## Anatomy of the Electricity Bill Power-Cut Vector
The **"Electricity Power Cut at 7:00 PM or 9:30 PM"** scam is a precision social engineering attack designed around the fear of darkness and disruption to domestic life.
The Social Engineering Trigger A typical SMS arrives from an unregistered personal mobile number (`+91 98xxx xxxxx`): ``` Dear Consumer, Your electricity connection will be disconnected tonight at 7:30 PM from the electric substation because your previous month's bill was not updated. Please immediately call our electricity officer at 9876543210. ```
Why the 7:00 PM Deadline? The scam intentionally specifies a tight evening deadline (between 6:00 PM and 9:00 PM): - Official electricity board offices are closed, making in-person verification impossible. - Family members are returning home, cooking, or watching TV, amplifying the immediate fear of a blackout. - Victims make hurried, irrational decisions under time stress.
The Malicious APK Delivery Mechanism When the consumer panics and calls the phone number: 1. The scammer answers courteously, pretending to check the consumer database. 2. They state: *"Sir, your ₹10 or ₹12 update fee is pending in the automated gateway. Please install our official Bijli Seva app so we can update your payment status instantly."* 3. The scammer sends an APK file via WhatsApp with names such as `Suvidha.apk`, `Electricity_Update.apk`, or `Mahavitaran_Service.apk`.
Device Takeover & Invisible OTP Interception Once installed: - The app prompts for accessibility services and **READ_SMS** permissions. - It asks the victim to make a nominal ₹10 test payment using net banking or a debit card. - As the user enters card credentials and PIN, the keylogger records every keystroke. - When the bank transmits the critical transaction OTP, the malware intercepts the SMS silently and relays it to an attacker-controlled Telegram Bot before deleting the SMS notification from the victim's notification shade. - Within minutes, recurring transfers drain the victim's primary bank account.
Defensive Action Rules
1. **Verify Sender ID**: Genuine discoms never send disconnection warnings from standard 10-digit personal phone numbers. 2. **Never Side-Load APKs**: Never download files ending in `.apk` shared over WhatsApp, Telegram, or Google Drive links. Official apps exist only on the Google Play Store or Apple App Store. 3. **Pay Exclusively Through Official Channels**: Settle utility bills only through certified BBPS (Bharat Bill Payment System) platforms like bank apps, BHIM, PhonePe, or the utility's official SSL-secured website.