Summary of this article
Fake e-challan SMS messages trick users into downloading malicious APK files.
Never download external apps; check fines only through official government websites.
Disconnect internet, uninstall suspicious apps, and report scams to cybercrime helpline.
Fraudsters are using fake e-challan scams to trick vehicle owners into opening malicious links and sharing sensitive information. Kerala Police has now warned motorists about a similar scam involving fake traffic challan messages that can lead to the installation of malicious Android applications.
How Fake E-Challan Scam Works
Fraudsters send SMS messages from private mobile numbers containing seemingly genuine e-challan details and a link. The messages are designed to appear as if they have been issued through an official government system. The link can take the users to a fake website resembling the official Motor Vehicles Department’s e-challan portal. Users are asked to enter their vehicle registration number, after which the website may display a security-related message and prompt them to download an application.
According to the police, the page displays a security review and prompts users to download an application. However, selecting the option to proceed can trigger the download of a malicious APK file. “Legitimate e-challan payment or verification services normally do not require users to download APK files from external sources,” Kerala Police said.”
An APK, or Android Package Kit, is used to install applications on Android devices. A malicious APK may seek permissions that can allow fraudsters to access sensitive information or misuse the device.
How To Protect Yourself From Fake Challan Scams
According to a PTI report, Kerala Police has advised vehicle owners not to install APK files received through SMS, WhatsApp, Telegram or other messaging platforms in the name of e-challans, traffic fines, vehicle verification, know-your-customer (KYC), refunds or RTO and MVD services.
Users should check challan details only through official MVD, Parivahan or e-challan websites and authorised government portals. Instead of opening links directly from the messages, they should type the official website address themselves or use verified government platforms.
Users should disconnect the device from the Internet and refrain from using it for important transactions, such as banking if a suspicious APK has already been installed. If possible, users should uninstall the program and check out any unauthorised transactions in their bank and Unified Payments Interface (UPI) accounts.
Users whose passwords or other credentials may have been compromised should change them using another secure device. If suspicious transactions are detected, they should immediately contact their bank or payment service provider. People who receive such messages or fall victim to the scam can report the matter to the cybercrime helpline at 1930 or through the National Cyber Crime Reporting Portal.







