Poisoned Notifications Hijack Google Gemini on Android
INDIA — By BharatSecure Threat Intelligence Team ·
Category: whatsapp_scam
Verdict Summary
Poisoned Notifications Hijack Google Gemini on Android shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.
Risk score: 7/10 · Severity: High · Verdict: Suspicious
Scam Intelligence: Poisoned Notifications Hijack Google Gemini on Android
Proprietary signals from BharatSecure's scam-tracking database.
| Last reported | Jun 04, 2026 |
How Poisoned Notifications Hijack Google Gemini on Android Works
A vulnerability allows malicious WhatsApp, Slack, or SMS notifications to hijack Google Gemini on Android devices without requiring a malicious app. A single poisoned alert can manipulate Gemini to generate fake messages, trigger actions, join calls, or corrupt its memory.
How This Scam Works — Detailed Explanation
Scammers often look for vulnerabilities within popular platforms and applications to target potential victims. In recent times, a vulnerability in the Android operating system allows poisoned notifications—coming from apps like WhatsApp or Slack—to hijack Google Gemini, which is a virtual assistant widely used in India. By crafting these deceptive notifications, cybercriminals can effectively manipulate Gemini without the need for a malicious app. Victims, often unaware of these tactics, might receive a seemingly innocent notification urging them to take action, leading them down a treacherous path of compromise.
Scammers utilize a variety of psychological tactics to lure users into their traps. One primary method involves creating a sense of urgency. For instance, a notification may falsely claim that an urgent message requires immediate attention or that an ongoing call needs to be joined right away. This approach exploits the normal human reaction to respond quickly to urgent prompts, often bypassing the critical thinking that could prevent a scam. Moreover, the use of familiar platforms such as WhatsApp or Slack serves to lower the defenses of the victims, making them more likely to trust the notifications they receive from these platforms.
Once a victim interacts with the hijacked notification, the consequences can unfold rapidly. For example, if a user thinks they are joining an important group call on Google Gemini, they might unwittingly provide sensitive information like their UPI details or Aadhaar number. One real-world case from Delhi describes a young professional who received a frenzied WhatsApp notification purportedly from a colleague, leading them to disclose bank login details under the guise of participating in a work discussion. As a result, funds worth ₹5 lakh were siphoned off from their account within hours, highlighting how swiftly financial loss can occur due to such scams.
The broader impact of these types of scams is alarming in India. According to recent reports, scams leveraging social engineering tactics have led to losses exceeding ₹1,000 crore in the past year alone. The Ministry of Home Affairs (MHA) has issued advisories regarding rising instances of notification hijacking, and the Reserve Bank of India (RBI) has called for stricter compliance with cybersecurity protocols. Additionally, CERT-In has outlined guidelines to avoid such vulnerabilities, but individuals must remain vigilant against these persistent threats.
Identifying this scam versus legitimate notifications requires a keen eye. A genuine notification from WhatsApp or Google will typically have consistent branding, and any request for personal information or immediate action should spark suspicion. Additionally, legitimate communications will rarely create a sense of panic or urgency. Therefore, if a notification prompts an uncharacteristic or unexpected action, take a moment to verify through official channels rather than responding directly. Trust your instincts, and whenever in doubt, consult official sources or helplines before taking action.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does Poisoned Notifications Hijack Google Gemini on Android Target?
General public across India
Red Flags — How to Identify Poisoned Notifications Hijack Google Gemini on Android
- Slack
- SMS
- Google Gemini
- Android
- notification hijacking
- AI manipulation
- vulnerability
What To Do If You Encounter Poisoned Notifications Hijack Google Gemini on Android
- Report suspicious notifications to the cybercrime helpline 1930 or visit cybercrime.gov.in.
- Do not respond to unknown messages asking for personal information.
- Verify notifications through official app settings or direct communication with contacts.
- Check your bank statement regularly for unauthorized transactions.
- Update your device security settings and install any software updates promptly.
- Educate family and friends about the dangers of notification hijacking scams.
How to Report Poisoned Notifications Hijack Google Gemini on Android in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I shared my UPI details in a poisoned notification scam?
- Immediately contact your bank's helpline, like SBI at 1800-11-1109, and inform them. Additionally, report to 1930 or cybercrime.gov.in.
- How can I identify a poisoned notification?
- Look for unusual requests for personal information or urgent actions that seem out of the ordinary for your contacts.
- How to report this type of scam in India?
- Report incidents to the cybercrime helpline 1930, file a complaint at cybercrime.gov.in, and contact your bank for any unauthorized transactions.
- What steps should I take to recover money lost due to this scam?
- Contact your bank immediately, take screenshots of the scam notifications, and file a police report if substantial amounts are involved.
How This Scam Works — BharatSecure AI
Spreading fastA plain-language breakdown based on 181 real reported scams of this type.
| How they reach you | Reported primary vector is unsolicited WhatsApp messages, group additions, or calls (often from foreign or spoofed numbers), frequently seeded via social media ads, forwarded messages, or malicious AP |
| How they gain your trust | Observed trust is built by impersonating authority (police/CBI, EPFO, UIDAI, RBI, banks, employers, or reputed brokerages) or intimacy (posing as children, romantic partners, or NRIs), reinforced with |
| How they take your money | Documented rails are predominantly UPI transfers and bank transfers to mule accounts, with reported use of fake trading/investment apps, gift cards, a |
| Who they target | Most commonly targeted are urban and semi-urban Indians across a broad spectrum: retail investors and professionals seeking returns, elderly and homemakers vulnerable to KYC/lottery/authority pressure |
- Authority bias (impersonating officials, executives, regulators)
- Fear and urgency (arrest, account freeze, bill cutoff, KYC expiry)
- Greed and FOMO (guaranteed high returns, lottery wins, IPO allotments)
- Unsolicited addition to WhatsApp/Telegram investment groups or messages from unknown/foreign numbers
- Requests to share OTPs, screen-share, or download APKs/links for 'verification' or 'KYC update'
- Pressure and urgency invoking arrest, account freeze, tax demands, or bill disconnection
- Guaranteed high returns, lottery/IPO wins, or advance fees to 'release' funds/prizes
- Impersonation of banks, police/CBI, government schemes, executives, or family members using forged documents and fake screenshots
Related Scams in India
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.