Google Pulls 28 ‘CallPhantom’ Android Apps After Millions Are Duped
The case shows how off-platform payments bypass Google refunds.
Overview
- Google removed 28 Android apps from the Play Store and canceled active subscriptions after ESET exposed the CallPhantom scam.
- The apps claimed to reveal any number’s call, SMS, and WhatsApp history but only displayed hardcoded, random entries and did not steal data.
- The cluster drew more than 7 million installs, with reports pointing to especially heavy uptake in India.
- Operators pushed payments through Google Play subscriptions, in‑app card forms, and third‑party or UPI flows designed to look familiar to local users.
- People who paid outside Google Play must seek refunds from their banks or payment providers because Google cannot reverse those charges.