
Not every app in the store is what it claims to be. Fake apps imitate popular banks, wallets and games to trick you into installing them, then steal your logins, drain accounts or bury your phone in ads. A few quick checks before you tap “install” will catch almost all of them. Our GetMyPassword team explains how to spot a fake app and keep malware off your phone.

Check the developer and the source
Start with who made it. Tap the developer name and confirm it matches the real company — fakes use slight misspellings or unknown publishers. Install only from official stores, and for banking or crypto apps, follow the link from the company’s own website. Avoid sideloading apps from random sites, which is how most mobile malware gets in.
Read the listing critically
- Download count: the real app of a big brand has millions, not hundreds.
- Reviews: watch for very few reviews, or a flood of generic five-star ones.
- Release date: a “major bank” app published last week is a red flag.
- Spelling and screenshots: typos and low-quality images signal a fake.
Watch the permissions
Before and after installing, check what the app asks to access. A flashlight or calculator that wants your contacts, messages and accessibility controls is a warning sign. Be especially careful with requests for SMS access or accessibility permissions, which malware abuses to steal two-factor codes and read your screen.
The most dangerous fake apps copy your bank or crypto wallet down to the logo. The login screen looks perfect — because its only job is to capture the password you type into it.
If you already installed one
Uninstall it immediately, then change the passwords of any account you opened in it — starting with email and banking — using our password generator for fresh, unique ones. Run a security scan, check for unfamiliar logins, and enable two-factor authentication so a stolen password alone cannot get in. Acting fast turns a scare into a near miss.
Frequently asked questions
How can I tell if an app is fake?
Check the developer name, download count, reviews and release date, and watch for misspellings or excessive permission requests. A brand-name app with few downloads or a recent publish date is likely a fake.
Are apps in official stores always safe?
They are much safer, but not perfect — fakes occasionally slip through before removal. Still verify the developer and reviews, and never sideload banking or crypto apps from outside the official store.
What should I do if I installed a fake app?
Uninstall it at once, change the passwords of accounts you used in it starting with email and banking, run a security scan, check for unfamiliar logins, and enable two-factor authentication on those accounts.



