India’s DigiLocker platform faces rising threats from counterfeit websites and apps, with scammers targeting students and parents amid higher stakes as official documents become vulnerable to impersonation and fraud.
By late May 2026, India’s warning over counterfeit DigiLocker services had broadened from bogus mobile downloads to a fake examination-results website aimed at students and parents. The Ministry of Electronics and Information Technology and DigiLocker said a sham portal posing as a CISCE-linked service was trying to exploit board-results traffic, and urged users not to interact with it or enter personal details. That escalation followed app-store alerts issued in late November and early December 2025 about cloned DigiLocker apps circulating under misleading names. (timesofindia.indiatimes.com)
The stakes are unusually high because DigiLocker is woven into everyday official life in India. The platform’s website says the MeitY-backed service now has more than 70 crore registered users and more than 900 crore issued documents. Its terms state that documents issued or shared through DigiLocker are legally equivalent to physical originals, while an official case study says it holds more than 80 crore educational certificates and that CBSE has been publishing Class X and Class XII marksheets there on the same day for the past five years. That reach helps explain why school-result periods have become such a tempting opening for scammers. (wb.digilocker.gov.in)
The first public warning in this run of alerts came on 29 November 2025, when the government’s Digital India account told users: “Protect your important documents using only the authentic DigiLocker application.” Moneycontrol reported that anyone who had already installed a suspicious version was told to delete it immediately and change passwords for linked accounts. NDTV Profit said a second government post, published on 1 December, sharpened the message by saying there was “only one genuine DigiLocker app” and cautioning users against lookalike icons and generic developer names. (moneycontrol.com)
Across the advisories and follow-up coverage, the red flags were simple but easy to miss in a hurry: confirm that the developer is the National e-Governance Division, Government of India; use official government links rather than forwarded messages; and treat spelling mistakes, vague publisher names and odd-looking icons as warning signs. The Times of India added that students should inspect app permissions and reviews, because unnecessary access requests, low ratings and suspicious comments can signal a fake. Financial Express reported that the warning covered both Google Play and Apple’s App Store, underscoring that even mainstream storefronts are not enough on their own to prove authenticity. (ndtvprofit.com)
The later website alert showed how quickly that deception can evolve. According to The Times of India, the fake CISCE-linked portal was designed to lure families looking for marksheets and certificates and then prompt them for Aadhaar numbers, OTPs, passwords, bank details or payment information. Telegraph India reported that officials also said the site had no connection to the National Academic Depository, widening the circle of institutions being impersonated. The official advice was blunt: “Do not share OTP or passwords”, and verify the web address before using any education service online. (timesofindia.indiatimes.com)
The scam, however, is not new. The Indian Express reported as far back as September 2016 that Google Play was carrying at least seven apps with “Digilocker” in their names, some decorated with Prime Minister Narendra Modi’s photograph and the national emblem to appear official. At the time, the genuine app had roughly 5 lakh downloads, while copies had attracted between 10,000 and 50,000 installs; one clone even held a higher rating than the real version. The paper also said Google’s automated “Bouncer” checks took time to identify the mimics. (indianexpress.com)
That long history matters because DigiLocker was built to replace routine dependence on paper records, not just to store files. The official platform describes itself as a secure, government-backed cloud service for storing, sharing and verifying documents, and says those records can be used as authentic digital documents. When criminals succeed in imitating a service with that kind of official standing, the likely prize is access to personal and financial information that users ordinarily trust the state to handle safely. (digitallocker.gov.in)
For users, the practical advice has barely changed across a decade of warnings: install DigiLocker only through official government links and verified app-store listings; if something looks wrong, remove it at once; change passwords for any linked accounts; and ignore install links sent over messaging apps or social media. The government has also urged users to report suspicious listings when they spot them, an acknowledgement that the fakes do not disappear for long but tend to return in slightly altered forms. (moneycontrol.com)
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





