A forest department official in Bengaluru has reportedly lost nearly Rs 10 lakh after becoming the victim of a cyber fraud involving a fake wedding invitation sent through WhatsApp. The incident has highlighted the growing threat posed by malicious Android Package Kit (APK) files, which cybercriminals are increasingly using to target unsuspecting smartphone users and gain access to sensitive financial information.
According to the police complaint, the victim, identified as 50-year-old Rameshbabu V, is a resident of Yeshwanthpur and works as a deputy range forest officer. The official allegedly received a WhatsApp message on July 14 that appeared to be a wedding invitation. The message reportedly contained an APK file, which he downloaded and opened, believing it to be connected to the invitation.
Soon after opening the file, the victim began receiving alerts related to financial transactions from his bank account. According to the complaint, several unauthorised transactions were carried out from his Bank of Baroda account within a short period on the same day.
The victim reportedly discovered that a total amount of Rs 9,96,659 had been transferred from his account without his knowledge or consent. He also found that the UPI IDs linked to his mobile phone had been deleted. The development raised suspicions that the fraudsters had gained unauthorised access to his smartphone or financial applications after the malicious APK file was installed.
The forest department official subsequently approached the North CEN Crime Police Station and lodged a complaint on July 15. Police have registered a case under relevant provisions of the Information Technology Act and the Bharatiya Nyaya Sanhita. An investigation is currently underway to identify the individuals behind the alleged fraud and determine how the money was transferred.
Fake wedding invitations emerge as a new cyber fraud tactic
The incident has drawn attention to a growing method of cybercrime in which criminals use fake wedding invitations to trick people into downloading malicious applications. Fraudsters often send messages through WhatsApp or other messaging platforms, making them appear like genuine invitations from friends, relatives or acquaintances.
The messages may contain an APK file that users are encouraged to download to view wedding details, photographs, venue information or other event-related content. However, such files can contain malicious software capable of compromising a smartphone.
Once installed, a malicious application may attempt to obtain access to sensitive information stored on the device. Depending on the permissions granted by the user, such applications could potentially expose banking information, payment details, messages and other personal data.
In the Bengaluru case, investigators suspect that the fake wedding invitation was used as a method to persuade the victim to install the malicious application. The unauthorised financial transfers that followed indicate that the attackers may have gained access to information or functions connected to the victim’s banking and digital payment accounts. 
Similar case reported in Bengaluru
The latest incident is reportedly similar to another cyber fraud case that was reported in Bengaluru earlier this year. In that case, a businessman allegedly lost Rs 5 lakh after receiving a WhatsApp message that appeared to contain a wedding invitation.
The recipient was reportedly asked to download an APK file to access information about the supposed wedding. After opening the file, the victim allegedly noticed suspicious activity involving his mobile phone and subsequently discovered that money had been withdrawn from his account.
Such cases demonstrate how cybercriminals are exploiting people’s familiarity with digital communication platforms. By presenting fraudulent messages as wedding invitations or other socially relevant communications, scammers attempt to create a sense of trust and reduce suspicion among potential victims.
Cybercriminals also frequently change the themes used in their scams. While wedding invitations are becoming increasingly common, similar malicious APK files may be distributed through fake messages involving government schemes, courier deliveries, traffic penalties, job offers, tax refunds or identity verification.
Police caution users against downloading unknown APK files
Police officials have repeatedly warned smartphone users against downloading APK files received from unknown or unverified sources. An APK file is the installation package used for Android applications, but files received through unofficial channels can potentially contain harmful software.
Users may not immediately realise that their device has been compromised after installing such an application. In some cases, criminals may attempt to operate in the background while collecting information or gaining access to applications installed on the phone.
The risk becomes particularly serious when the device is used for mobile banking or digital payments. If attackers manage to compromise financial information or obtain access to sensitive authentication details, they may attempt to conduct unauthorised transactions.
The Bengaluru case highlights how quickly such fraud can occur. Within a short period after the suspicious file was opened, the victim reportedly lost nearly Rs 10 lakh through multiple unauthorised transactions.
APK-based cyber fraud cases reportedly increasing
The incident comes amid concerns over the increasing use of malicious APK files in cyber fraud. Police records have reportedly shown a rise in cases involving such files in Karnataka.
The reported increase suggests that cybercriminals are increasingly relying on social engineering techniques rather than simply using traditional phishing links. By convincing victims to voluntarily download and install an application, scammers may be able to bypass some of the caution users normally exercise when dealing with suspicious links.
The use of wedding invitations is particularly effective because people are often less suspicious of messages related to social and family events. A recipient may assume that the message has been sent by someone they know or that the invitation is genuine.
However, police and cybersecurity experts have warned that users should not trust an attachment simply because the message appears personal or familiar.
How people can protect themselves from APK scams
Cybersecurity professionals advise users to avoid installing applications received through WhatsApp, SMS or other messaging platforms unless the source has been independently verified.
People should be especially cautious when an unknown sender asks them to download an APK file to access an invitation, document or service. Genuine applications should preferably be downloaded through trusted and official app distribution platforms.
Users should also avoid clicking on suspicious links or opening unexpected attachments. If a message appears to come from a friend or family member but contains an unusual file, the recipient should verify the message directly with that person through another communication method.
Experts also recommend regularly updating smartphones and security software, reviewing application permissions and monitoring bank accounts for unusual transactions. Users should immediately report suspicious financial activity to their bank and the appropriate cybercrime authorities.
Financial losses can occur within minutes
The Bengaluru incident serves as a warning that cyber fraud can affect anyone, regardless of their profession or level of awareness. The victim in this case was a government forest department official, yet a seemingly ordinary WhatsApp message allegedly resulted in a financial loss of nearly Rs 10 lakh.
The case also demonstrates the importance of treating unexpected digital files with caution. Cybercriminals often rely on human curiosity, urgency and trust to convince victims to take actions that may compromise their devices.
As digital banking and UPI payments continue to become an integral part of everyday life, cybercriminals are also developing new methods to exploit users. Fake wedding invitations containing malicious APK files represent one such emerging threat.
The police investigation into the Bengaluru case is expected to establish how the fraudulent transactions were carried out, identify the recipients of the stolen money and determine the extent to which the victim’s mobile device and financial accounts were compromised.
For smartphone users, the incident offers a clear lesson: an unexpected APK file should never be downloaded or installed without verifying its source. A message that appears harmless could potentially provide cybercriminals with access to sensitive personal and financial information.
