Incident response / mobile

You Already Installed It: What To Do Now

Most guidance stops at do not click. This page is for the situation after someone has already installed a malicious file, which is when order of operations decides how much is lost.

How the scam runs

The moment an attacker holds SMS and notification access, they are racing to authenticate into accounts before the victim reacts. Every minute matters, and the instinctive first move, opening the banking app to check the balance, is close to the worst one because it can expose credentials to an app that is now watching the screen and messages.

The correct first action is to cut the device off from the network. Enable airplane mode, or remove the SIM. This severs the channel the attacker needs to receive intercepted codes, and it does so without requiring you to unlock anything sensitive on the compromised device.

Only then, from a different and trusted device, contact the bank to freeze accounts, and change passwords on the accounts tied to that phone number. Uninstalling the app is important but comes after containment, because uninstalling first does not undo access already established through a live session.

Signals that give it away

Battery draining unusually fast, or the device running hot

Malicious apps that monitor messages and forward data run continuously in the background. Sudden battery or heat changes after installing something are a strong signal the app is still active.

Bank notifications stopping, or arriving late

Some of these apps suppress or intercept notifications so fraudulent transactions go unnoticed. Silence from an account that normally notifies you is a warning, not a relief.

An app you do not recognise, sometimes with a blank or generic icon

After installation the app often does not appear under the name that was advertised. Check the full application list in settings rather than the home screen, since the icon may be hidden.

The one rule that stops it

Contain before you investigate. Airplane mode or SIM removal first, then call the bank from a different device, then change passwords, then uninstall. Checking your balance on the infected phone is the one action to avoid.

These pages describe fraud tactics for defensive awareness and staff briefing purposes. They are general information, not legal or financial advice. If you have lost money, report it through official channels: the police cyber crime unit, your bank, and for investment or lending matters, OJK.

Frequently asked questions

  • Your exposure is much lower, because interception requires the SMS and notification permissions. Still uninstall the app, and monitor accounts for unexpected activity, since some variants request permissions again later or use other access paths.

Turn awareness into measured behaviour

Reading about scams does not change what people click. Claro runs bilingual simulations across email, WhatsApp, SMS and voice, then measures who is actually resilient.

See how Claro measures it