Social Engineering

Deepfake Scams in India: When Your Face Becomes a Weapon

Deepfake fraud is no longer science fiction. Real Indians are losing lakhs to AI-generated videos of themselves. Here's what's actually happening—and how to defend yourself.

CyberSathi DeskAI-assisted · editorially reviewed
Deepfake Scams in India: When Your Face Becomes a Weapon

The Video That Wasn't You

Mumbai, three weeks ago. A software engineer received a WhatsApp message from his "boss"—a video call request. He answered. On screen was his director, sitting in the office cabin he recognised. The man was furious. "Why is the project delayed? I'm cancelling your appraisal unless you wire ₹5 lakhs to this account right now. Do not tell anyone. If you go to HR, you're fired."

The call lasted ninety seconds.

He transferred ₹5 lakhs in a panic. Then he called the office. His boss answered from the cabin behind him. He was still there.

I feel that we have not yet grasped how dangerous this moment is—not because the technology is new, but because the technology works. Deepfake video fraud has crossed from theoretical threat into operational reality on Indian ground. It is no longer something we warn about in seminars. It is something someone you know has already fallen victim to. The face in the video was convincing enough. The voice was convincing enough. The social pressure—the terror of job loss, shame, disgrace—was more convincing than both.

And it worked.

What Actually Happens

A deepfake scam unfolds in layers, each layer designed to exploit a different kind of trust.

Layer 1: The Deepfake Scammers source a photograph or video of the target—your boss, a family member, a bank officer. They feed it into an AI tool (many freely available on GitHub, some sold on dark web forums for ₹500–₹2,000). In 2–3 hours, they have a synthetic video of that person saying words they never spoke. The quality varies. The cheap ones have a slight flicker around the eyes. The expensive ones—the ones the organised syndicates use—are indistinguishable from reality. The lips sync. The expressions change. The person blinks at natural intervals.

Layer 2: The Message The deepfake is weaponised through a social engineering script. "Your son has been arrested." "Your daughter has eloped with a boy." "Your payment has failed; urgent action needed." "Your account is compromised; verify immediately." The video arrives via WhatsApp, Telegram, or email. It comes from a phone number or email that looks like it came from someone you trust—spoofed, cloned, or impersonating a known contact.

Layer 3: The Pressure Unlike text-based phishing, the video creates a visceral sense of reality. You see the person's face. You hear their voice. Your amygdala—the fear centre—does not distinguish between a real video and a synthetic one recorded five minutes ago. It sees authority. It sees emotion. It sees urgency. The scammer knows you will not have time to verify. They know you will call your boss, your bank, your son—but only after you have already sent the money because the video felt real enough to bypass rational thought.

Layer 4: The Cash Money flows to a proxy account—often a mule account opened with fake Aadhaar, or a cryptocurrency wallet, or a hawala network contact. By the time the victim discovers the truth, the money has moved three times and vanished into the grey economy.

The Ground Reality

Why is this happening now in India specifically?

First: India has 500+ million smartphone users and a deepening digital payment culture. We move money faster and more casually than almost any nation on earth. UPI transactions are near-instant. Regret arrives a moment too late.

Second: Organised fraud syndicates—many operating from Southeast Asia, some from within India—have industrialised the process. They are not random hackers. They are businesses. They have customer service departments. They run A/B tests on which emotional hooks work best. They know that a video of a parent claiming a child is in danger has a 60% conversion rate. They know that impersonating a bank officer has a 40% rate. They test, measure, optimise, scale.

Third: Our verification systems have not caught up. A bank officer may ask, "Can you verify your identity?" You prove who you are. Then they say, "Please confirm the OTP we've sent." But if the person calling is a deepfake, and the phone spoofing is good, you may believe you are speaking to the bank even while the bank's fraud team is trying to reach you on another line.

I watched a case in Bengaluru where a 67-year-old retired teacher received a video of her son—crystal clear, unmistakable—saying he was in jail for a hit-and-run accident and needed ₹8 lakhs bail. She wired the money within an hour. When her son picked her up from her house an hour later, she fainted. He was never in jail. She had never seen him look so frightened. "Mom, that wasn't me. That wasn't even a video of me. That was someone else's face overlaid with my voice extracted from my Instagram reels."

He had posted exactly three videos to Instagram in five years.

They had used all three to train the algorithm.

The Complication

Here is the hard part: no law enforcement agency in India is well-equipped to investigate deepfake fraud yet. CERT-In publishes alerts. The cyber police have registered cases. But investigation requires expertise that is not yet present in every police district. CyberSathi Desk has spoken to investigators in four states, and the pattern is the same: "We know it's deepfake. We can't prove it in court. We don't have the equipment to reverse-engineer the synthetic video, and the suspect is in Bangkok."

RBI has issued guidelines. Banks are supposed to flag suspicious transactions. But a transaction flagged at ₹5 lakhs is flagged. A transaction flagged at ₹50,000 is sometimes approved because the victim is "verified" (the deepfake call convinced them to authorise it themselves). By the time the bank's fraud team moves, the account has been drained and closed.

Yes, RBI has a consumer redressal mechanism. Yes, many banks have paid back victims. No, the process is not fast. No, not every victim has the emotional strength to fight through it.

The real problem is this: deepfake scams exploit a gap between visual trust and identity certainty. Your eyes tell you this is your boss. Your fear tells you to obey. But your eyes are lying. And by the time you verify the truth, your bank account has told the real story.

What You Can Do Right Now

I do not have a perfect solution. But I have a set of practices that shift the odds in your favour.

  1. Never trust video calls from authority figures requesting money or personal information. Not "be cautious of." Never. Call them back on a known number from your records. Verify before you respond. If it's your boss, walk to their cabin. If it's your bank, call the main branch number, not the number shown on a call.

  2. Set up a verbal code with family members for financial emergencies. Your son has been arrested—but before money changes hands, he must answer a question only he knows the answer to. A childhood pet's name. The name of your first teacher. Something a deepfake cannot extract from social media.

  3. Assume every audio or video message requesting money is deepfake until proven otherwise. This sounds extreme. Good. Extremism is warranted. Verify in person or on a phone line you initiated, not one that called you.

  4. Do not post videos of yourself on social media. I understand the appeal. I understand it feels small and private. But a single video of you saying "hello" can be used to generate a thousand synthetic videos of you saying anything. If you must post—keep videos short, keep them rare, keep your face partially obscured when discussing money or work.

  5. Inform your bank that you will never authorise large transfers via phone call or video call alone. Submit this in writing. Ask them to flag your account. Most banks have a "high-risk transaction" protocol—use it. Require a physical visit, a confirmed email from a registered address, a second person in the room. Make it inconvenient for scammers to impersonate you to your own bank.

  6. Teach your parents this, explicitly, with examples. Show them a deepfake. Let them see how real it looks. Then tell them: if their grandchild calls in a panic, they must hang up and call the grandchild back on the original number. Write the family rule down. Repeat it annually.

  7. Report suspected deepfake videos to CERT-In (cert@cert.org.in) and your local cyber police. Even if you are not a victim, even if you are not sure—report it. Data points help. Patterns emerge. Intelligence builds.

The philosophy emerging here is hard but necessary: In an age of synthetic media, your scepticism must exceed your love.

That is not comfortable. But it is the price of safety.

Read next