It happens to careful people too. You search the app store for your energy supplier’s or your bank’s app, tap the first result and enter your details. A few days later you notice that the developer was not the right one, that the icon was almost the same but not quite, and that the app asked for permissions that had nothing to do with what it was meant for.
At that point it is natural to feel uneasy, or a little embarrassed. There is no need: the people who make fake apps work hard precisely to make them look real. What you do need is to know what to do, and in what order, because some steps only work if they come before others.
This post organises the response into four moments: preventing it from happening again, detecting the signs that something is wrong, responding by taking every power away from the app, and recovering a stable situation. It is the practical side of the recommendation on checking an app is genuine before you install it: here we look at what to do when, just this once, that check did not happen.
Before you start: why the order matters
A fake app is an app that imitates a real service, in its name, its icon or its design, in order to obtain data, money or control of your phone. Not all fake apps do the same amount of harm, and not everything on your phone carries the same weight.
Once the app has been removed, the accounts to secure should be tackled in this order:
- your main email account — it is the key for resetting almost everything else;
- your bank, cards and payment services — especially if you entered payment details in the app;
- the service the app was imitating — any credentials you typed in there should be treated as exposed;
- your phone number and messages — many verification codes arrive by text message;
- cloud storage, photos and documents;
- social networks and messaging apps;
- everything else, at your own pace.
The sequence of steps, on the other hand, is this: uninstall the app, revoke its special permissions, change your passwords from another device, check your accounts and subscriptions, run a scan, report the app, and only if necessary reset the phone. If you have twenty minutes, spend them on the first three steps.
1. Prevention: reducing the chance of it happening again
Start from the service’s official website
What to do. When you need an app from a bank, a courier or a public body, open the service’s official website, typing the address in yourself, and follow the link to the app store that you find there. It is the simplest way to reach the right app without having to pick it out from ten near-identical ones.
Check the developer, the name and the number of downloads
What to do. On the store page, look at who the developer is, meaning the company or person publishing the app: it should match the service. Then check that the name is spelled exactly right, that the app has been around for a while and that the number of downloads is in line with how well known the service is.
Grant permissions only when they are needed
What to do. An app for reading your energy bills has no need for your text messages, or to control your screen. If a request makes no sense given what the app promises, turn it down: this is the principle behind the recommendation on checking what your apps can do.
Keep the system’s protections switched on
What to do. Phones have built-in protection that checks installed apps and flags those known to be harmful. Leave it switched on and keep your system updated, as explained in the recommendation on keeping your software up to date. If an installation is blocked, trust the warning rather than looking for a way round it.
Don’t forget. If someone sends you an installation file in a chat, do not open it: ask for the exact name of the app and look for it yourself, starting from the official website.
2. Detection: noticing early
Look again at the store page of the app you installed
What to do. If you have any doubts, open the app’s page in the store and compare it with the one you reach from the service’s official website. A different developer, a name with one extra letter, a handful of reviews all posted recently: these are concrete clues. The full list is in the post on the signs of a fake app.
Watch how your phone behaves
What to look for. Adverts that appear even outside apps, an icon that disappears after installation, a battery that drains much faster than usual, a phone that heats up for no reason. None of these signs is proof on its own. Taken together, and appearing straight after an installation, they deserve attention.
Notice codes and messages you did not ask for
What to do. A verification code by text message that you did not request, an alert about a sign-in from an unknown device, a password reset email: these may mean that someone is using the credentials you entered in the app. Do not use the links in those messages; go to each service through its official address.
Don’t ignore it. If the store removes the app, or the built-in protection flags it, do not assume it is a mistake: it is time to move on to the response.
3. Response: taking every power away from the app
Here, more than anywhere else, the order matters. If the app is still running, you can turn on aeroplane mode, which cuts all of the phone’s connections, while you carry out the first two steps.
