A fast-growing scam in the Philippines starts with a message that looks official. Someone claiming to be from SSS, GSIS, the BIR, LTO, the eGov PH app, GCash or your bank contacts you by text, call or Messenger — often warning that your account will be suspended, that you have a pending benefit or refund, or that you need to 'verify' your details right away.
The urgency is deliberate. To 'fix' the problem, they tell you to install an app from a link they send — not from the official Google Play Store or App Store. That file is a disguised APK: a fake version of the government or banking app that actually contains malware.
During installation the app asks you to turn on 'Install from unknown sources' and to grant powerful permissions — most dangerously the Android Accessibility Service, plus access to your SMS and the ability to draw over other apps. People grant these because the app looks like the real thing and the 'agent' on the line is walking them through it.
That's the moment the theft happens. While you think you're logging in or 'verifying', the malware works in parallel: it reads the one-time passwords (OTPs) that arrive by SMS, captures what you type, and can even show a fake login screen on top of your real banking app or remote-control your phone. Using your OTPs and credentials, the scammers log into your bank and e-wallet accounts and transfer the money out — sometimes while keeping you on the call so you 'don't interrupt the verification'.
The red flags are consistent. Government agencies and banks never send app-download links by SMS or DM, and their real apps live only on the official Google Play Store or App Store. No legitimate agency asks you to enable Accessibility for an app, to install an APK from a link, or to read out your OTP. And genuine account issues are never solved by 'install this app in the next five minutes'.
How to protect yourself: only install financial and government apps from the official store, and only follow the official links published on each provider's own page — the same ones we list for each company in our e-wallets and bank listings. Never sideload an APK, never grant Accessibility permission to an app a stranger told you to install, and never share an OTP with anyone — not even someone claiming to be 'support'.
If you already installed a suspicious app: switch your phone to airplane mode immediately to cut its connection, then uninstall it (restart into safe mode if it resists). From a different, clean device, change your online-banking and e-wallet passwords. Call your bank and wallet providers right away to freeze the accounts and dispute any unauthorized transfers.
Then report it — to your bank or e-wallet, to the BSP consumer assistance channel, and to the PNP Anti-Cybercrime Group or the NBI Cybercrime Division. Reporting quickly gives the best chance of stopping or reversing a transfer, and helps warn others before they fall for the same fake app.