AI deepfakes threatening financial systems: MHA issues urgent advisory
Synopsis
Key Takeaways
The Ministry of Home Affairs (MHA) has issued a fresh advisory warning that cybercriminals are increasingly weaponising Artificial Intelligence (AI) to fabricate deepfake videos and synthetic identities, posing a direct threat to India's financial and digital ecosystems. The alert, released by the National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cyber Crime Coordination Centre (I4C), details a sophisticated multi-stage fraud pattern that can defeat standard identity verification systems.
How the Fraud Operates
The modus operandi typically begins with an unsolicited approach via social media platforms, messaging apps, job portals, dating applications, or direct phone calls. Once contact is established, attackers move to harvest facial data — either from publicly available online content or by manipulating victims into performing specific actions on camera, such as blinking, turning their heads, or speaking directly at a screen.
Those recordings are then fed into AI-powered deepfake tools that reconstruct a person's facial expressions, eye movements, gestures, and voice with high fidelity. The resulting synthetic identity can, in systems lacking adequate detection capabilities, bypass facial authentication, liveness verification, and Video-KYC checks entirely.
Threat to KYC and Financial Accounts
The advisory specifically flagged the risk to Know Your Customer (KYC) processes. According to the NCTAU, fraudsters who successfully defeat identity verification safeguards could create, activate, or operate financial accounts for illegal purposes — effectively laundering illicit activity behind a stolen biometric identity.
'These technologies may be exploited to bypass facial authentication, liveness verification, Video-KYC, account recovery, and unauthorised access to financial and digital services. Fraudsters may attempt to gain unauthorised access to accounts by using facial recordings obtained through deceptive video calls, fake online job interviews or social engineering tactics,' the advisory stated.
This comes amid a broader surge in AI-assisted cybercrime globally, with India's rapid expansion of digital financial services — including UPI, digital lending, and fintech onboarding — making its citizens a high-value target.
What Institutions Are Advised to Do
The NCTAU has called on financial institutions and fintech firms to integrate robust deepfake-detection mechanisms into their customer onboarding pipelines. The advisory makes clear that standard liveness checks are no longer sufficient against next-generation AI-generated content.
'Locking your biometric profile is the strongest defence against this type of remote identity theft,' the advisory noted, urging individuals to take proactive steps rather than rely solely on institutional safeguards.
What Citizens Should Watch For
Individuals have been advised to monitor email alerts for any unauthorised login attempts and to remain alert to sudden disruptions in mobile network services — a potential indicator of a fraudulent SIM swap attack. Any suspected financial fraud or identity theft should be reported immediately on the National Cyber Crime Reporting Portal, along with the fraudster's contact details and any video links associated with the scam.
The MHA clarified that the advisory is intended to raise awareness about emerging AI-enabled identity fraud techniques, and that references to authentication systems are based on observed threat trends rather than any confirmed breach of a specific platform or service. As deepfake technology grows more accessible, the gap between institutional defences and attacker capabilities is narrowing — making public awareness as critical as any technical countermeasure.