers to access sensitive information on the device.
Police warned that one-time passwords (OTPs) and information associated with Unified Payments Interface (UPI) applications could be exposed. Fraudsters may also misuse payment applications such as PhonePe and Google Pay or install additional payment applications without the user’s knowledge.
The warning does not identify the hospitals whose names have been misused or specify how many people have lost money through the scam.
Why UPI Lite users face an additional risk
Police have particularly cautioned people who use UPI Lite, which allows small-value payments without requiring a UPI PIN for every transaction. Under the Reserve Bank of India‘s framework, UPI Lite permits transactions of up to ₹1,000, with a maximum balance of ₹5,000.
The facility does not require additional authentication for individual payments within the applicable limits, although replenishing the balance requires authentication. Police warned users not to ignore repeated unauthorised transactions involving small amounts, particularly those below ₹1,000.
A series of such payments could result in financial losses before the account holder notices suspicious activity. The absence of a PIN requirement for individual UPI Lite payments does not mean that installing a malicious application automatically gives criminals access to the funds. The risk arises when a compromised device or payment application can be misused.
What should users do?
Kerala Police advised people to verify hospital contact numbers through the institution’s official website or verified social media accounts rather than relying solely on numbers appearing in search results.
“Do not install app files received through WhatsApp for purposes such as appointment booking, KYC or refunds under any circumstances,” police said.
Users should install applications from trusted sources such as the Google Play Store and avoid granting unfamiliar applications access to SMS messages, notifications, contacts or phone functions.
If a suspicious application has already been installed, police advised users to disconnect the phone from the internet and immediately contact their bank or UPI service provider to secure their accounts.
Victims of financial fraud should report the incident through the national cybercrime helpline, 1930, or the
National Cyber Crime Reporting Portal.
The government operates the helpline round the clock for reporting cyber financial fraud. Prompt reporting can help authorities and financial institutions act on suspicious transactions, although recovery of stolen money is not guaranteed.





