The Old Scams We Learned to Ignore
Social engineering is the art of manipulation, where attackers exploit human trust to bypass security defences. For decades, this primarily took the form of phishing emails or fraudulent phone calls. We were trained to look for the tell-tale signs: glaring
spelling mistakes, awkward grammar, and impersonal salutations like "Dear Valued Customer." These errors were often a dead giveaway that the message was from a scammer, likely a non-native speaker using clumsy translation software. An email supposedly from your bank but written in broken English would immediately raise red flags. This language barrier acted as an unintentional, but effective, security filter. The effort required to create a convincing scam in multiple languages was high, so attackers focused on widely spoken languages like English, limiting their reach and effectiveness in diverse linguistic landscapes.
How AI Supercharges Deception
Generative AI has completely dismantled that language barrier. The same large language models (LLMs) that help businesses draft reports can now be used by attackers to generate flawless, context-aware text in virtually any language. An attacker no longer needs to know Hindi, Tamil, or Bengali to write a convincing message in it. Beyond just text, AI-powered voice cloning has become alarmingly accessible. With just a few seconds of audio scraped from social media or a voicemail, AI tools can create a realistic deepfake of a person's voice. This elevates a standard phone scam (vishing) into a highly personal and persuasive attack. The combination means cybercriminals can now automate and scale sophisticated, personalized attacks that were once the domain of highly skilled, resource-rich groups.
The Threat Becomes Personal
Imagine this scenario: You receive a frantic WhatsApp voice note. It’s your mother’s voice, speaking to you in your native dialect, claiming she’s in trouble and needs an urgent money transfer. The voice is hers, the language is perfect, and the sense of urgency is palpable. Or consider a call at work. It’s your boss's voice, using the exact phrases they always use, asking you to quickly process an invoice for a new vendor. In both cases, the emotional pressure to comply is immense. This is the new reality of AI-powered social engineering. Attackers use these deepfake voice and video technologies to impersonate executives, family members, or government officials, exploiting trust and urgency to manipulate victims into sending money or divulging sensitive information. Because the impersonation feels so real, traditional skepticism is easily overcome.
A Unique Challenge for India
In a country with the linguistic diversity of India, this technology presents an unprecedented threat. Previously, a scammer in another country would have found it nearly impossible to craft a believable phishing attempt in Marathi or a vishing call in Malayalam. Now, AI does the work for them, effectively turning India's rich tapestry of languages and dialects into a vast, vulnerable attack surface. A mix of Hindi and English, or 'Hinglish', which feels natural in conversation, can be used to make a fraudulent request seem more authentic and bypass security tools that are often tuned only for a single language. Attackers can scrape data from social media to pepper their messages with personal details, creating highly targeted scams that resonate with cultural and regional nuances, making them far more effective than generic English-only attempts.
Your New Digital Defence Playbook
Since spotting the scam is no longer about finding errors in the text, our defences must evolve. The new golden rule is "verify, then trust." If you receive an urgent or unusual request for money or data, even if it appears to be from a trusted source, you must verify it through a separate and secure communication channel. If your boss emails you to urgently pay an invoice, call them back on their known phone number to confirm. If a family member sends a distressing voice note, try calling them directly. Furthermore, enable multi-factor authentication (MFA) on all your accounts. This provides a crucial security layer that can stop an attacker even if they manage to steal your password. Finally, awareness is key. Talk to your colleagues, family, and friends, especially older relatives, about these new types of scams. The fundamental defence is no longer technical, but behavioural.














