KYCKART
KYCKART Guide · August 2026Guide

Fake Loan Apps and AI Deepfake Lending Scams: What BFSI Institutions Need to Know

Fake loan apps harvest data and coerce repayment; RBI has repeatedly enforced against them. The AI-deepfake angle remains anticipated, not yet documented.

calendar_monthAugust 2026
schedule15 min read
library_books23 Cited Sources
personBhanujeet Choudhary, Head of Compliance

A fake loan app is a mobile lending app with no genuine link to any RBI-regulated bank or NBFC, built to harvest a borrower’s personal data or run an advance-fee and harassment-based extraction scheme rather than disburse credit in good faith. These apps are typically sideloaded outside official app stores or pushed via social-media and SMS links specifically to dodge app-store vetting, then ask for contact-list, photo-gallery, and SMS access under the guise of “loan verification”. Indian regulators have targeted this ecosystem repeatedly over the past five years through distinct, separately dated actions, ranging from a 2021 RBI-led review finding roughly 600 illegal apps among 1,100 examined to a cumulative 87 apps MeitY has blocked under the IT Act as of a December 2025 parliamentary reply. No single consolidated figure captures that full enforcement record. This piece walks through how the typology actually works, what regulators have actually done (as distinct events, not one headline number), what separates a compliant lender from a fake one, and where the AI-deepfake angle is genuinely documented versus still anticipated.

01

How the Typology Works: From Install to Harassment

02

Permission harvesting

During onboarding, these apps typically request broad device permissions (the contact list, photo gallery, SMS/call logs, and file storage), under the pretext that this is needed to assess loan eligibility, close to the exact set of permissions RBI’s own digital lending rules bar a genuine lender from requesting at all.

03

Fake approval and fee demand

Victims are lured with instant approval, minimal paperwork, and no credit checks. In documented cases, the amount actually disbursed is reduced by an undisclosed upfront “processing fee” (a borrower requesting ₹10,000 might receive only ₹6,000-7,000), while the full amount is still recorded as owed, paired with artificially short repayment windows of 5-7 days and rapidly escalating late fees.

04

Harassment and escalation

If a borrower misses payment, delays, or disputes the amount, operators escalate: mass-messaging or calling the harvested contact list, and in the most severe documented cases digitally morphing photos pulled from the victim’s own gallery into obscene or defamatory images, circulated to the victim’s own contacts or posted to social groups, alongside fake “employer” calls falsely claiming the borrower is absconding from a debt.

A documented case illustrates the pattern end to end. A 36-year-old woman in Wilson Garden, Bengaluru, downloaded an app called “AMC Credit Park,” not available on either the Google Play Store or Apple App Store, via a third-party link. The same day, ₹2,400 was credited to her Citibank account three separate times without her requesting it. She then received harassing recovery calls from roughly ten different phone numbers, several with foreign country codes (Bangladesh, Indonesia, and the US), whose callers threatened to circulate morphed, obscene photographs of her and her minor daughter to her contact list, accessed because she had unwittingly granted permission during installation. Some of her contacts did in fact receive the doctored images. She filed a police complaint, and a case was registered.

Contact-list harvesting used for public shaming, and doctored images used to coerce payment, fall squarely inside what RBI’s Digital Lending Guidelines were written to prohibit, covered in full below.

02

The Enforcement Record: Separate Actions, Separate Dates

Enforcement against fake loan apps has come in stages, each measuring a different population of apps at a different point in time. There is no single confirmed figure that captures “how many fake loan apps have been flagged” or “how many have been blocked.” The actions below are distinct, separately dated events:

03

What Makes a Digital Lending App RBI-Compliant

RBI now runs a public Digital Lending Apps (DLAs) directory on its own website, effective 1 July 2025, built from data regulated entities submitted through RBI’s Centralised Information Management System portal by 15 June 2025. Its purpose is narrow: it lets a customer verify whether an app’s claimed association with a specific regulated bank or NBFC is genuine. RBI does not itself “certify” or endorse apps through this listing; it only confirms an app’s reported linkage to a named regulated entity.

A separate proposal, a body called the “Digital India Trust Agency” (DIGITA), was reported in 2024 as under consideration to formally verify and register authorized apps. No source confirms whether DIGITA was ever formally constituted as its own operating body, or whether its intended function was absorbed into the DLA directory RBI ultimately launched. The DLA directory is the confirmed, currently operating mechanism; DIGITA should be read only as a 2024 proposal, not a body that exists today.

