
Cybercriminals have deployed sophisticated AI deepfake technology to promote illegal betting platforms during IPL 2026, according to a report by digital intelligence firm CloudSEK. The criminals used AI deepfake tools to clone the faces and voices of Indian cricketers and popular content creators to fabricate endorsements for betting platforms and tipper channels. As reported by CloudSEK, these videos are produced cheaply and distributed across Instagram reels and Telegram before they can be taken down, making them difficult to remove once they go viral. The operation relies on clone-script betting platforms sold openly on Telegram that can be deployed in days, with new users typically allowed small early wins to build confidence and justify larger deposits before funds are blocked, delayed, or denied outright.
The cybercriminal operations spanned over 1,200 domains actively promoting illegal betting platforms during IPL 2026, according to CloudSEK's report. The company accessed the admin panel of one such platform and found it was simultaneously operating over 25 different betting websites from a single backend, providing full visibility into user deposits, bets, and withdrawal queues. This networked approach allows operators to scale operations while maintaining centralized control over multiple platforms. The ecosystem operates through fake prediction channels where tippers earn affiliate commissions on every rupee their followers deposit, win or lose, with no actual insider knowledge of match outcomes.
The scale of financial losses from these operations became evident when CloudSEK found that more than 9,300 user withdrawal requests were deliberately rejected by agents on a single platform between May 2025 and May 2026. These were not system errors but intentional, single-click denials, resulting in an estimated ₹4.65 crore in potential user losses from just one platform alone. The company also discovered a second admin panel revealing a network of business-registered bank accounts consistent with money mule setups used to receive and move user deposits. Victims who turn to fake loan apps promoted on social media enter a second trap where their personal data is weaponised against them through threats and public humiliation.
The cybercriminal operations extended to compromising multiple Indian government websites with .gov domain extensions, as reported by CloudSEK. These compromised government websites were injected with backlinks pointing to illegal betting platforms, exploiting the trust and search authority of official domains to funnel unsuspecting users toward illegal content. An email query sent to the Ministry of Electronics and IT regarding these findings did not elicit any response from the ministry. The exploitation of government infrastructure for SEO manipulation makes official domains unwitting participants in fraud, with black-hat SEO networks injecting links into compromised websites to manipulate search rankings.
Beneath the platforms, a mature underground economy keeps operations running through multiple channels including money mule networks that receive and move deposits through rented bank accounts, black-hat SEO networks that manipulate search rankings, and bulk SMS operators sending mass unsolicited messages from spoofed IDs. Lead generation services run Meta and Google ad campaigns targeting cricket fans on behalf of illegal platforms. The operation also targets victims after their losses through fake loan apps advertised on social media with promises of instant approval, which harvest contacts, photos, and call logs to coerce repayment through threats and public humiliation. As CloudSEK Researcher Sourajeet Majumder noted, this represents a structured, seasonal criminal industry that grows more advanced each IPL season.