The Press Information Bureau (PIB) issued a crucial fact-check warning about a sophisticated phishing scam targeting State Bank of India (SBI) customers.
Fraudsters have been sending SMS and WhatsApp messages urging users to download a malicious file named ‘SBI REWARD27.apk’ to claim reward points allegedly expiring soon, with a claimed value of Rs 9,98,000.
The fake message, highlighted with conspicuous red ‘FAKE’ stamps, reveals common scam tactics designed to create urgency.
In a post on X, PIB Fact Check cautioned users against falling for the scam, stressing that SBI never sends APK files or links via messaging platforms.
Did you also receive a message asking you to download & install an APK file to redeem SBI rewards❓
Beware ‼️#PIBFactCheck
❌ @TheOfficialSBI NEVER sends links or APK files over SMS/WhatsApp
✔️Never download unknown files or click on such links pic.twitter.com/yIVXqtEozs
— PIB Fact Check (@PIBFactCheck) December 27, 2025
Cybersecurity experts confirm that downloading such APK files can compromise devices, install malware, and steal sensitive banking credentials.
They caution that fraudsters exploit human psychology, leveraging panic over expiring rewards to trick users into immediate action.
Throughout 2025, authorities have observed a sharp increase in reward-related APK scams across India.
The government has issued multiple alerts since January, emphasising that no legitimate bank asks users to download external applications to redeem points.
Officials repeatedly advise that all reward claims should be verified strictly through official SBI apps or the bank’s website.
The scam mirrors evolving tactics in cybercrime. Fraudsters now combine social engineering with technical malware deployment to extract confidential information from unsuspecting users.
By linking malware to seemingly lucrative rewards, attackers increase the likelihood of users installing harmful applications.
In this particular case, the ‘SBI REWARD27.apk’ file not only poses a risk to individual accounts but can also compromise the integrity of mobile devices.
Cybersecurity specialists recommend enabling two-factor authentication, regularly updating mobile operating systems, and installing trusted antivirus software.
Authorities urge users to stay alert to messages promising unusually high rewards, urgent deadlines, or requesting downloads of unknown applications.
By verifying every communication through official channels, customers can significantly reduce their exposure to fraud.
SBI itself has reiterated that all genuine communication regarding reward points occurs exclusively via verified bank platforms.
Customers are warned to report suspicious messages immediately to the bank’s official helpline.
Experts, however, underscore that widespread awareness remains critical. They further add that cautious digital behaviour is the most effective defence against phishing attacks and financial cybercrime.
As digital banking continues to grow, cybercriminals will persistently exploit shortcuts and unverified apps.
Vigilance, verification, and proactive cybersecurity practices are critical to protecting both financial assets and personal data.
This latest PIB advisory serves as a stark reminder that technology convenience must always be balanced with digital caution.
Also Read: PIB Busts Fake Claim Of ‘13 New Rules’ Restricting Calls And Social Media From December 2025
To read more such news, download Bharat Express news apps
