AI deepfakes threatening financial systems: MHA issues urgent advisory

Share:
Audio Loading voice…
AI deepfakes threatening financial systems: MHA issues urgent advisory

Synopsis

India's Home Ministry has sounded the alarm on a new breed of cybercrime: AI-generated deepfakes sophisticated enough to fool Video-KYC, facial authentication, and liveness checks. The NCTAU advisory lays out a step-by-step fraud playbook — from social engineering to synthetic identity creation — and warns that standard biometric defences are no longer enough.

Key Takeaways

The Ministry of Home Affairs issued an advisory through NCTAU (I4C) warning of AI deepfake-enabled identity fraud targeting financial systems.
Fraudsters use AI tools to replicate facial expressions, eye movements, gestures, and voice to defeat Video-KYC and liveness verification .
The attack chain begins on social media, job portals, or dating apps and escalates to harvesting facial recordings via deceptive video calls.
Successful attacks can enable fraudsters to create or operate financial accounts illegally by defeating KYC safeguards.
Fintech firms have been directed to deploy deepfake-detection in onboarding systems; citizens advised to lock biometric profiles and monitor login alerts.
Suspected fraud should be reported on the National Cyber Crime Reporting Portal with contact details and video links.

The Ministry of Home Affairs (MHA) has issued a fresh advisory warning that cybercriminals are increasingly weaponising Artificial Intelligence (AI) to fabricate deepfake videos and synthetic identities, posing a direct threat to India's financial and digital ecosystems. The alert, released by the National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cyber Crime Coordination Centre (I4C), details a sophisticated multi-stage fraud pattern that can defeat standard identity verification systems.

How the Fraud Operates

The modus operandi typically begins with an unsolicited approach via social media platforms, messaging apps, job portals, dating applications, or direct phone calls. Once contact is established, attackers move to harvest facial data — either from publicly available online content or by manipulating victims into performing specific actions on camera, such as blinking, turning their heads, or speaking directly at a screen.

Those recordings are then fed into AI-powered deepfake tools that reconstruct a person's facial expressions, eye movements, gestures, and voice with high fidelity. The resulting synthetic identity can, in systems lacking adequate detection capabilities, bypass facial authentication, liveness verification, and Video-KYC checks entirely.

Threat to KYC and Financial Accounts

The advisory specifically flagged the risk to Know Your Customer (KYC) processes. According to the NCTAU, fraudsters who successfully defeat identity verification safeguards could create, activate, or operate financial accounts for illegal purposes — effectively laundering illicit activity behind a stolen biometric identity.

'These technologies may be exploited to bypass facial authentication, liveness verification, Video-KYC, account recovery, and unauthorised access to financial and digital services. Fraudsters may attempt to gain unauthorised access to accounts by using facial recordings obtained through deceptive video calls, fake online job interviews or social engineering tactics,' the advisory stated.

This comes amid a broader surge in AI-assisted cybercrime globally, with India's rapid expansion of digital financial services — including UPI, digital lending, and fintech onboarding — making its citizens a high-value target.

What Institutions Are Advised to Do

The NCTAU has called on financial institutions and fintech firms to integrate robust deepfake-detection mechanisms into their customer onboarding pipelines. The advisory makes clear that standard liveness checks are no longer sufficient against next-generation AI-generated content.

'Locking your biometric profile is the strongest defence against this type of remote identity theft,' the advisory noted, urging individuals to take proactive steps rather than rely solely on institutional safeguards.

What Citizens Should Watch For

Individuals have been advised to monitor email alerts for any unauthorised login attempts and to remain alert to sudden disruptions in mobile network services — a potential indicator of a fraudulent SIM swap attack. Any suspected financial fraud or identity theft should be reported immediately on the National Cyber Crime Reporting Portal, along with the fraudster's contact details and any video links associated with the scam.

The MHA clarified that the advisory is intended to raise awareness about emerging AI-enabled identity fraud techniques, and that references to authentication systems are based on observed threat trends rather than any confirmed breach of a specific platform or service. As deepfake technology grows more accessible, the gap between institutional defences and attacker capabilities is narrowing — making public awareness as critical as any technical countermeasure.

Point of View

Given that the RBI and SEBI have long required digital onboarding. Awareness advisories are necessary but insufficient; without binding technical standards and audit requirements for fintech onboarding pipelines, the gap between attacker capability and institutional defence will keep widening. India's scale — hundreds of millions of digitally onboarded accounts — makes the exposure uniquely large.
NationPress
28 Jul 2026

Frequently Asked Questions

What is the MHA advisory on AI deepfakes about?
The Ministry of Home Affairs has warned that cybercriminals are using AI-generated deepfake videos and synthetic identities to bypass Video-KYC, facial authentication, and liveness verification systems used by banks and fintech firms. The advisory, issued by NCTAU under I4C, outlines the fraud method and recommends protective steps for both institutions and individuals.
How do fraudsters use deepfakes to commit financial fraud?
Attackers first establish contact via social media, job portals, or dating apps, then trick victims into performing facial actions on camera — blinking, turning their head, or speaking. These recordings are processed by AI deepfake tools to create realistic synthetic identities that can fool automated identity verification systems, potentially enabling fraudsters to open or access financial accounts.
What should individuals do to protect themselves?
The NCTAU advisory recommends locking your biometric profile, monitoring email alerts for unauthorised login attempts, and staying alert to sudden mobile network disruptions that may signal a SIM swap attack. Any suspected fraud should be reported on the National Cyber Crime Reporting Portal along with the fraudster's contact details and relevant video links.
What are fintech and financial firms advised to do?
Institutions are advised to integrate robust deepfake-detection mechanisms into customer onboarding systems, going beyond standard liveness checks. The advisory makes clear that conventional biometric verification is no longer sufficient against advanced AI-generated synthetic identities.
Does the advisory mean specific platforms have been compromised?
No. The MHA clarified that the advisory is based on observed threat trends and does not imply any vulnerability or confirmed breach of a specific organisation, platform, or service. It is intended as a proactive awareness measure.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 5 months ago
  4. 9 months ago
  5. 9 months ago
  6. 11 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google