You Already Installed It: What To Do Now
Most guidance stops at do not click. This page is for the situation after someone has already installed a malicious file, which is when order of operations decides how much is lost.
How the scam runs
The moment an attacker holds SMS and notification access, they are racing to authenticate into accounts before the victim reacts. Every minute matters, and the instinctive first move, opening the banking app to check the balance, is close to the worst one because it can expose credentials to an app that is now watching the screen and messages.
The correct first action is to cut the device off from the network. Enable airplane mode, or remove the SIM. This severs the channel the attacker needs to receive intercepted codes, and it does so without requiring you to unlock anything sensitive on the compromised device.
Only then, from a different and trusted device, contact the bank to freeze accounts, and change passwords on the accounts tied to that phone number. Uninstalling the app is important but comes after containment, because uninstalling first does not undo access already established through a live session.
Signals that give it away
Battery draining unusually fast, or the device running hot
Malicious apps that monitor messages and forward data run continuously in the background. Sudden battery or heat changes after installing something are a strong signal the app is still active.
Bank notifications stopping, or arriving late
Some of these apps suppress or intercept notifications so fraudulent transactions go unnoticed. Silence from an account that normally notifies you is a warning, not a relief.
An app you do not recognise, sometimes with a blank or generic icon
After installation the app often does not appear under the name that was advertised. Check the full application list in settings rather than the home screen, since the icon may be hidden.
The one rule that stops it
Contain before you investigate. Airplane mode or SIM removal first, then call the bank from a different device, then change passwords, then uninstall. Checking your balance on the infected phone is the one action to avoid.
These pages describe fraud tactics for defensive awareness and staff briefing purposes. They are general information, not legal or financial advice. If you have lost money, report it through official channels: the police cyber crime unit, your bank, and for investment or lending matters, OJK.
Frequently asked questions
Your exposure is much lower, because interception requires the SMS and notification permissions. Still uninstall the app, and monitor accounts for unexpected activity, since some variants request permissions again later or use other access paths.
Related pages
The Wedding Invitation That Is Not An Invitation
The single most successful disguise for a malicious APK in Indonesia, because a wedding invitation from an unknown number is socially plausible rather than suspicious.
Learn morePhone Scams: Fake Police, Tax and Courier Calls
A caller claiming authority, a problem only they can solve, and pressure to act while still on the line. The technique has a name: vishing.
Learn moreThe Wrong Transfer Setup
Money you did not expect arrives, followed by someone asking for it back. Returning it directly is the trap, and it often connects to an illegal loan taken in your name.
Learn moreTurn awareness into measured behaviour
Reading about scams does not change what people click. Claro runs bilingual simulations across email, WhatsApp, SMS and voice, then measures who is actually resilient.
See how Claro measures it