
India's escalating deepfake threat is being driven less by frontier artificial intelligence models and more by customised applications built on open-source models, enabling fraudsters to create increasingly sophisticated scams at significantly lower costs. According to reports from Business Standard, the threat has begun to permeate the banking, financial services and insurance sector, with fraudsters generating synthetic bank statements and manipulating live Know Your Customer checks to bypass defences. An industry source revealed that cases have been processed and underwritten, leading to frauds of ₹15-20 crore at an NBFI. The rapid proliferation of such tools among organised fraud networks is likely to have prompted the Indian Cyber Crime Coordination Centre (I4C) to issue an advisory warning that fraudsters are using AI-powered techniques to circumvent existing cybersecurity safeguards.
The fraudsters are using smaller AI models that can be run on local consumer hardware like gaming computers, making the cost of organised fraud increasingly affordable. As reported by Business Standard, Sandesh GS, chief technology officer at Bureau, explained that fraudsters use these smaller models to generate deepfakes and distribute them through Telegram channels and dark-web marketplaces. The models are shared across these platforms, allowing widespread access to sophisticated fraud tools without requiring significant investment. Prakarsh Paritosh, principal product manager at Idfy, noted that these are wrappers built on top of open source large language models, which are easily available at fairly cheap costs. The expertise required for sophisticated attacks has decreased significantly, with fraudsters not using standard frontier models that require trillions of tokens to train.
The industry reported frauds worth ₹48,021 crore in FY26, up 46.4% from ₹32,803 crore in FY25, according to data released by the Reserve Bank of India. Despite fewer fraud cases being reported, the total value of money involved rose to its highest in three years, driven by cheating in loans and advances, with the majority concentrated in state-owned lenders. The Indian Cyber Crime Coordination Centre (I4C) has issued an advisory warning that fraudsters are using AI-powered techniques to circumvent existing cybersecurity safeguards, recommending that customer onboarding systems integrate deepfake detection mechanisms. The I4C has called on users to report suspicious activity and identity theft to the national cybercrime reporting portal.
Deepfake injection involves injecting images into compromised devices that can defeat likeness checks, as well as AI-based document tampering. As reported by Business Standard, these deepfakes can pass most likeness-matching checks, especially when KYC is designed around the principle that a live human face on camera is proof of presence and life. Industry executives explained that these fraud models are specifically trained for deepfakes and can be built on open source large language models at fairly cheap costs. Since most deepfakes are generated using models trained for malicious intent, they bypass GAN fingerprints or synthetic IDs, which are unique identifiers used to detect deepfakes. These are invisible patterns left behind images or data that result in patterns that can detect deepfakes.
The threat extends beyond the BFSI sector to e-commerce and quick commerce platforms, social media sites, and dating apps. According to Prakarsh Paritosh from Idfy, sophisticated mule networks carry out these frauds, with frontier models around identity accounts creating fake cohorts to exploit vulnerabilities. Industry executives noted that since most deepfakes are generated using models trained for malicious intent, they bypass GAN fingerprints or synthetic IDs. The I4C has recommended that customer onboarding systems, including fintech companies, should integrate deep fake and synthetically generated content detection mechanisms. The challenge lies in securing devices themselves, as fraudsters can inject images or deepfakes into compromised devices, making detection extremely difficult for normal users.