Hyderabad Cyber Crime Police registered two separate FIRs on July 31 against the head of Apple’s App Store in India and officials responsible for Telegram’s compliance and grievance-redressal functions, after two city residents alleged combined losses of over ₹21 lakh in unrelated online fraud cases.
In the first case, a 62-year-old retired resident of Somajiguda told police he lost ₹12.7 lakh after clicking an Instagram advertisement for a stock-trading platform and downloading an app from the App Store, then transferring money in installments over several weeks. In the second, a homemaker from Almasguda said she lost around ₹8.57 lakh after an Instagram job listing led her into a Telegram channel offering paid work rating Google reviews — she was first paid small amounts to build trust, then asked for larger “deposits.”
Cases were registered against the individuals accused of directly running the scams, along with the platforms’ India-level officials, under relevant provisions of the IT Act and the Bharatiya Nyaya Sanhita. This is where readers need to slow down: naming a company official in an FIR is a procedural step, not a finding of guilt. It means police believe there’s enough to investigate that person’s role — often tied to intermediary-liability rules about how a platform responds to takedown requests — not that wrongdoing has been established. It’s also not an isolated move: Hyderabad police have named country-level heads at Google and Meta as co-accused in similar fraud cases in recent weeks, so this fits a wider pattern rather than singling out Apple or Telegram.
What can be addressed reliably is the consumer-safety issue behind such reports. Fraudsters frequently use phishing and other online attack methods to deceive users. Cloudflare’s security guidance identifies phishing among common cyber threats, while the Government of India’s National Cyber Crime Reporting Portal provides an official channel for citizens to report cybercrime.
What is known and what remains unverified
The basic facts above — the ₹21 lakh combined loss, the Hyderabad location, and who was named in the FIRs — are consistent across multiple news reports. What remains unverified is everything downstream of the complaint: how the investigation actually unfolds, and whether it results in any finding against the named officials.
Until primary records or reliable reporting are reviewed, readers should not assume:
- that the named or described officials personally communicated with the victim;
- that the platforms knowingly enabled the alleged fraud;
- that every account, app or message mentioned in the complaint was controlled by the same person;
- that the reported loss and other details have been established by a court; or
- that the filing of a complaint proves criminal liability.
It is also important not to dismiss the broader risk. Messaging services, websites and mobile applications can be misused by impersonators. A logo, profile name, app listing or familiar platform interface is not sufficient proof that the person behind a message is genuine.
How platform-based fraud can reach consumers
Online fraud does not always begin with an obviously suspicious message. A scammer may first create urgency, claim to represent a company or authority, and then direct the recipient to a link, account or application. Phishing is designed to make a person disclose information or take an unsafe action.
Common warning signs include:
- unexpected requests to pay immediately;
- threats of account suspension, arrest, penalties or loss of access;
- requests for passwords, one-time codes or other login information;
- links that imitate the name or appearance of a familiar service;
- instructions to move a conversation away from an official support channel;
- requests to install an unfamiliar app or grant unnecessary permissions; and
- pressure to keep the conversation secret from family, a bank or the police.
Any one sign may not prove fraud. Several signs together, particularly urgency plus a request for money or credentials, should prompt the recipient to stop and verify.
Similar pressure tactics can appear under different stories. For example, parcel impersonation scams may claim that a shipment is detained and demand urgent action. ScamDekho’s guide to the FedEx and DHL parcel scam in India explains how that type of lure can be framed.
Safety checks before trusting a message or app
Whether a message arrives through Telegram, SMS, email or another service, the safest response is to verify it outside the conversation. Do not use the contact number or link supplied by the sender for that verification.
- Pause before acting. Urgency is often used to prevent careful checking. A genuine issue can be verified through an independently located official channel.
- Inspect the destination. Look at the full website address rather than the visible button text. Misspellings, extra words and unusual domains deserve caution. You can also submit a suspicious address to ScamDekho’s URL Checker for an additional check. A tool result should be treated as one signal, not a guarantee.
- Review the message language. Look for demands for secrecy, immediate payment, credentials or one-time codes. ScamDekho’s Scam Message Checker can help identify suspicious wording, but it does not replace independent verification.
- Find the official contact yourself. Open the service’s official app directly or type its known website address. Do not rely on a search advertisement, forwarded number or link supplied by the unknown sender.
- Check permissions. Before installing an app, consider whether its requested access matches its stated purpose. A simple service should not need broad control over unrelated information or device functions without a clear reason.
- Do not share authentication details. Passwords and one-time codes can allow another person to access an account. Treat requests for them as a serious warning.
These checks cannot determine who is legally responsible in the reported Hyderabad matter. They are preventive steps for reducing exposure to phishing and impersonation attempts.
What to do if money or account access is at risk
If you suspect fraud, stop communicating through the suspicious channel. Do not send additional money in the hope of recovering an earlier payment. Do not install more software or follow instructions from someone claiming they can reverse the transaction for a fee.
A practical response is to:
- contact the relevant bank or payment provider using a verified channel;
- change affected passwords from a device you trust;
- review the account for unfamiliar activity;
- retain messages, usernames, payment details, website addresses and transaction records; and
- submit a report through the Government of India’s National Cyber Crime Reporting Portal.
The National Cyber Crime Reporting Portal is the official government channel included in the source material for reporting cybercrime. Provide accurate information and distinguish what you directly observed from what another person told you. Do not alter screenshots or invent details to make a complaint appear stronger.
How to read claims about companies and officials
Cyber fraud may involve several layers: an impersonator, a messaging account, a payment route, a website, an application and the infrastructure used to reach a victim. The appearance of a platform’s name in a complaint does not explain the role of every person associated with that platform.
Readers should look for case-specific documentation before reaching conclusions. Useful questions include:
- Which police unit reportedly registered the case?
- Does the report cite a complaint or another primary record?
- Are the statements allegations, police findings or court findings?
- Have the organisations or individuals concerned responded?
- Is the reported amount a claimed loss or an amount established through investigation?
On this story, most of those questions now have straightforward answers: Hyderabad Cyber Crime Police registered the FIRs on July 31 under IT Act and BNS provisions, based on two victims’ complaints. What’s still open is the one that matters most — whether the investigation finds any actual wrongdoing by the named officials. That’s the part no one can answer yet, including this article.
Frequently asked questions
Were App Store India and Telegram officials confirmed guilty?
No such conclusion is supported by the supplied sources. The source pack does not include case records or a court finding. A report that someone was booked should not be presented as proof of guilt.
Is the reported ₹21 lakh Hyderabad loss confirmed?
Multiple Hyderabad news outlets report the same figure — a combined ₹12.7 lakh and ₹8.57 lakh lost by two separate complainants. That’s consistent sourcing, but it’s still the amount victims told police they lost, not a figure a court has verified.
Does a Telegram message or app-store listing prove legitimacy?
No. The presence of a message on a known platform or an app in a familiar environment does not by itself verify the identity or intentions of the person contacting you. Verify claims through an independently found official channel.
Where can an Indian consumer report suspected cybercrime?
The Government of India’s National Cyber Crime Reporting Portal is an official reporting channel. If an account or payment is at risk, the consumer should also contact the relevant bank or service provider through verified contact details.