The CallPhantom campaign shows that mobile fraud does not always need dangerous permissions or advanced malware. These apps reportedly did not even retrieve real call, SMS, or WhatsApp history. They simply used a tempting claim, fake trust signals, and payment screens to turn curiosity into financial loss. That is depressingly effective, because human curiosity remains the most reliable zero-day.


Users should treat any app claiming to show another person’s call history or WhatsApp records as a scam and a privacy red flag. No legitimate app can provide such data for “any number” just because someone paid a subscription. The fact that 28 apps crossed 7.3 million downloads before removal is a reminder that app-store presence is not the same as trust. Consumers should cancel suspicious subscriptions, seek refunds through Google Play where applicable, and avoid entering card or UPI details into apps promising impossible access.


Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss. The 28 apps have collectively racked up more than 7.3 million downloads, with one of them alone accounting for over

Source: Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads via The Hacker News — published 08 May 2026.