The National Bank of the Republic of Tajikistan has warned that fraudsters are distributing malicious .apk files through social media, Telegram, WhatsApp and other communication channels. The files may be disguised as banking applications, documents, receipts, wedding invitations or photos. Installing them can give fraudsters access to mobile devices, personal data, SMS messages, banking applications and electronic wallets, enabling the theft of funds. Users should not download .apk files from unknown or unverified sources, open suspicious links or disclose PINs, passwords and one-time SMS codes. They should verify the source of files and messages even when these appear to come from a known person, bank, government authority or other organization. Financial credit institution employees do not request security credentials or ask customers to install unofficial applications. Anyone who has installed a suspicious file or suspects unauthorized access to banking information should immediately contact their servicing financial credit institution.