UP Teen Held for Allegedly Building AI-Powered Fake Banking Apps in ₹64 Crore Fraud Case

An 18-year-old Class 11 dropout from Uttar Pradesh has been arrested for allegedly developing artificial intelligence-assisted fake banking and government mobile applications that investigators say were used in a nationwide cyber fraud network responsible for losses exceeding ₹64 crore.

The arrest was made by the Surat City Cyber Crime Cell, which identified the accused as Rohit Virendrasinh Shakya. According to police, Shakya allegedly used AI tools, coding skills and Telegram channels to create malicious Android application packages (APKs) that closely resembled legitimate banking and government apps. These applications were then supplied to cybercriminal networks operating across multiple states on a subscription-based model.

The investigation began after a Surat resident reportedly downloaded a fake Punjab National Bank mobile application and lost approximately ₹5 lakh. Digital forensic analysis led investigators to the alleged developer, who was arrested from a hotel in Kanpur, Uttar Pradesh. Police have seized electronic devices, including mobile phones and a laptop, which are now undergoing forensic examination.

Investigators claim the accused developed 121 malicious APK files over the past two years. These applications allegedly impersonated several well-known banks, financial institutions, government schemes and consumer brands, including PNB One, State Bank of India, Axis Bank, Union Bank, UCO Bank, PM-Kisan, Aadhaar-related services and RTO challan portals. The fake applications were designed to appear authentic, encouraging unsuspecting users to install them and share sensitive financial information.

According to Surat Police, the fake applications were downloaded more than 21,000 times and allegedly contributed to fraud affecting nearly 3,000 victims across India. Investigators estimate the financial loss linked to the network at over ₹64 crore. Police allege that the accused charged cybercriminals between ₹10,000 and ₹15,000 per month for access to the malicious applications through a subscription model.

Officials said the accused had dropped out after Class 11 but became proficient in coding at an early age. Police allege he relied on freely available online tutorials, AI-assisted development tools and Telegram communities to create malware capable of stealing banking credentials, one-time passwords and other sensitive information. In some cases, investigators said the network operated separate applications for victims and administrators, allowing fraudsters to monitor compromised devices and capture data in real time.

The case highlights the growing role of generative AI and readily available software development tools in lowering the technical barriers for cybercrime. While AI itself is not inherently malicious, cybersecurity experts have increasingly warned that accessible AI platforms can accelerate the creation of phishing kits, fraudulent applications and social engineering campaigns when used by criminal actors. Authorities have also observed a rise in AI-enabled cybercrime involving deepfakes, identity fraud and sophisticated financial scams in recent months.

Law enforcement agencies are continuing to investigate the wider network that allegedly distributed and used the fake applications. Police are examining digital evidence to identify additional suspects and determine the full extent of the operation. Officials have urged users to download banking applications only from verified app stores and to avoid installing APK files received through messaging platforms or unofficial websites.

The investigation remains ongoing, and the allegations against the accused are yet to be tested in court.