Mumbai Cyber Fraud: Bank Of Baroda GM Loses ₹4.27 Lakh After Fake ‘RTO Challan APK’ Attack Linked To CSMT Free Wi-Fi; FIR Registered
A Bank of Baroda General Manager allegedly lost Rs 4.27 lakh in unauthorised credit card transactions after installing a fake “RTO Challan APK” file that was reportedly circulated following a connection to free public Wi-Fi at Mumbai’s CSMT station. MRA Marg Police have registered an FIR and are investigating the malware attack and the possible misuse of the public Wi-Fi network.

Mumbai Police are investigating a ₹4.27 lakh cyber fraud involving a fake APK file allegedly circulated after a phone connected to free Wi-Fi at CSMT | AI Generated Representational Image
Mumbai, August 7, 2026: A shocking cyber fraud case has highlighted the dangers of using free public Wi-Fi networks in Mumbai. A General Manager (GM) of Bank of Baroda lost Rs 4.27 lakh after his phone was allegedly compromised through a fake APK file that spread after his personal secretary connected to the free Wi-Fi service at Chhatrapati Shivaji Maharaj Terminus.
The MRA Marg Police registered an FIR on August 4 and have launched an investigation into the incident.
According to the police, the complainant, Gobinda Biswas (56), a resident of Himalayan Heights in Bhakti Park, Wadala, works as a General Manager at the Bank of Baroda’s Fort branch.
The incident began on July 18, when his personal secretary, Narayan Swamy, connected his mobile phone to the free public Wi-Fi network at CSMT railway station.
How The Fraud Unfolded
Investigators said that immediately after connecting to the Wi-Fi, cyber criminals allegedly hacked the secretary’s phone. The malware then automatically sent a suspicious file named “RTO Challan APK” to all the contacts stored on his device.
Believing the message to be a genuine RTO challan, Biswas downloaded and installed the APK file without verifying its authenticity. As soon as the file was installed, his phone was also compromised, and the same malicious message was forwarded to his contacts.
On July 21, after noticing unusual behaviour on his phone, Biswas deleted the APK file. At that time, he had not received any transaction alerts from the bank.
The fraud came to light on August 3, when he received his credit card statement. It revealed that hackers had carried out five unauthorised transactions worth Rs 4,27,264 within just 28 minutes on July 21.
Also Watch:
Police Investigation Underway
After detecting the suspicious transactions and being unable to reach the cardholder, the bank’s credit card department blocked the card as a precaution. The victim subsequently lodged a complaint on the National Cyber Crime Reporting Portal and approached the Mumbai Police.
The MRA Marg Police are now investigating the fake APK file, the cyber fraud, and whether the public Wi-Fi network was exploited as part of the attack.
To get details on exclusive and budget-friendly property deals in Mumbai & surrounding regions, do visit: https://budgetproperties.in/
RECENT STORIES
-
J&K Open 2026: Khalin Joshi Wins ₹1 Crore Title By 9 Shots For Second DP World PGTI Victory Of The... -
'We Cannot Accept Any Money...': Satluj Director Honey Trehan Reveals Gullaks Are Kept At Gurudwaras... -
MEA Clarifies No Govt Involvement In Sheikh Hasina's New Delhi Virtual Briefing | VIDEO -
Shadab Khan Snubs Pakistani Cricketers, Picks Rohit Sharma To Open And Lead His 'Perfect T20' Team;... -
Mumbai Cyber Fraud: Bank Of Baroda GM Loses ₹4.27 Lakh After Fake ‘RTO Challan APK’ Attack...
