Fake Loan Apps and AI Deepfake Lending Scams: What BFSI Institutions Need to Know
Fake loan apps harvest data and coerce repayment; RBI has repeatedly enforced against them. The AI-deepfake angle remains anticipated, not yet documented.
A fake loan app is a mobile lending app with no genuine link to any RBI-regulated bank or NBFC, built to harvest a borrower’s personal data or run an advance-fee and harassment-based extraction scheme rather than disburse credit in good faith. These apps are typically sideloaded outside official app stores or pushed via social-media and SMS links specifically to dodge app-store vetting, then ask for contact-list, photo-gallery, and SMS access under the guise of “loan verification”. Indian regulators have targeted this ecosystem repeatedly over the past five years through distinct, separately dated actions, ranging from a 2021 RBI-led review finding roughly 600 illegal apps among 1,100 examined to a cumulative 87 apps MeitY has blocked under the IT Act as of a December 2025 parliamentary reply. No single consolidated figure captures that full enforcement record. This piece walks through how the typology actually works, what regulators have actually done (as distinct events, not one headline number), what separates a compliant lender from a fake one, and where the AI-deepfake angle is genuinely documented versus still anticipated.
How the Typology Works: From Install to Harassment
Distribution
Fake loan apps rarely rely on the Play Store, since its India listing policy now restricts loan-app listings to RBI-regulated entities or their partners. Instead, they’re commonly distributed via side-loaded APK files or links shared through social media and SMS ads, which lets them skip that vetting entirely.
Permission harvesting
During onboarding, these apps typically request broad device permissions (the contact list, photo gallery, SMS/call logs, and file storage), under the pretext that this is needed to assess loan eligibility, close to the exact set of permissions RBI’s own digital lending rules bar a genuine lender from requesting at all.
Fake approval and fee demand
Victims are lured with instant approval, minimal paperwork, and no credit checks. In documented cases, the amount actually disbursed is reduced by an undisclosed upfront “processing fee” (a borrower requesting ₹10,000 might receive only ₹6,000-7,000), while the full amount is still recorded as owed, paired with artificially short repayment windows of 5-7 days and rapidly escalating late fees.
Harassment and escalation
If a borrower misses payment, delays, or disputes the amount, operators escalate: mass-messaging or calling the harvested contact list, and in the most severe documented cases digitally morphing photos pulled from the victim’s own gallery into obscene or defamatory images, circulated to the victim’s own contacts or posted to social groups, alongside fake “employer” calls falsely claiming the borrower is absconding from a debt.
A documented case illustrates the pattern end to end. A 36-year-old woman in Wilson Garden, Bengaluru, downloaded an app called “AMC Credit Park,” not available on either the Google Play Store or Apple App Store, via a third-party link. The same day, ₹2,400 was credited to her Citibank account three separate times without her requesting it. She then received harassing recovery calls from roughly ten different phone numbers, several with foreign country codes (Bangladesh, Indonesia, and the US), whose callers threatened to circulate morphed, obscene photographs of her and her minor daughter to her contact list, accessed because she had unwittingly granted permission during installation. Some of her contacts did in fact receive the doctored images. She filed a police complaint, and a case was registered.
Contact-list harvesting used for public shaming, and doctored images used to coerce payment, fall squarely inside what RBI’s Digital Lending Guidelines were written to prohibit, covered in full below.
The Enforcement Record: Separate Actions, Separate Dates
Enforcement against fake loan apps has come in stages, each measuring a different population of apps at a different point in time. There is no single confirmed figure that captures “how many fake loan apps have been flagged” or “how many have been blocked.” The actions below are distinct, separately dated events:
- •January-November 2021: RBI’s own Working Group on Digital Lending examined roughly 1,100 digital lending apps across 81 Indian app stores and found that around 600 were operating illegally, of which about 350 were unique illegitimate apps (the rest being clones or imitations of legitimate apps).
- •January 2020-March 2021 (covered in the same Working Group report): RBI’s “Sachet” complaint portal had received 2,562 complaints related to digital lending, including complaints about exorbitant interest rates, non-updated loan-settlement records, and threats to misuse borrowers’ phone contacts.
- •2022: Acting on the Working Group’s recommendations, RBI shared a whitelist of 442 unique digital lending apps linked to its own regulated NBFCs with the Ministry of Electronics and Information Technology (MeitY), so app stores could be directed to host only apps on that list. RBI’s Governor has publicly confirmed the list’s origin and purpose in this whitelist form: it identified legitimate, RE-linked apps, not apps flagged as fraudulent.
- •September 2022-August 2023 (per a Rajya Sabha reply dated 6 February 2024): Following RBI’s list and a Google policy update restricting Play Store loan-app listings to RBI-regulated entities or their partners, Google removed more than 2,200 fraudulent or predatory loan apps from the Play Store in that window.
