Police have arrested an 18-year-old from Uttar Pradesh for allegedly developing 121 fake Android applications which investigators say were used by cybercriminal networks to carry out phishing attacks and large-scale online financial fraud. The amount of losses was believed to be over ₹64 crore as well as thousands of people in India being targeted by the scam.
According to investigators, the teenager, a Class 11 dropout, learned Android application development online through free resources including YouTube tutorials and used artificial intelligence-assisted coding tools to speed up the development process. Police say the apps were designed to mimic the official mobile apps of a large number of banks, government welfare schemes, and other popular services on the internet.
The services allegedly impersonated were State Bank of India (SBI), Punjab National Bank (PNB), Axis Bank, PM-Kisan, BigBasket, and digital platforms used for paying traffic challans and accessing government services. The fake applications, the investigators say, copied the appearance, logos, and interfaces of legitimate apps which made it difficult for many users to distinguish between genuine software and fraudulent copies.
Police claim that the applications were distributed through cybercrime groups operating on encrypted messaging platforms like Telegram. The fake apps were offered to cybercriminals on a subscription model costing around ₹15,000 per month, enabling several groups to launch phishing campaigns on unsuspecting smartphone users.
According to authorities, the fake applications were downloaded more than 21,000 times and nearly 3,000 people have allegedly become victims of financial fraud. The total financial loss related to the investigation is estimated at over ₹64 crore but officials have said that the amount may change as more complaints are investigated.
The victims were lured to install the counterfeit apps by messages from SMS, social media ads, messaging apps, and phishing links, according to investigators. Once installed, the fake apps requested sensitive information from internet banking usernames, passwords, debit card numbers, PINs, CVV details, and one-time passwords (OTPs), and the stolen information was used by cybercriminals to access victims’ bank accounts and transfer funds.
Police have seized electronic devices belonging to the accused and are investigating them by performing detailed forensic examinations to recover application source code, communication records, digital payment information, and transaction histories. Authorities are also attempting to identify other members of the alleged cybercrime network responsible for distributing the applications and carrying out fraudulent financial transactions.
Phishing applications have become one of the fastest-growing threats in digital banking, cybersecurity experts say, with millions of Indians increasingly relying on smartphones for financial transactions. Criminals are now developing sophisticated fake applications to trick even experienced users.
The case also demonstrates the growing importance of artificial intelligence in software development. AI-powered coding assistants have made programming more accessible by helping users write and debug code more efficiently. While these tools are transforming education, innovation, and business, they can also be exploited for illegal activities if misused.
Law enforcement agencies stress that technology itself is not responsible for cybercrime; rather, criminal intent determines whether digital tools are used ethically or unlawfully. Cybercrime investigation capabilities have been strengthened through digital forensics, cross-state coordination, and collaboration with technology companies.
Experts in cybersecurity recommend a number of precautions to help protect against phishing attacks. Users should only download applications from trusted and verified official app stores, verify the identity of developers before downloading software, and avoid clicking on links received through unsolicited messages. They also recommend enabling multi-factor authentication, regularly updating operating systems, and never sharing banking credentials or OTPs with anyone.
Banks and government departments have repeatedly reminded customers that they never ask users to disclose confidential financial information through unofficial applications, text messages, or phone calls. Individuals noticing suspicious transactions are encouraged to immediately contact their bank and report the incident to cybercrime authorities.
INDIA: Police have arrested an 18-year-old accused of helping run a ₹64 crore cyber fraud network.
— The Crypto Times (@CryptoTimes_io) July 22, 2026
Authorities say he learned Android app development through YouTube and AI tools, then created 121 fake apps impersonating SBI, PNB, Axis Bank, PM-Kisan, BigBasket, RTO challan,… pic.twitter.com/szGqMbFx7p
Police have said that the investigation is still in progress, seeking to track more suspects, dismantle the wider network, and recover stolen funds where possible. Investigators are also examining whether similar fake applications may have been used in other states.
The case serves as a stark reminder of the evolving sophistication of cybercrime in India. As digital services continue to expand, cybersecurity awareness, responsible use of emerging technologies, and prompt reporting of suspicious activities remain essential to protecting individuals from increasingly complex online fraud schemes.