The Old Scams Have Learned New Tricks
For years, cyber safety advice was simple: look for spelling mistakes, beware of suspicious links, and never share your OTP. This advice is now dangerously outdated. Artificial intelligence has made cyberattacks more sophisticated, scalable, and personal.
Attackers are no longer just sending mass emails with grammatical errors; they are using AI to generate fluent, personalised messages, clone voices of loved ones, and even create deepfake videos to bypass security checks. The key change is that AI lowers the barrier for creating convincing fraud. A scammer can now use a few seconds of audio from social media to clone a person's voice and create a fake emergency call demanding a UPI transfer. This evolution from basic phishing to intelligent social engineering is the new reality.
UPI: The New Frontier for Voice Scams
The immediacy of UPI makes it a prime target for AI-powered fraud. The most prominent new threat is the AI voice cloning scam. Fraudsters create a sense of panic by using a cloned voice of a family member or friend claiming to be in an accident, arrested, or facing a medical crisis. The victim is pressured to send money instantly via UPI before they have time to verify the story. These calls are effective because they are short, emotionally manipulative, and sound authentic. The Reserve Bank of India (RBI) has identified AI-enabled cyber threats as a significant emerging risk to the financial system, acknowledging that traditional fraud detection methods are often one step behind. In response, UPI operators have flagged rising security costs as they work to defend against these advanced threats.
Aadhaar: The Deepfake and Data Challenge
Aadhaar, as the world's largest biometric ID system, faces a different kind of AI threat: deepfakes. Fraudsters have attempted to use AI-generated videos with realistic movements like eye-blinking to fool the 'liveness' detection systems used in facial authentication for KYC processes. This could potentially allow criminals to open bank accounts, take out loans, or access services in someone else's name. The Unique Identification Authority of India (UIDAI) has been proactive in countering this. It has implemented multi-layered security, including advanced AI and machine learning models that analyse facial patterns and detect anomalies to distinguish between a real person and a synthetic image or video. UIDAI also uses a two-layer system for fingerprint authentication to prevent spoofing with materials like silicone.
How the System is Fighting Back
Regulators and financial bodies are not standing still. The RBI Governor has stated that only AI can effectively combat AI-powered fraud, urging banks to adopt machine learning models for real-time anomaly detection. The National Payments Corporation of India (NPCI) is actively deploying AI and machine learning for fraud monitoring in UPI transactions. It has also launched pilot programs for AI models that can track stolen money in real-time as it moves between bank accounts, aiming to intercept fraudulent transactions before the funds are lost. On the identity front, UIDAI has been enhancing its security with features like liveness detection and has launched initiatives to collaborate with startups on developing next-generation security solutions to tackle deepfakes.
How You Can Protect Yourself
While institutional defenses are crucial, user vigilance is more important than ever. The old rules may be insufficient, but new ones are emerging. If you receive a distressing call asking for money, hang up and call the person back on their known, saved number. Do not trust a voice alone, especially if the call comes from an unknown number. For Aadhaar, a powerful but underused feature is the ability to lock your biometrics through the UIDAI website or mAadhaar app. This prevents anyone from using your fingerprint or iris for authentication without you temporarily unlocking it. Regularly checking your credit score can also help you spot any unknown loans taken out in your name. Finally, be aware that Indian law enforcement does not have a process called "digital arrest" that requires you to stay on a video call and transfer money.
















