The Wedding Invitation That Is Not An Invitation
This variant deserves its own entry because it defeats the usual advice. People are trained to distrust messages about money, but an invitation triggers curiosity and social obligation instead of suspicion.
How the scam runs
A message arrives with a warm, personal tone and a file named like a wedding invitation. The sender is often a number the recipient does not recognise, which in most contexts would be a warning, but for an invitation it reads as ordinary: guests routinely receive invitations from numbers they have not saved.
Curiosity does the work that urgency does in other scams. The recipient wants to know whose wedding it is, and whether they have overlooked someone they know. Opening the file offers to install an application, which many people accept because they assume a digital invitation needs a viewer.
From there it behaves identically to any malicious APK: SMS and notification permissions, interception of one-time passcodes, and access to financial accounts. The same pattern circulates as delivery receipts, tax notices and traffic fines, but the invitation version consistently performs best.
Signals that give it away
A digital invitation should be a link or an image, never an app
Real digital invitations are web pages, PDFs or images. No invitation requires you to install software. If viewing it needs an installation, it is not an invitation.
The file name looks like a document but ends in .apk
Attackers name files to read as documents, sometimes with a fake extension earlier in the name. Check what the name actually ends with, because that is what determines how the phone treats it.
You cannot identify the couple, and the message avoids specifics
A genuine invitation names people, a date and a venue in the message itself. Vagueness paired with an attachment means the attachment is the point, not the event.
The one rule that stops it
Curiosity is the payload here, not urgency. If you cannot identify who is getting married from the message text alone, there is nothing to open. Ask the sender directly through a channel you trust.
These pages describe fraud tactics for defensive awareness and staff briefing purposes. They are general information, not legal or financial advice. If you have lost money, report it through official channels: the police cyber crime unit, your bank, and for investment or lending matters, OJK.
Frequently asked questions
The .apk cannot install on iOS, so that specific file will not run. Do not treat the message as harmless though, since the same campaigns send phishing links to iPhone users. Delete it either way.
Related pages
Phone Scams: Fake Police, Tax and Courier Calls
A caller claiming authority, a problem only they can solve, and pressure to act while still on the line. The technique has a name: vishing.
Learn moreThe Wrong Transfer Setup
Money you did not expect arrives, followed by someone asking for it back. Returning it directly is the trap, and it often connects to an illegal loan taken in your name.
Learn moreFake Job Offers and Recruitment Fraud
An offer arrives for a role you did not apply for, from a company name you recognise. The pattern ends in a fee, a data harvest, or a money-laundering role.
Learn moreTurn awareness into measured behaviour
Reading about scams does not change what people click. Claro runs bilingual simulations across email, WhatsApp, SMS and voice, then measures who is actually resilient.
See how Claro measures it