- •February 2023: MeitY, acting on a Ministry of Home Affairs referral, blocked 232 apps under Section 69A of the Information Technology Act, 2000, of which 94 were identified as unauthorized digital lending apps with Chinese ownership links, some charging effective annualized interest rates reported as high as 3,000% and using extortion-style recovery tactics; the remaining apps in that action were betting and gambling platforms.
- •To date, per a Lok Sabha reply dated 2 December 2025: MeitY has blocked a cumulative total of 87 illegal digital lending apps under Section 69A, citing borrower harassment, fraudulent practices, and misuse of personal data. The same reply noted the Ministry of Corporate Affairs had separately opened investigations into 665 apps with alleged Chinese-linked ownership.
- •October 2023-May 2024 (per media reports citing government figures, reported in July 2024): The Indian Cyber Crime Coordination Centre (I4C), working with the National Internet Exchange of India, disabled 379 websites found to be hosting illegal loan or scam apps, alongside 91 phishing sites.
What Makes a Digital Lending App RBI-Compliant
RBI now runs a public Digital Lending Apps (DLAs) directory on its own website, effective 1 July 2025, built from data regulated entities submitted through RBI’s Centralised Information Management System portal by 15 June 2025. Its purpose is narrow: it lets a customer verify whether an app’s claimed association with a specific regulated bank or NBFC is genuine. RBI does not itself “certify” or endorse apps through this listing; it only confirms an app’s reported linkage to a named regulated entity.
A separate proposal, a body called the “Digital India Trust Agency” (DIGITA), was reported in 2024 as under consideration to formally verify and register authorized apps. No source confirms whether DIGITA was ever formally constituted as its own operating body, or whether its intended function was absorbed into the DLA directory RBI ultimately launched. The DLA directory is the confirmed, currently operating mechanism; DIGITA should be read only as a 2024 proposal, not a body that exists today.
Per RBI’s Digital Lending Guidelines, announced 10 August 2022 and formally notified 2 September 2022 (cited here by date and title, since no separate circular or notification number is publicly confirmed), a Digital Lending App’s access to borrower-device data is restricted: it bars DLAs from accessing a borrower’s phone contact list, call logs, or stored files and media altogether, and permits only one-time access to the camera, microphone, or location, with explicit consent, for defined onboarding purposes such as document or selfie capture, Video KYC, or address verification.
The same guidelines require all disbursal and repayment transactions to happen directly between the regulated lender’s own bank account and the borrower’s, with no intermediary pass-through or pooled third-party account involved, aside from narrow carve-outs such as co-lending arrangements between two regulated entities. They also require every regulated entity to appoint a nodal grievance redressal officer for digital-lending complaints, with contact details published on the lender’s (and its Lending Service Provider’s, or LSP’s) website, and mandate a minimum cooling-off period during which a borrower may exit a loan by repaying only the principal plus a proportionate Annual Percentage Rate, without penalty: at least 3 days for loans with a tenor of 7 days or more, and at least 1 day for shorter-tenor loans.
Per the RBI (Digital Lending) Directions, 2025, issued 8 May 2025, and the April 2024 Key Fact Statement (KFS) rules (both cited here by date only, as with the 2022 guidelines above), a regulated lender must give the borrower a KFS before the loan contract is executed, in simple language the borrower understands, disclosing the lender’s name, the all-in Annual Percentage Rate, the total cost of credit, all applicable fees and penal charges, the recovery mechanism, the grievance redressal officer’s details, and the cooling-off period. The KFS is mandatory for MSME and retail term-loan products (excluding credit cards and corporate loans), and where more than one lender’s offer is being compared, each must be presented in a comparable format.
Separately, Google’s Play Store listing policy for personal-loan apps in India was updated, following RBI/MeitY coordination, to restrict eligible listings to apps published directly by a regulated entity or operating in partnership with one. That’s a platform-level policy, not an RBI enforcement action in itself, and it does not prevent distribution via direct APK download outside the Play Store.
AI Voice Cloning and Deepfakes: What's Actually Documented
RBI has issued a specific advisory on AI-generated impersonation, but it addresses a different scam category than loan recovery. On 20 November 2024, RBI issued a press release cautioning that fabricated (“deepfake”) videos of the RBI Governor were circulating on social media, falsely claiming his endorsement of certain investment schemes, stating that RBI officials are not involved in or supportive of any such schemes and that RBI does not provide financial or investment advice. That advisory is specific to investment-scheme deepfakes; no comparable dedicated RBI advisory naming loan-recovery or lending deepfakes was found.