Per RBI’s Digital Lending Guidelines, announced 10 August 2022 and formally notified 2 September 2022 (cited here by date and title, since no separate circular or notification number is publicly confirmed), a Digital Lending App’s access to borrower-device data is restricted: it bars DLAs from accessing a borrower’s phone contact list, call logs, or stored files and media altogether, and permits only one-time access to the camera, microphone, or location, with explicit consent, for defined onboarding purposes such as document or selfie capture, Video KYC, or address verification.

The same guidelines require all disbursal and repayment transactions to happen directly between the regulated lender’s own bank account and the borrower’s, with no intermediary pass-through or pooled third-party account involved, aside from narrow carve-outs such as co-lending arrangements between two regulated entities. They also require every regulated entity to appoint a nodal grievance redressal officer for digital-lending complaints, with contact details published on the lender’s (and its Lending Service Provider’s, or LSP’s) website, and mandate a minimum cooling-off period during which a borrower may exit a loan by repaying only the principal plus a proportionate Annual Percentage Rate, without penalty: at least 3 days for loans with a tenor of 7 days or more, and at least 1 day for shorter-tenor loans.

Per the RBI (Digital Lending) Directions, 2025, issued 8 May 2025, and the April 2024 Key Fact Statement (KFS) rules (both cited here by date only, as with the 2022 guidelines above), a regulated lender must give the borrower a KFS before the loan contract is executed, in simple language the borrower understands, disclosing the lender’s name, the all-in Annual Percentage Rate, the total cost of credit, all applicable fees and penal charges, the recovery mechanism, the grievance redressal officer’s details, and the cooling-off period. The KFS is mandatory for MSME and retail term-loan products (excluding credit cards and corporate loans), and where more than one lender’s offer is being compared, each must be presented in a comparable format.

Separately, Google’s Play Store listing policy for personal-loan apps in India was updated, following RBI/MeitY coordination, to restrict eligible listings to apps published directly by a regulated entity or operating in partnership with one. That’s a platform-level policy, not an RBI enforcement action in itself, and it does not prevent distribution via direct APK download outside the Play Store.

04

AI Voice Cloning and Deepfakes: What's Actually Documented

RBI has issued a specific advisory on AI-generated impersonation, but it addresses a different scam category than loan recovery. On 20 November 2024, RBI issued a press release cautioning that fabricated (“deepfake”) videos of the RBI Governor were circulating on social media, falsely claiming his endorsement of certain investment schemes, stating that RBI officials are not involved in or supportive of any such schemes and that RBI does not provide financial or investment advice. That advisory is specific to investment-scheme deepfakes; no comparable dedicated RBI advisory naming loan-recovery or lending deepfakes was found.

RBI has separately and repeatedly stated its general position on unsolicited contact, including in a press release dated 6 February 2012: it “never contacts the public via unsolicited phone calls or emails asking for money or any other type of personal information,” and nobody from RBI calls individuals about lottery winnings or funds received from abroad. This is RBI’s long-standing general position, not a statement issued specifically about digital lending or AI-generated voices.

On the general prevalence of AI voice cloning, a McAfee-commissioned global survey of 7,054 respondents across seven countries, including 1,010 in India, reported on 1 May 2023, found that 47% of Indian respondents said they, or someone they knew, had experienced an AI-generated voice scam, roughly double the 25% global average in the same survey. Of Indian respondents who said they’d lost money to such a scam, 83% reported a financial loss, and 48% of those lost more than ₹50,000. McAfee’s researchers said as little as three seconds of sample audio could produce a voice clone with an 85% match to the real voice. This is general voice-cloning-fraud prevalence data, not a lending-scam-specific statistic.

Some consumer-safety commentary online describes fake recovery calls now using AI-generated voices or deepfake video of “RBI officers,” but that specific claim could not be traced to a citable, independently verifiable source in this research pass, and no RBI advisory or reported case names loan-recovery deepfakes specifically the way the Governor deepfake advisory names investment-scheme deepfakes. Until that specific pattern is independently documented with its own named incident, source, or advisory, it reads as a plausible extension of the confirmed investment-scheme deepfake threat and RBI’s general anti-impersonation position into loan-recovery calls, not as an already-documented phenomenon with its own statistics. For a broader look at how AI voice cloning and deepfake impersonation fit into India’s wider bank-fraud picture, see KYCKART’s overview of bank fraud in India.

