What Are AI-Enabled Threats?
Unlike traditional cyberattacks that often relied on clumsy emails or basic scams, AI-enabled threats are far more sophisticated and scalable. Cybercriminals are now using AI tools to create hyper-realistic fraudulent content and automate attacks. This
includes deepfake technology, where a person's voice and likeness can be convincingly mimicked in a video or audio call to trick someone into making a payment. Another technique is generating highly personalized phishing messages in fluent regional languages, which are harder to spot than older scams filled with grammatical errors. AI can also be used to create synthetic identities by combining real and fake data to open mule bank accounts, or to probe a bank's security systems for weaknesses before launching a major attack. These tools lower the barrier to entry, allowing less-skilled criminals to execute sophisticated fraud campaigns.
The Direct Risk to UPI Users
The greatest strength of the Unified Payments Interface (UPI)—its instant, real-time settlement—is also its biggest vulnerability in the face of AI threats. Once a fraudulent transaction is authorized, the money is gone in seconds, making reversal nearly impossible. Scammers are using AI to exploit this, with reports of AI voice-cloning being used to impersonate family members in fake emergencies or officials demanding urgent transfers. These scams leverage psychological pressure and technological deception. A recent analysis noted that a significant percentage of Indian adults have encountered AI voice scams, with many suffering financial losses. Scammers also use AI to create fake payment confirmation screens or fraudulent QR codes to trick merchants and users. The sheer volume of UPI transactions, which run into the billions monthly, makes it a prime target for these scalable AI-driven attacks.
How Aadhaar's Security is Being Tested
Aadhaar, as India's foundational identity document, is also in the crosshairs. The risk is not just about data breaches but about identity manipulation. AI tools can create deepfake videos or images to bypass facial recognition checks used in some Know Your Customer (KYC) processes. This allows fraudsters to open bank accounts, apply for instant loans, or obtain SIM cards in someone else's name, leaving the real individual to deal with the consequences. There have already been cases where criminals used AI-generated biometrics to manipulate Aadhaar-linked data and mobile numbers. By exploiting vulnerabilities in the Aadhaar ecosystem, criminals can hijack a person's entire digital identity, gaining access to linked bank accounts and financial services.
The Defensive Push: Fighting AI with AI
The response from regulators and financial institutions is a multi-layered effort to fight fire with fire. The National Payments Corporation of India (NPCI), which runs UPI, has deployed its own AI and machine learning systems to monitor transactions and detect fraud in real time. These systems analyze user behavior, transaction patterns, and geo-location data to flag suspicious requests before a user even approves them. The Reserve Bank of India (RBI) has also been proactive, launching initiatives like the Digital Payments Intelligence Platform to share live fraud data between banks and fintech companies. Furthermore, the government's cybersecurity arm, CERT-In, is using AI-driven systems to detect malicious activity and has issued blueprints for defending digital infrastructure against these advanced threats. The UIDAI, which manages Aadhaar, is also collaborating on research into deep tech like quantum security and using AI to verify documents and detect enrolment fraud.














