Sarah has just switched banks. The branch told her that almost everything is done through the app, so that same evening she opens the app store on her phone and types the bank’s name into the search bar. Five results appear: similar icons, the same colours, near-identical names. One says “Mobile”, another says “Plus”, a third has a slightly different logo. Sarah is tired and would just like to tap “Install” on the first one.
It is a very common scene: searching for an app in the store is the most natural thing in the world. The catch is that the first result is not necessarily the right app. Sometimes it is an advert, sometimes an app from another company with a similar name, and now and then a copy built to look like the real thing and collect logins, data or money.
This recommendation — R25 of the Cyber Welfare Framework — suggests a simple habit: before you install anything, take a moment for checking an app is genuine. You do not need technical skills. You need a couple of minutes and a clear order: start from the service’s official website, then check a few details on the app’s store page.
What this recommendation says
Recommendation R25 states that an app should only be installed once you have checked that it really is the one published by the service you are looking for, starting from that service’s official website or its direct link to the store.
In practice, the check rests on two moves:
- going back to the source: the official website of the bank, the local council, the delivery company or the service tells you which app is theirs and takes you straight to the right page in the store;
- checking the store page: the developer, the exact name, the release date and the number of downloads should all match what you would expect.
An official app store is the distribution platform built into your phone’s operating system, or a recognised alternative catalogue: it is where developers publish apps after a series of checks. The developer is the company, organisation or person who published the app and is responsible for it.
What it is not. It is not the rule about where to download from: that is the job of recommendation R26, which asks you to use official stores only. R25 comes straight after it and is about what to choose even inside the store, because official catalogues are huge and an imitation can stay there for a while before it is taken down. Nor is it an invitation to distrust every app: the vast majority of the apps you download are exactly what they say they are.
Where it applies. To your phone and tablet, to personal and work apps, and to the apps you install on the devices of family members who ask you for a hand. It matters most for apps that handle money, identity, health or communications.
Why it matters
An installed app is not a web page you close and forget. It stays on your device, it receives the permissions you grant it — access to contacts, photos, location, notifications, text messages — and you often trust it with your most sensitive logins: your bank, your email, your digital identity.
The people who create copies rely on three very human things: haste, trust in a familiar logo, and the idea that anything in the store must be safe. Stores do run many checks and remove a lot of imitations; but no automated check is infallible, and days can pass between a copy being published and it being removed. How those checks work, and where they stop, is covered in the post on how app stores check apps.
The concrete consequences of an app that is not genuine show up on four fronts:
- logins handed to the wrong people — a sign-in screen identical to the real one collects your username, password and codes;
- personal data exposed — contacts, photos, messages and location can be read and sent elsewhere, if the permissions allow it;
- unexpected costs — subscriptions started without you noticing, payments approved by mistake, intrusive advertising that eats up data and battery;
- losing control of your device — some copies ask for special permissions that let them act on the screen in your place.
One case deserves special attention: apps that ask you to sign in to a service you already use. Banking, email, payments, health, government services: if the app is fake, the first thing it gets is the very key that opens everything else.
| Benefit of checking | Why it counts |
|---|---|
| You only give your logins to the real service | A fake sign-in screen never receives your password |
| You avoid granting permissions to strangers | Contacts, photos and location stay with whoever you chose |
| You reduce the risk of hidden costs | No subscription started by an app you never wanted |
| You do not rely on the store’s checks alone | You add a filter of your own to the automated one |
| It becomes a quick, repeatable habit | Two minutes, the same checks, for every new app |
A concrete example
Back to Sarah. Instead of tapping the first result, she closes the store and opens the bank’s website, typing the address she finds on her account documents. At the bottom of the page there is a “Get the app” section with buttons for the stores. She taps one: the app’s page opens directly in the store, without going through the search.
Now she compares. The app the website led her to has exactly the bank’s name, and the developer is the bank itself, with the same company name that appears on her paperwork. It has been available for several years, has a long history of updates and a number of downloads that fits a national bank.
Then she goes back to the search and looks at the earlier top result. The name adds “Plus”, the developer means nothing to her, the app appeared three weeks ago and has only a few thousand downloads. The best reviews were all posted on the same day, in almost identical words.
Sarah does not have to establish for certain whether that second app is a scam. It is enough to know that it is not her bank’s app. She installs the one the website pointed her to, and that is the end of it.
When to apply it
The check applies to every new app, but there are moments when it makes an obvious difference.
- When a service asks you to use its app. Banks, local councils, schools, health services, delivery companies, parking, public transport: these are the most imitated apps, because people searching for them trust the name.
- When a message invites you to download something. Texts, emails or chats saying “install the app to track your parcel” or “to unlock your account”: ignore the link, and look for the app starting from the official website.
- When you set up a new or restored phone. This is when you reinstall lots of apps in a row, often in a hurry, searching for them from memory.
- When travelling or going to an event. Tickets, transport in another city, the app for a concert or a trade fair: services you do not know, searched for at the last minute.
- When an app promises to protect or “clean” your phone. This is a category where imitations are common and the permissions requested are very broad.
- When someone asks you to install a remote support app, meaning a program that lets another person see and control your screen: first check who is asking, and through which official channel.
How to apply it
The check takes a few minutes, and it gets quicker every time you do it.
- Start from the service’s official website. Type the address you know, or the one printed on contracts, cards and official letters, rather than using a sponsored result or a link that arrived by message. Look for the section about the app and use the buttons that lead to the store.