05

Where Compliant and Fake Apps Diverge in Practice

A published grievance officer, a comparable-format Key Fact Statement, a DLA-directory listing tied to a named regulated entity, and permission requests scoped to a single onboarding purpose are each requirements of a compliant lending app, cited above. Read together, this points to why fake apps skip all of them: reproducing these features would require the regulatory relationship the apps don’t have.

The same distinction suggests itself in onboarding. RBI’s Digital Lending Guidelines permit only one-time camera, microphone, or location access, collected for a defined KYC purpose such as Video KYC or document capture. Read against KYCKART’s overview of eKYC and digital KYC verification, that narrower, purpose-bound scope is a useful marker of what a legitimate onboarding flow is supposed to ask for, versus the broad, standing access a fake loan app requests under the same “verification” label.

On the complaint side, two public channels carry the referral and reporting load: Sachet (sachet.rbi.org.in), RBI’s dedicated portal for reporting unauthorized deposit-taking, lending, chit-fund, or investment operations, and the National Cyber Crime Reporting Portal, paired with the 1930 helpline, for cyber and financial fraud generally, including fraud connected to loan apps. Both generate trackable references and route complaints to the relevant regulator.

Legitimate RBI-Linked AppFake / Unauthorized App
Distribution channelPublished directly by a regulated bank or NBFC, or by a partner operating with one, per Play Store’s India listing policySideloaded APK files, or links shared via social media/SMS, specifically to bypass app-store vetting
Permissions requestedOne-time camera, microphone, or location access only, with consent, for a defined onboarding purpose; contact list, call logs, and stored files are off-limits entirelyBroad, standing access to contacts, photo gallery, SMS/call logs, and file storage, requested under the pretext of loan verification
Fee disclosureAll fees, penal charges, and the all-in APR disclosed upfront in a mandatory Key Fact Statement before the loan contract is executedAn undisclosed upfront “processing fee” deducted from the disbursed amount while the full amount is still recorded as owed
Recovery conductA published nodal grievance redressal officer whose contact details appear on the lender’s and its Lending Service Provider’s websiteMass messaging or calling the harvested contact list, and in documented cases morphing photos into obscene or defamatory images
Public verificationListed on RBI’s Digital Lending Apps directory, effective 1 July 2025, as linked to a named regulated entityNo genuine link to any RBI-regulated bank or NBFC
Cooling-off / exitA minimum cooling-off period (at least 3 days for tenors of 7 days or more, at least 1 day for shorter tenors) to exit by repaying principal plus a proportionate APR, without penaltyShort 5-7 day repayment windows with rapidly escalating late fees

Read together, the enforcement timeline above tells a different story than a single headline number would. RBI’s 2022 whitelist covered 442 apps already linked to its own regulated NBFCs, Google’s Play Store removals covered a separate population measured against its own listing policy, and MeitY’s Section 69A blocks covered yet another population selected for borrower harassment, fraudulent practices, and misuse of personal data. That’s three different tracks, each counting a different set of apps, which is why no single confirmed figure captures how many fake loan apps exist or how many have been shut down. The practical implication for a compliance team is that checking one list, such as the DLA directory, does not by itself establish an app’s full regulatory history, since each enforcement track measures a different population.

The evidence base also isn’t uniform across this piece’s two main threats. The typology, the fee-deduction pattern, and the enforcement timeline are each backed by a named case, a government reply, or app-store data. The AI-deepfake angle rests on a narrower foundation: RBI’s investment-scheme-specific deepfake warning, its long-standing general anti-impersonation position, and general voice-cloning prevalence data with no lending-specific incident attached to any of it. This suggests BFSI institutions get more near-term compliance value from strengthening the well-documented mechanics (permission scope, KFS disclosure, grievance-officer visibility, DLA-directory listing) than from building a deepfake-specific control today, given that the public record doesn’t yet describe deepfake-driven loan-recovery calls as an independently documented, active tactic.

verified

How KYCKART Helps

KYCKART’s onboarding platform is built around the same purpose-bound, one-time verification permissions RBI’s Digital Lending Guidelines require, not the broad, standing device access a fake loan app asks for.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 30, 2026

This piece describes publicly available regulatory requirements and reported enforcement actions for informational purposes. It is not legal, regulatory, or compliance advice, and BFSI institutions should consult counsel before making compliance decisions based on it.

KYCKART Intelligence

Verify Once, Not Every Time

KYCKART’s fraud intelligence platform helps BFSI institutions spot the same coercive, data-harvesting patterns fake loan apps use, before they reach your customers.

Explore Fraud Intelligencearrow_forward