Social Engineering

Deepfake scams India: जब आपका चेहरा हथियार बन जाए

Boss/family की AI video से UPI pressure — deepfake कैसे काम करता है, India में क्यों बढ़ रहा है, और family code word सहित अभी के steps।

CyberSathi DeskAI-assisted · editorially reviewed
Deepfake scams India: जब आपका चेहरा हथियार बन जाए

वो video जो आप नहीं थे

Mumbai। Software engineer को “boss” का WhatsApp video call। Screen पर director — familiar cabin — गुस्से में: “Project delay — अभी ₹5 lakh इस account में भेजो, किसी को मत बताना, HR गए तो fired।” नब्बे seconds। Panic में transfer। फिर office call — असली boss पीछे cabin में बैठा था।

Deepfake अब seminar की चेतावनी नहीं — operational reality है। Face, voice, job-loss का डर — तीनों काफी थे।

असल में क्या होता है

Layer 1 — Deepfake: Boss/family/bank officer की photo/video AI tool में (कुछ free, कुछ dark web ₹500–2,000)। 2–3 घंटे में synthetic video। सस्ते में आँखों के पास flicker; महंगे syndicate वाले indistinguishable — lip sync, blink, expression।

Layer 2 — Message: “बेटा गिरफ्तार,” “बेटी भागी,” “payment fail,” “account compromised।” WhatsApp/Telegram/email — spoofed/cloned contact से।

Layer 3 — Pressure: Text phishing से अलग — amygdala real vs synthetic में फर्क नहीं करती। Verify का समय नहीं मिलता; पैसे पहले, call बाद।

Layer 4 — Cash: Mule account / crypto / hawala — पता चलते-चलते तीन hops।

Ground reality (India क्यों)

500M+ smartphones + UPI की गति = पछतावा एक पल देर। Organised syndicates (SE Asia / India) industrial process चलाते हैं — A/B test emotional hooks; “parent + child danger” ऊँची conversion। Verification systems पीछे: deepfake call + good spoofing में लगता है आप bank से बात कर रहे हो।

Bengaluru: 67-year-old teacher को “बेटे” की crystal clear video — hit-and-run, ₹8 lakh bail। एक घंटे में wire। असली बेटा घर से लेने आया — Instagram के तीन पुराने reels से voice/face train हुआ था।

Complication

हर district में deepfake reverse-engineer expertise नहीं। “हम जानते हैं deepfake है — court में prove / Bangkok suspect।” RBI guidelines / bank flags — ₹5 lakh flag हो सकता है; ₹50k “verified” victim खुद authorise कर चुका हो तो देर। Redressal धीमा; हर victim लड़ने की शक्ति नहीं रखता।

असली gap: visual trust vs identity certainty। आँखें कहती हैं ये boss है; डर कहता है obey करो; आँखें झूठ बोल रही हैं।

अभी क्या करें

  1. पैसे/personal info माँगने वाले authority video calls पर trust मत करो। Known number पर वापस call / cabin में जाओ / bank main number (call वाला number नहीं)।
  2. Family financial emergency code word — deepfake Instagram से नहीं निकाल सकता।
  3. Money वाली हर audio/video को deepfake मानो जब तक आपने खुद initiate करके verify न कर लिया।
  4. खुद की videos social पर कम/छोटी — एक “hello” से हज़ार synthetic clips।
  5. Bank को writing में बताओ: large transfer सिर्फ phone/video से authorise नहीं — high-risk protocol, second factor, branch visit।
  6. Parents को example दिखाकर drill — panic call → hang up → original number पर वापस।
  7. Report — CERT-In + local cyber police (victim न भी हो)।

Philosophy कठोर है: synthetic media के युग में scepticism को प्यार से आगे रखना पड़ता है।

Related: Digital arrest · Social engineering · WhatsApp OTP · Mumbai ₹89L loan warning · 1930 FAQ.

Family fridge card (एक पंक्ति)

Video में पैसे माँगे = hang up → known number पर वापस call → code word। असली emergency तीन मिनट इंतज़ार सह सकती है; deepfake नहीं सह सकता।

अगर call “CBI/ED digital arrest” में बदल जाए तो digital arrest playbook चालू करें — video authenticity पर बहस मत करें, isolation तोड़ें।

Frequently asked questions

Video बिलकुल असली लगे तो?

फिर भी known number पर वापस call। Face ≠ proof।

Code word क्यों?

Deepfake social media से pet/teacher नाम नहीं जानता — family secret चाहिए।

Bank video पर transfer approve कराए?

Writing में policy: phone/video alone से large transfer नहीं।

कहाँ report?

CERT-In · local cyber police · 1930 · cybercrime.gov.in

Read next