IIT-BHU Scholar Loses ₹46,000 After Installing App Sent by Caller

By Harsh Mehra7 min read
A worried IIT-BHU student checks a phone beside a laptop security warning
Illustrative editorial image.

Varanasi: A doctoral scholar at IIT-BHU has reported losing ₹46,000 after installing a mobile application sent by an unknown caller. The case appears to follow a familiar cyber-fraud pattern in which a victim is persuaded to install software that can expose a phone screen, messages or banking credentials to a remote operator.

According to the initial complaint, the caller gained the scholar’s confidence before directing the app installation. Soon afterwards, money was transferred from the account without authorisation. Police and cybercrime personnel will need to trace the transaction trail, identify the beneficiary accounts and determine exactly what permissions the application obtained. The scholar’s account is an allegation at this stage, and the identity of the person behind the call remains under investigation.

The amount may be modest compared with headline-grabbing investment scams, but ₹46,000 can represent months of living expenses for a research student. Doctoral scholars regularly use their phones for stipend messages, banking, institutional email and one-time passwords, which makes a compromised device particularly damaging. A fraudulent app can also capture contacts or documents that create risks beyond the immediate debit.

Cyber-safety advice is simple but easy to ignore during a convincing call: no bank, courier company, police unit or government department should ask a customer to install a remote-access application to complete verification. Users should also be suspicious of links sent through messaging platforms and of callers who create urgency around account closure, refunds or legal action. Application permissions deserve the same caution as handing over a key.

After an unauthorised transfer, speed matters. Victims should contact their bank immediately, call the national cybercrime helpline at 1930 and submit details through the official cybercrime reporting portal. Screenshots, phone numbers, transaction IDs and the app file or link can help investigators. Deleting everything in panic may remove evidence, while continuing to use a compromised device for banking can create further loss.

Universities can reduce risk by treating cyber awareness as part of student welfare rather than an occasional poster campaign. Short briefings during registration, prominent helpline information and rapid campus support for compromised devices would be useful. The IIT-BHU complaint is a reminder that technical education does not make anyone immune to social engineering: most successful digital fraud begins not with sophisticated code, but with a conversation engineered to make a careful person act quickly.

The investigating team should also warn other students if the malicious application remains in circulation, while avoiding details that would help copy the fraud. A campus notice can describe the approach, the claimed pretext and the official reporting route. Shared quickly, one victim’s experience can become a protective lesson for thousands of phones connected to the university network.

Sources and reporting

Based on local police and campus-linked reporting published on 14 August 2026. The alleged method and loss are attributed to the complainant; the investigation has not established the identity of the caller.

Related Stories