Don’t Trust Your Eyes Alone: A Practical Handbook for Spotting Deepfakes and AI Scams in India

The video call looked and sounded exactly like your son. Same face, same voice, same worried tone, asking you to urgently transfer money for a hospital emergency. It was not your son. In January 2026, the State Bank of India warned its customers about exactly this kind of fraud: criminals using artificial intelligence to clone faces and voices, posing as bank officials or relatives, and persuading victims to transfer money or hand over sensitive details. Deepfakes and AI-driven scams have moved from a technology curiosity to one of the most common frauds targeting Indian households. This handbook explains how these scams work, how to spot them, and what to do if you are targeted.
How the scams actually work
A deepfake is synthetic media, an image, audio clip or video created or altered by AI to impersonate a real person. Scammers need surprisingly little raw material: a few seconds of voice from a social media video is enough to clone it, and a handful of photographs can build a convincing face. The most common attacks in India follow familiar scripts. The family emergency scam uses a cloned voice or a video call to impersonate a relative in distress, demanding urgent money and insisting on secrecy. The official impersonation scam poses as a bank officer, police official or government authority, often over a video call, to extract one-time passwords or account details. Fake investment scams use AI-generated videos of well-known personalities endorsing trading schemes that do not exist. And non-consensual fake images are used for blackmail, with ordinary people’s profile photographs turned into fabricated intimate content. The common thread is always the same: manufactured urgency, designed to stop you thinking.
How to spot a fake before it costs you
No single trick catches every deepfake, and the technology keeps improving, so verification must become a habit rather than a one-time skill. Watch for the technical tells: unnatural blinking or no blinking at all, lips that do not quite match the speech, skin that looks oddly smooth, hands or ears that distort during movement, and lighting on the face that does not match the background. But do not rely on your eyes alone. The strongest defences are procedural.
- Slow down. Urgency is the scammer’s weapon. A genuine emergency will survive a ten-minute verification.
- Verify through a separate channel. If a “relative” calls asking for money, hang up and call them back on their known number, or contact another family member.
- Agree on a family code word. A simple secret phrase, shared only within the family, defeats voice cloning instantly.
- Ask a question only the real person could answer. Scammers rely on you not checking.
- Never share one-time passwords, PINs, card details or QR codes on a call you did not initiate. No genuine bank official will ever ask for them.
- Check extraordinary claims independently. If a video shows a celebrity promising guaranteed returns, search for the same claim on established news websites; if only forwards carry it, it is fake.
- Limit what you publish. Every public photo and voice clip is raw material for cloning; review privacy settings on social media profiles.
If you are targeted: act fast, in this order
First, do not pay and do not continue engaging; scammers escalate once money moves. Second, preserve evidence: screenshots, the caller’s number or profile, chat history, transaction references and the exact time of contact, without editing the originals. Third, report immediately. Call the national cybercrime helpline at 1930, file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in, and inform your bank at once if money has moved, since quick reporting can sometimes freeze the transaction. Fourth, warn your circle, because scammers often work through a victim’s contact list next.
Know your legal ground
India does not yet have a standalone deepfake law, but crimes committed through synthetic media are punishable under the Information Technology Act of 2000 and the IT Rules of 2021, which cover identity misuse, unauthorised use of personal images and the spread of misleading or obscene content, and place takedown responsibilities on social media platforms. The direction of regulation is towards faster platform action and heavier penalties. The law, however, will always arrive after the crime. In the age of synthetic media, the most reliable security tool remains the oldest one: a healthy refusal to believe your eyes and ears until you have checked.
Source: NewsBytes
Leave a Reply