Mumbai SIR Scam Alert: How Cyber Fraudsters Use Fake Voter List Errors to Hack Phones via APK Files

Cybercriminals in Mumbai are exploiting the Election Commission’s voter list verification drive to defraud residents of lakhs of rupees. Posing as election officials, fraudsters claim errors in voters’ details and trick victims into installing malicious APK files, giving hackers complete control of their mobile devices.

Representative Image

Cybercriminals in Mumbai are exploiting the Election Commission of India’s ongoing voter list verification process to defraud residents of lakhs of rupees. By targeting public anxiety around electoral roll corrections, fraudsters pose as election officials, claim there are critical errors in voters' personal details, and trick victims into installing malicious Android Package Kit (APK) files that give hackers complete control over their mobile devices.

Recent police reports reveal a sharp surge in these voter list scams across the metropolitan area, with senior citizens being heavily targeted. In one case from Deonar, a former college principal lost ₹17 lakh after a fraudster using an Election Commission logo as his display picture convinced him to download a verification app to fix an error in his father's name on the voter roll. Similar cases have been recorded in Trombay and Chembur, where residents lost ₹6.7 lakh and ₹11.2 lakh respectively through identical tactics. Maharashtra SIR: 2.07 Crore Voters Face Exclusion From Draft Electoral Roll After First Phase.

Exploiting the Special Intensive Revision (SIR) Exercise

The fraudulent operation relies on creating immediate panic around the Special Intensive Revision (SIR) framework. Scammers place voice calls or send text messages posing as Booth Level Officers (BLOs) or senior election officials. They inform citizens that their details contain severe discrepancies—such as misspellings, mismatched parentage, or address mismatches—and warn that failure to correct the records immediately will result in the deletion of their voting rights.

To make the scheme appear legitimate, callers direct victims to resolve the issue digitally rather than visiting a government booth. They send a direct messaging link—typically via WhatsApp or SMS—containing a custom APK file styled as an official ECI voter verification app.

How Malicious APK Files Hijack Devices

Once a user downloads and installs the APK file, the file bypasses standard mobile security protocols found on official application stores. The app requests extensive device permissions, granting the cybercriminals remote access to the victim's phone. This allows fraudsters to intercept incoming SMS messages, view two-factor authentication One-Time Passwords (OTPs), and monitor banking application keystrokes. Maharashtra Voter List Update: How To Complete Your Enumeration Form Online.

In most recorded incidents, the fraudster asks the victim to pay a nominal processing fee of ₹5 or ₹10 through net banking or a credit card to complete the "voter record update". As the user enters their credentials to complete the small transaction, the malware captures the banking details and OTPs in real time, allowing scammers to perform unauthorized money transfers out of the victim's account.

Official Advisory and Preventive Steps

Cybersecurity authorities and election officials emphasize that legitimate electoral roll updates never require citizens to download third-party files or pay processing fees via private links. Official voter roll verifications are handled in person by designated Booth Level Officers or through official Election Commission portals and verified mobile app stores.

Law enforcement agencies advise citizens to take immediate precautions:

  • Never download APK files sent via SMS, WhatsApp, or email attachments.

  • Ignore unsolicited calls demanding immediate voter verification fees or financial details.

  • Verify electoral roll details exclusively on official Election Commission portals or at local electoral offices.

  • Report suspicious activity immediately to the national cybercrime helpline at 1930 or through the official cybercrime reporting portal (cybercrime.gov.in).

Vigilance and Timely Reporting Remain Essential

As digital identity management and administrative updates increasingly intersect with everyday life, cybercriminals will continue leveraging fake bureaucratic urgency to breach mobile devices. Municipal authorities and cybersecurity experts stress that public awareness remains the primary defense against such social engineering tactics. By strictly adhering to official channels for any voter documentation updates and refusing to install unverified software from messaging links, citizens can safeguard both their democratic rights and their financial assets.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (Time Of India), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Aug 24, 2026 07:33 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now