Deepfake fraud surge targets Indian financial institutions: Seqrite report

Share:
Audio Loading voice…
Deepfake fraud surge targets Indian financial institutions: Seqrite report

Synopsis

India's financial sector is confronting a new AI-powered threat: deepfake fraud that mimics executives and customers well enough to authorise transactions and take over accounts. With 265.52 million threat detections logged in a single year and legacy verification systems still widespread, the Seqrite report is a warning that the trust layer underpinning Indian banking is under direct attack.

Key Takeaways

Seqrite (Quick Heal Technologies) released a cybersecurity report on 18 May 2025 flagging deepfake-enabled fraud as a critical threat to Indian financial institutions.
AI-driven attacks use synthetic voice, video, and identity manipulation to bypass traditional verification and enable account takeovers and fraudulent payments.
Over 265.52 million detections were recorded across more than 8 million endpoints between October 2024 and September 2025 — averaging 505 detections per minute .
Trojans accounted for 43% of detections; file infectors for 35% , with many campaigns using social engineering as the entry point.
Breaches can trigger violations of the Digital Personal Data Protection (DPDP) Act, 2023 , exposing institutions to regulatory penalties.
The report recommends a shift to dynamic, behaviour-led validation and multi-layered authentication across transaction flows.

Deepfake-enabled fraud powered by artificial intelligence is rapidly emerging as a high-impact attack vector against Indian financial institutions, their customers, and broader transaction ecosystems, according to a new report released on Monday, 18 May 2025. The findings, published by Seqrite — the enterprise security arm of cybersecurity firm Quick Heal Technologies Limited — warn that AI-driven impersonation attacks are now sophisticated enough to defeat traditional verification systems.

How Deepfake Attacks Work

The report details how attackers deploy synthetic voice, video, and identity manipulation to convincingly mimic bank executives, relationship managers, or customers. This enables fraudulent transaction authorisations, account takeovers, and real-time payment manipulation — all without triggering conventional security alerts.

These attacks are particularly effective in high-velocity transaction environments, where the speed of processing routinely outpaces verification depth. By embedding themselves within legitimate communication channels — including phone calls, video-based KYC verifications, and internal approval workflows — deepfake intrusions are significantly harder to detect than conventional phishing or malware campaigns.

Scale of the Threat

The scale of the broader threat landscape is striking. Seqrite recorded over 265.52 million detections across more than 8 million endpoints between October 2024 and September 2025, averaging 505 detections every minute. Trojans accounted for approximately 43% of all detections, while file infectors made up around 35%. The report noted that many of these campaigns relied heavily on social engineering and identity deception as the initial point of compromise — the same techniques that underpin deepfake-based fraud.

Regulatory and Compliance Exposure

The report flags significant legal risk under the Digital Personal Data Protection (DPDP) Act, 2023, which mandates that financial institutions safeguard personal data and ensure secure processing across all digital interactions. A successful deepfake-led breach can result in unauthorised data access, identity misuse, and direct compliance violations — exposing organisations to regulatory penalties and lasting reputational damage.

This comes amid growing regulatory scrutiny of data security practices in India's financial sector, with the Reserve Bank of India (RBI) having already tightened fraud-reporting norms in recent years. Notably, deepfake fraud represents a qualitative escalation: unlike brute-force attacks, it exploits the trust architecture that financial systems are built upon.

What Institutions Must Do

Seqrite urged a structural shift away from static identity verification toward dynamic, behaviour-led validation. Specific recommendations include strengthening multi-layered authentication, deploying anomaly detection across transaction flows, and actively monitoring communication channels for manipulation signals.

The report forecasted that the next generation of threats will be increasingly AI-driven, adaptive, and capable of bypassing conventional security controls — a trajectory that demands proactive investment rather than reactive patching. Industry observers note that Indian banks and non-banking financial companies (NBFCs), many of which still rely on legacy verification frameworks, face disproportionate exposure.

Point of View

Especially smaller NBFCs and cooperative banks, still depend on video-KYC and voice-based verification frameworks that were never designed to withstand synthetic media. The DPDP Act creates a compliance hook, but regulation alone will not close the gap. The real challenge is that deepfake attacks scale cheaply while defences require sustained investment. Until dynamic behavioural authentication becomes standard practice rather than a premium add-on, Indian financial institutions will remain disproportionately exposed.
NationPress
11 Aug 2026

Frequently Asked Questions

What is deepfake-based fraud in the context of Indian financial institutions?
Deepfake-based fraud uses AI-generated synthetic voice, video, or identity data to impersonate bank executives, relationship managers, or customers, enabling attackers to authorise fraudulent transactions, take over accounts, or manipulate payments. According to the Seqrite report released on 18 May 2025, these attacks are now accurate enough to defeat traditional verification mechanisms used by Indian financial institutions.
How widespread is the cybersecurity threat to Indian financial institutions?
Seqrite recorded over 265.52 million threat detections across more than 8 million endpoints between October 2024 and September 2025, averaging 505 detections every minute. Trojans accounted for 43% of detections and file infectors for 35%, with many campaigns using social engineering — the same technique that underpins deepfake fraud.
What legal risks do Indian banks face from deepfake breaches?
Under the Digital Personal Data Protection (DPDP) Act, 2023, financial institutions are required to protect personal data across all digital interactions. A deepfake-led breach can result in unauthorised access, identity misuse, and compliance violations, exposing organisations to regulatory penalties and reputational damage.
What steps should financial institutions take to defend against deepfake fraud?
The Seqrite report recommends moving from static identity verification to dynamic, behaviour-led validation. Institutions should implement multi-layered authentication, deploy anomaly detection across transaction flows, and monitor communication channels for manipulation signals to stay ahead of AI-driven threats.
Why are financial institutions particularly vulnerable to deepfake attacks?
Financial institutions operate on trust-driven interactions across customers, vendors, and internal systems. Deepfake fraud exploits this trust layer by embedding within legitimate channels such as calls, video verifications, and approval workflows. In high-velocity transaction environments, speed often outpaces verification depth, making these attacks especially effective.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 months ago
  2. 2 months ago
  3. 3 months ago
  4. 4 months ago
  5. 5 months ago
  6. 9 months ago
  7. 10 months ago
  8. 1 year ago
Google Prefer NP
On Google