RBI has separately and repeatedly stated its general position on unsolicited contact, including in a press release dated 6 February 2012: it “never contacts the public via unsolicited phone calls or emails asking for money or any other type of personal information,” and nobody from RBI calls individuals about lottery winnings or funds received from abroad. This is RBI’s long-standing general position, not a statement issued specifically about digital lending or AI-generated voices.
On the general prevalence of AI voice cloning, a McAfee-commissioned global survey of 7,054 respondents across seven countries, including 1,010 in India, reported on 1 May 2023, found that 47% of Indian respondents said they, or someone they knew, had experienced an AI-generated voice scam, roughly double the 25% global average in the same survey. Of Indian respondents who said they’d lost money to such a scam, 83% reported a financial loss, and 48% of those lost more than ₹50,000. McAfee’s researchers said as little as three seconds of sample audio could produce a voice clone with an 85% match to the real voice. This is general voice-cloning-fraud prevalence data, not a lending-scam-specific statistic.
Some consumer-safety commentary online describes fake recovery calls now using AI-generated voices or deepfake video of “RBI officers,” but that specific claim could not be traced to a citable, independently verifiable source in this research pass, and no RBI advisory or reported case names loan-recovery deepfakes specifically the way the Governor deepfake advisory names investment-scheme deepfakes. Until that specific pattern is independently documented with its own named incident, source, or advisory, it reads as a plausible extension of the confirmed investment-scheme deepfake threat and RBI’s general anti-impersonation position into loan-recovery calls, not as an already-documented phenomenon with its own statistics. For a broader look at how AI voice cloning and deepfake impersonation fit into India’s wider bank-fraud picture, see KYCKART’s overview of bank fraud in India.
Where Compliant and Fake Apps Diverge in Practice
A published grievance officer, a comparable-format Key Fact Statement, a DLA-directory listing tied to a named regulated entity, and permission requests scoped to a single onboarding purpose are each requirements of a compliant lending app, cited above. Read together, this points to why fake apps skip all of them: reproducing these features would require the regulatory relationship the apps don’t have.
The same distinction suggests itself in onboarding. RBI’s Digital Lending Guidelines permit only one-time camera, microphone, or location access, collected for a defined KYC purpose such as Video KYC or document capture. Read against KYCKART’s overview of eKYC and digital KYC verification, that narrower, purpose-bound scope is a useful marker of what a legitimate onboarding flow is supposed to ask for, versus the broad, standing access a fake loan app requests under the same “verification” label.
On the complaint side, two public channels carry the referral and reporting load: Sachet (sachet.rbi.org.in), RBI’s dedicated portal for reporting unauthorized deposit-taking, lending, chit-fund, or investment operations, and the National Cyber Crime Reporting Portal, paired with the 1930 helpline, for cyber and financial fraud generally, including fraud connected to loan apps. Both generate trackable references and route complaints to the relevant regulator.
Read together, the enforcement timeline above tells a different story than a single headline number would. RBI’s 2022 whitelist covered 442 apps already linked to its own regulated NBFCs, Google’s Play Store removals covered a separate population measured against its own listing policy, and MeitY’s Section 69A blocks covered yet another population selected for borrower harassment, fraudulent practices, and misuse of personal data. That’s three different tracks, each counting a different set of apps, which is why no single confirmed figure captures how many fake loan apps exist or how many have been shut down. The practical implication for a compliance team is that checking one list, such as the DLA directory, does not by itself establish an app’s full regulatory history, since each enforcement track measures a different population.
The evidence base also isn’t uniform across this piece’s two main threats. The typology, the fee-deduction pattern, and the enforcement timeline are each backed by a named case, a government reply, or app-store data. The AI-deepfake angle rests on a narrower foundation: RBI’s investment-scheme-specific deepfake warning, its long-standing general anti-impersonation position, and general voice-cloning prevalence data with no lending-specific incident attached to any of it. This suggests BFSI institutions get more near-term compliance value from strengthening the well-documented mechanics (permission scope, KFS disclosure, grievance-officer visibility, DLA-directory listing) than from building a deepfake-specific control today, given that the public record doesn’t yet describe deepfake-driven loan-recovery calls as an independently documented, active tactic.
How KYCKART Helps
KYCKART’s onboarding platform is built around the same purpose-bound, one-time verification permissions RBI’s Digital Lending Guidelines require, not the broad, standing device access a fake loan app asks for.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published August 30, 2026
This piece describes publicly available regulatory requirements and reported enforcement actions for informational purposes. It is not legal, regulatory, or compliance advice, and BFSI institutions should consult counsel before making compliance decisions based on it.
KYCKART Intelligence
Verify Once, Not Every Time
KYCKART’s fraud intelligence platform helps BFSI institutions spot the same coercive, data-harvesting patterns fake loan apps use, before they reach your customers.
Explore Fraud Intelligencearrow_forward