The New Face of Digital Fraud
The familiar advice to spot scams by looking for poor grammar or suspicious links is becoming outdated. Today, cybercriminals are using AI to create highly convincing and personalised attacks. This new toolkit includes AI voice cloning, which can mimic
a loved one’s voice in a fake emergency call asking for money. Another potent threat is deepfake videos, where realistic impersonations of celebrities or officials are used to promote fraudulent investment schemes. AI also crafts flawless phishing emails and messages that can reference your workplace or recent activities, making them appear legitimate. These tools don't need to be perfect; they just need to be slightly more believable and scalable to cause significant harm. The result is a shift from low-effort, high-volume scams to targeted social engineering that preys on trust, fear, and urgency.
What Hasn't Changed: The Core Defences
Despite the new threats, the fundamental security architecture of UPI and Aadhaar remains robust. These systems were built with multiple layers of protection that have not been fundamentally broken by AI. Aadhaar’s system relies on biometric data like fingerprints and iris scans, which are encrypted. UIDAI, the authority managing Aadhaar, uses AI-based facial recognition with liveness detection to thwart replay attacks using static photos. Similarly, UPI transactions are secured by a multi-factor authentication process, typically involving your phone and a secret UPI PIN. The National Payments Corporation of India (NPCI) also deploys AI and machine learning models to monitor transactions in real-time for fraudulent patterns. These core defences, designed to verify your identity and authorise transactions securely, have not changed. The fortress walls are, for the most part, holding strong.
What Has Changed: The Point of Attack
What has dramatically changed is not the strength of the systems themselves, but the methods used to attack their users. AI doesn’t need to crack complex encryption when it can trick a person into willingly giving away access or money. The primary target has shifted from the technology to the human element. Scams like "digital arrest," where fraudsters impersonate police officers on convincing video calls, create panic to extort money. The effectiveness of these social engineering attacks is magnified by AI, which can personalise a scam at a scale never seen before. Fraudsters now operate like organised businesses, using technology to study institutional controls and adapt their tactics quickly. Therefore, while the core UPI and Aadhaar platforms remain secure, the environment around them has become far more dangerous. The risk is less about a hacker breaking into a server and more about a scammer convincingly tricking you into authorising a payment yourself.
The Race to Keep Up
Indian regulators and financial institutions are aware of this escalating AI-versus-AI contest. Concerns over the rising costs of cybersecurity have been flagged by UPI platform operators, who note that defending against advanced AI will require significant investment. In response, government agencies are stepping up. India's Computer Emergency Response Team (CERT-In) is deploying its own AI-driven systems to detect malicious activity and has been conducting cybersecurity drills focused on AI threats. Regulators are also pushing for stronger controls, with RBI's guidelines encouraging risk-based checks using biometrics and contextual AI. Banks and fintech companies are in a continuous race, upgrading their fraud detection systems and sharing threat intelligence to stay ahead of sophisticated attacks. This marks a critical shift from simply reacting to incidents to building a proactive and collaborative defence ecosystem.
Your Role in the Digital Shield
Ultimately, the most critical line of defence is user awareness and vigilance. Since AI-powered attacks are designed to manipulate human psychology, technology alone cannot solve the problem. The first rule is to be skeptical of urgency. Whether it’s a call from a panicked “relative” or a message from a “bank official” threatening to block your account, pause and verify. Contact the person or institution through a separate, trusted channel, like a known phone number or an official app. Never share your PIN, OTP, or password with anyone, no matter how convincing they sound. Legitimate authorities and banks will not ask for this information over a call or message. Be wary of unsolicited job offers or investment schemes that promise unrealistic returns. By treating every unexpected request for money or information with caution, you can become the security layer that AI cannot easily bypass.
















