Deepfake fraud surge targets Indian financial institutions: Seqrite report
Synopsis
Key Takeaways
Deepfake-enabled fraud powered by artificial intelligence is rapidly emerging as a high-impact attack vector against Indian financial institutions, their customers, and broader transaction ecosystems, according to a new report released on Monday, 18 May 2025. The findings, published by Seqrite — the enterprise security arm of cybersecurity firm Quick Heal Technologies Limited — warn that AI-driven impersonation attacks are now sophisticated enough to defeat traditional verification systems.
How Deepfake Attacks Work
The report details how attackers deploy synthetic voice, video, and identity manipulation to convincingly mimic bank executives, relationship managers, or customers. This enables fraudulent transaction authorisations, account takeovers, and real-time payment manipulation — all without triggering conventional security alerts.
These attacks are particularly effective in high-velocity transaction environments, where the speed of processing routinely outpaces verification depth. By embedding themselves within legitimate communication channels — including phone calls, video-based KYC verifications, and internal approval workflows — deepfake intrusions are significantly harder to detect than conventional phishing or malware campaigns.
Scale of the Threat
The scale of the broader threat landscape is striking. Seqrite recorded over 265.52 million detections across more than 8 million endpoints between October 2024 and September 2025, averaging 505 detections every minute. Trojans accounted for approximately 43% of all detections, while file infectors made up around 35%. The report noted that many of these campaigns relied heavily on social engineering and identity deception as the initial point of compromise — the same techniques that underpin deepfake-based fraud.
Regulatory and Compliance Exposure
The report flags significant legal risk under the Digital Personal Data Protection (DPDP) Act, 2023, which mandates that financial institutions safeguard personal data and ensure secure processing across all digital interactions. A successful deepfake-led breach can result in unauthorised data access, identity misuse, and direct compliance violations — exposing organisations to regulatory penalties and lasting reputational damage.
This comes amid growing regulatory scrutiny of data security practices in India's financial sector, with the Reserve Bank of India (RBI) having already tightened fraud-reporting norms in recent years. Notably, deepfake fraud represents a qualitative escalation: unlike brute-force attacks, it exploits the trust architecture that financial systems are built upon.
What Institutions Must Do
Seqrite urged a structural shift away from static identity verification toward dynamic, behaviour-led validation. Specific recommendations include strengthening multi-layered authentication, deploying anomaly detection across transaction flows, and actively monitoring communication channels for manipulation signals.
The report forecasted that the next generation of threats will be increasingly AI-driven, adaptive, and capable of bypassing conventional security controls — a trajectory that demands proactive investment rather than reactive patching. Industry observers note that Indian banks and non-banking financial companies (NBFCs), many of which still rely on legacy verification frameworks, face disproportionate exposure.