Uninstall the app
What to do. Remove the app from the phone’s settings, in the section dedicated to apps, rather than simply dragging the icon away. If you cannot find the icon, look for the app in the full list of apps: some fake apps hide themselves from the home screen.
If it will not uninstall. When the remove button is greyed out or the app keeps reopening by itself, it has usually given itself special powers. Move on to the next step, then come back here. Some phones also offer a safe mode, a start-up in which only the system’s own apps run: removing a stubborn app from there is often easier. How to turn it on varies from model to model, so look up the procedure on the manufacturer’s official website.
Revoke permissions and the administrator role
What to check. In the security and privacy settings, look for these items, whose names vary depending on the system:
- device administrator: a role that allows an app to lock the screen or prevent itself from being removed. Untick anything you do not recognise;
- accessibility services: designed to help people who find it hard to use the screen, they let an app read and tap everything on your behalf. A fake app that obtains them can see what you type;
- notification access and default text messaging app: these allow an app to read verification codes;
- configuration or management profiles: settings installed separately that can change how the phone behaves. Remove any that were not given to you by your employer or your school.
Why it counts. An app with these powers can go on doing harm even after you have changed your passwords, or stop you from removing it.
Change your passwords from another device
What to do. Use a computer or another phone you trust, not the one the app was installed on. Follow the order of priority: main email account, bank and payments, the imitated service, then everything else. Every password you typed into the fake app, or that you used unchanged elsewhere, should be replaced with a new, unique one.
Why from another device. If the app was reading your screen or what you typed, changing your passwords from the same phone could mean handing them over a second time.
Straight afterwards. Turn on multi-factor authentication, a second check on top of the password, for your main accounts, and use the “sign out of all devices” feature wherever it exists, after changing the password.
Check your accounts and subscriptions
What to check. Bank and card transactions, active subscriptions in the app store, charges on your mobile phone bill, saved payment methods. If you entered your card details in the app, call your bank on the number printed on the back of the card or shown on its official website and ask them to block it: the time allowed for disputing a charge is limited.
A word of caution. In the days that follow you may receive calls from fake bank staff, or fake staff of the imitated service, offering to “help”. A genuine bank will never ask you for codes or passwords over the phone: hang up and call the official number yourself.
4. Recovery: getting back to a stable state
Scan your phone
What to do. Run a check with the system’s built-in protection, which you will find in the settings or in the app store. If you also want to use a security app, install it starting from the developer’s official website: fake protection apps are among the most common imitations of all.
Worth knowing. A clean scan is good news, but not an absolute guarantee. If the signs persist, consider a reset. To understand what these tools really check, and where they stop, read about how app stores check apps.
Report the app to the store
What to do. On the app’s page, if it is still visible, look for the option to report it as misleading or harmful. Let the imitated service know too, through its official website: it often collects these reports so it can ask for the app to be taken down. If you have lost money, you can report it to the police or to your country’s official cybercrime reporting service.
Why it counts. Every report helps get the app out of the store before someone else installs it.
Reset the phone, if necessary
When it is needed. If the app will not let itself be removed, if the signs continue after the scan, or if the phone still behaves strangely, a factory reset returns the phone to the state it was in when you bought it, erasing everything.
What to do first. Save your photos, contacts and documents in a backup, a safety copy of your data. After the reset, do not blindly restore the complete backup of your apps: reinstall them one at a time, starting from the official websites, so that the fake one does not come back.
Let your contacts know, if needed
What to do. If strange messages were sent from your number or your accounts, let the people involved know through a different channel. That way, nobody else installs the same app.
A plan in three twenty-minute sessions
If all of this feels like a lot, here is a version split into three moments.
Session 1 — Straight away (20 minutes)
- Turn on aeroplane mode on the phone with the suspicious app.
- Revoke device administrator, accessibility and notification access.
- Uninstall the app from the full list of apps.
- From another device, change the password for your main email account and turn on multi-factor authentication.
With this one session alone, you have taken control away from the app and secured the account all the others depend on.