- If you search the store directly, use the exact name and do not stop at the first result. The top spots can be taken by adverts, often labelled as such very discreetly.
- Check the developer. It should match the company or organisation that provides the service. The store page usually also lists the developer’s other apps and links to its website: both should fit with what you know.
- Look carefully at the name and the icon. Imitations play on small differences: an extra word (“Pro”, “Plus”, “Mobile”), a swapped letter, an almost identical logo. The name should be exactly the one given on the official website.
- Look at the release date and the number of downloads. What matters is not the figure itself but whether it fits. A nationally known service whose app appeared a few weeks ago with few downloads is a sign worth noticing; a small local association, on the other hand, may have few downloads and be perfectly genuine.
- Read the reviews with a method. Do not stop at the star rating: look at the most recent reviews and the negative ones. Lots of glowing reviews on the same day, in similar words, is a warning sign; the resource on fake app reviews explains why.
- Check the permissions requested. They should make sense for what the app does: a weather app does not need your text messages. To go further, the recommendation on checking what your apps can do explains what each permission means.
- If in doubt, ask the service or wait. Contact the company through the channels listed on its website, or put off the installation. No genuine app needs to be installed within ten minutes.
A broader guide to assessing an app, even when it is not imitating any brand, is in the resource on checking app details before you install.
Common mistakes to avoid
- Choosing the top search result. Being first in the list says nothing about being genuine: it may be an advert, or simply an app with a similar name.
- Trusting the icon and the colours. Copying a logo is easy. What a copy cannot imitate is the right developer and the app’s history.
- Installing from a link received by chat, text or email. Even if the message seems to come from a service you know, the link may lead to a fake page or to an installation file from outside the store.
- Thinking “it is in the store, so it must be the right one”. The store greatly reduces the risk, but it does not check for you that the app belongs to your bank: it checks that the app follows its rules.
- Looking for the “free Pro version”. Paid apps offered for free outside official channels, or “modified” versions, are a classic way of hiding unwanted features.
- Accepting an update offered by a pop-up in the browser. Apps are updated through the store or your phone’s settings, not through a notice that appeared on a website. It is the same principle as the recommendation on keeping your software up to date.
- Installing under pressure. “Download now or your parcel goes back”, “install today or your account will be suspended”: haste is the main tool of the people who make copies.
How this connects to the Cyber Welfare Framework
R25 turns an automatic gesture — search and install — into a conscious choice, without making it slow or complicated.
| Pillar | How this contributes |
|---|---|
| Skills | Knowing how to read an app’s store page: developer, exact name, date, downloads, permissions |
| Awareness | Understanding that an official store reduces the risk but does not choose the genuine app for you |
| Secure Behaviour | Always starting from the service’s official website before installing a new app |
Digital maturity levels.
- FL1 — Basic. You install the first result that roughly matches the name you searched for. It is the most common behaviour, not a fault.
- FL2 — Beginner. For important apps — banking, email, payments — you start from the official website and check at least the developer.
- FL3 — Autonomous. You run the same check for every new app, also looking at the exact name, date, downloads and permissions.
- FL4 — Skilled. You recognise subtler signs, such as suspicious reviews or a change of developer, and you report the imitations you come across to the store.
- FL5 — Expert-Guide. You help family members, colleagues or your organisation turn the check into a shared habit.
R25 consolidates level FL2 and prepares the step up to FL3.
How to check you are applying it properly
Three questions, to be answered honestly.
- The last time you installed an app, did you start from the service’s website or from the top search result?
- Could you say who the developer of your bank’s app is, and where you checked it?
- If you received a text today with a link to install an app, what would you do before tapping it?
Quick checklist
- ☐ I installed my banking, email and payment apps starting from the official website
- ☐ Before installing, I check that the developer matches the service
- ☐ I look at the exact name, not just the icon
- ☐ I compare the release date and number of downloads with what I would expect
- ☐ I do not install apps from links received by chat, text or email
- ☐ When I have a doubt, I put off the installation and ask the service
If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.
In short
Official stores are the right place to download apps from, but inside the store you still need to choose the right one. Imitations rely on familiar names and logos, on haste and on trust.
Checking an app is genuine takes a few repeatable steps: start from the official website and follow its link to the store, check the developer, exact name, date and downloads, read the reviews with a method, weigh up the permissions and, if in doubt, wait.
Digital security does not ask you to stop trying new apps. It asks you to know where they come from before you hand them the keys to your home.
Something to think about. Of the apps on your phone, how many could you say for certain who published?
Explore this recommendation
This recommendation is the pivot of a content unit. Each post looks at a different aspect.
- Impact of fake apps — what gets hit, in terms of the confidentiality, integrity and availability of your data and your device
- Consequences of installing a clone app — the concrete effects on the operational, financial, legal, reputational and personal levels
- What to do after installing a fake app — the mitigations, from prevention to recovery
- Signs of a fake app — the indicators to check before and after installing, and what they mean
- How app stores check apps — the checks run by stores and operating systems, with their advantages and limits
- Cloned and counterfeit apps — the ways imitations are built and spread
Related resources
Short reads from the Resources section, for anyone who wants to focus on a single aspect:
- Check App Details: The Filter Before You Install
- Fake App Reviews: Why the Rating Tells You Little
- Fake Security Apps: When the Protection Is the Problem
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



