Fake E-Challan APK Hijacks Varanasi Entrepreneur’s WhatsApp, Spreads to 100 Contacts

Varanasi: A file disguised as a traffic e-challan compromised the phone of Varanasi entrepreneur R K Chaudhary and used his WhatsApp account to send the same malicious message to more than 100 contacts, according to a complaint made to the national cybercrime helpline. The incident shows why an installable Android file should never be treated like an ordinary PDF notice.
Chaudhary, an office-bearer of the Indian Industries Association and a resident of Chandrika Nagar in the Sigra area, said the message arrived from an unknown number at about 10.20 p.m. on Wednesday. When he tapped the attached APK file, his phone stopped responding normally. Soon afterwards, acquaintances began calling to say that identical e-challan messages were arriving from his WhatsApp number.
An APK is an Android application package. Installing one from outside a trusted app store can grant it access to messages, contacts, notifications or accessibility controls, depending on the permissions requested and the phone’s security settings. The traffic-fine theme creates urgency: a recipient worries about a penalty and clicks before checking the file type.
Chaudhary reported the incident through helpline 1930 and the national cybercrime reporting system. Sigra station in-charge Shivakant Mishra advised residents to delete unverified APK attachments and stressed that official e-challan information is not distributed as an installable WhatsApp file.
Anyone who has already opened such a file should disconnect the phone from mobile data and Wi-Fi, use a separate trusted device to change important passwords and contact the bank if financial apps were present. Merely deleting the WhatsApp chat may not remove an installed application. A security check or professional reset may be necessary, and evidence such as the sender number and screenshot should be preserved before wiping the device.
Contacts who receive the message from a familiar person should verify it through a phone call. Compromised accounts exploit trust, so the sender’s known name or profile photograph is not proof. Traffic challans should be checked only through official government portals or applications reached independently, not through a link embedded in an unsolicited message.
Businesses are attractive targets because one infected phone may contain vendors, staff and customers. Employers should disable installation from unknown sources on work devices, maintain backups and create a simple incident plan that tells staff whom to call and how to warn contacts quickly.
The complaint does not yet establish who created or distributed the file, and the investigation must trace infrastructure and financial activity before assigning responsibility. But the prevention lesson is already clear: an e-challan is a notice, not an app. If a message asks you to install it, stop.
Sources and reporting
Based on the complaint made to cybercrime helpline 1930 and the Sigra police advisory reported on 6 August 2026.
Related Stories

BLW and Varanasi Municipal Corporation Sign Two-Part Waste Management Pact

Varanasi POCSO Court Sentences Juvenile Tried as Adult to 20 Years

₹5 Lakh Stolen From Unlocked Car After Property Registration in Naria

Court Adds Former BHU Chief Proctor as Accused in Gaurav Singh Murder Case

Four-Year Hunt Ends as Varanasi Police Arrest Film-Investment Fraud Accused in Mumbai

