Fake Airport Lounge Access App Scams Over 450 Passengers Out of ₹9 Lakh
Over 450 passengers have lost more than ₹9 lakh (approximately $11,000) through "Lounge Pass," a fraudulent app designed to appear as a legitimate service for airport lounge access.
This deceptive app represents a new and significant threat within the aviation sector, preying on travelers seeking convenient lounge access. Circulated through WhatsApp messages, it directed users to domains such as loungepass[.]in, loungepass[.]info, and loungepass[.]online, all tied to the scam. Once installed, the app intercepted sensitive information, including OTPs (One-Time Passwords) from victims’ mobile devices, allowing the scammers to siphon funds from their accounts.
CloudSEK’s threat research team uncovered the scam, according to their report. The team’s findings, corroborated by authorities, suggest that the issue could be much larger, as multiple similar fake apps are circulating, with this deceptive strategy rapidly spreading.
The scam first gained attention following a viral post on X (formerly Twitter), where a traveler at Bengaluru airport reported losing over ₹87,000 to the fraudulent app.
Over 450 unsuspecting travelers installed the fake "Lounge Pass" app on their Android devices between July and August 2024. Once installed, the app captured incoming SMS messages from the victims’ phones. CloudSEK's investigation revealed a critical flaw in the app's design: scammers had inadvertently exposed their Firebase server endpoint, which stored stolen SMS messages. This vulnerability allowed investigators to assess the scam's scale and track the stolen funds.
The fact that 450 travelers have already fallen victim, with losses exceeding ₹9 lakh, is alarming. With the discovery of just one fraudulent app, it is likely that many similar scams are operational. Travelers are urged to exercise caution and only download apps from trusted, official sources.
Comments
Post a Comment