Session 2 — The same day (20 minutes)
- Still from another device, change the passwords for your bank, payment services and the imitated service.
- Check transactions, cards and subscriptions; call your bank if you entered payment details.
- Run a scan with the system’s built-in protection.
Session 3 — Over the following days (20 minutes, repeatable)
- Report the app to the store and to the imitated service.
- Check your bank statement again after a few days.
- If the signs persist, make a backup and consider a reset.
In three sessions, you have closed the doors the app had opened.
Frequent mistakes when fixing things
Even people who react straight away tend to stumble at the same points.
- Changing passwords from the same phone. If the app was reading the screen, the new passwords end up in the same place as the old ones.
- Uninstalling and stopping there. If the app was a device administrator or used accessibility services, check that those roles really have been removed.
- Installing the first security app found with a quick search. That is how people end up installing a second fake app.
- Restoring the complete backup after the reset. You risk reinstalling the very app you wanted to get rid of.
- Putting off checking your bank statement. The time allowed for disputing a charge is limited, and the sooner you spot it the simpler it is.
- Trusting callers who offer help. A fake app is often followed by fake support staff: always call back yourself, on the official number.
- Telling nobody out of embarrassment. Reporting it to your bank and to the store is the most useful thing you can do, for yourself and for others.
Operational checklist
Stage 1 — Stop the app
- ☐ Aeroplane mode turned on during removal
- ☐ Administrator, accessibility and notification roles revoked
- ☐ App removed from the full list of apps
Stage 2 — Protect your accounts
- ☐ Passwords changed from another device, starting with email
- ☐ Multi-factor authentication turned on for your main accounts
- ☐ Unknown sessions signed out
Stage 3 — Check and report
- ☐ Transactions, cards and subscriptions checked
- ☐ Bank informed, if you entered payment details
- ☐ App reported to the store and to the imitated service
Stage 4 — Consolidate
- ☐ Scan completed with the built-in protection
- ☐ Reset carried out, if the signs remained
- ☐ New apps installed only by starting from the official website
A short scenario
Helen searches the app store for her gas and electricity supplier’s app, installs the first result and enters her customer account login and her card details to pay a bill. The app also asks her to turn on accessibility “so that it works better”. Two days later she receives a verification code from her bank that she did not request.
She does not open her banking app on the same phone straight away. She turns on aeroplane mode, takes accessibility and the administrator role away from the app, and uninstalls it. Then, from the computer at home, she changes her email password and her bank password, and calls the number on the back of her card to have it blocked. In the evening she checks her subscriptions, runs a scan and reports the app to the store.
An hour in all, in the right order. If she had changed her passwords from the phone with the app still active, she would have handed them over again.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to carry out, in the right order, the steps that take power away from a fake app |
| Awareness | Understanding why special permissions matter more than the icon, and why passwords must be changed elsewhere |
| Secure Behaviour | Reacting calmly and methodically, and installing future apps by starting from the official website |
Reference level: FL2 — Beginner. This is the level at which you recognise the main risks and follow a clear sequence of steps, without needing any particular technical skills.
Conclusion
Installing a fake app is not a failing, and it is almost always a fixable problem. What makes the difference is the order: first take control away from the app, then secure your accounts from a clean device, then check, report and, only if needed, start again from scratch.
What to do right now. Open your phone’s settings today and see which apps have the device administrator role or access to accessibility services. If you find one you do not recognise, you already know where to start.
To see where you stand, the digital resilience self-assessment gives you a reference point.
Related content
- Checking an app is genuine — the recommendation this belongs to
- How app stores check apps — the checks that work before and after installation, and their limits
- Signs of a fake app — what to watch in order to notice in time
- Consequences of installing a clone app — what you avoid by acting early
- Cloned and counterfeit apps — what you are protecting yourself against
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- Check App Details: The Filter Before You Install
- Fake Security Apps: When the Protection Is the Problem
- Fake App Reviews: Why the Rating Tells You Little
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



