How Scams Used to Work
Until recently, most online scams had tell-tale signs. You might have received an SMS with a suspicious link, riddled with grammatical errors. Or perhaps a phishing email pretending to be from your bank, but sent from a strange address. These older methods
relied on tricking a large number of people, hoping a small fraction would fall for the scam. Fraudsters would create fake websites, send mass messages, or make calls to try and steal sensitive information like your UPI PIN or bank OTP. While effective to a degree, they often lacked personalisation and were easier for a vigilant user to spot.
The Game Changer: Artificial Intelligence
Artificial intelligence, especially generative AI, has given cybercriminals a powerful new toolkit. These tools can create highly convincing text, images, audio, and even video with minimal effort. This lowers the barrier for criminals, allowing even less skilled individuals to launch sophisticated attacks. What used to take days of planning can now be automated and executed in minutes. India's Computer Emergency Response Team (CERT-In) has issued high-severity warnings, noting that AI can autonomously find software vulnerabilities and execute multi-stage attacks, shrinking the response time for defenders from weeks to mere hours.
The New Weapons: Deepfakes and Smart Scams
The most alarming new threats are deepfakes and hyper-personalised scams. Fraudsters can use AI to clone a person's voice from just a small audio sample. Imagine getting a call from someone who sounds exactly like a family member, frantically asking for an urgent UPI transfer. These AI-generated voice and video deepfakes can be incredibly realistic, making it difficult to distinguish them from reality. Similarly, AI can write flawless phishing emails tailored specifically to you, using information gathered from public sources. These messages are more convincing and designed to manipulate you into authorising fraudulent transfers or revealing your credentials.
Why UPI and Aadhaar Are Prime Targets
With billions of transactions monthly, the UPI network is the backbone of India's digital economy. Aadhaar, with over 1.4 billion enrolments, is the country's central identity database. This scale makes them high-value targets. For criminals, gaining access to these systems means access to a massive trove of financial and personal data. A compromised Aadhaar number could be used for identity theft and financial fraud, while exploiting UPI vulnerabilities could lead to direct monetary loss for millions of users. The sheer volume of transactions and data makes it a challenging environment to secure.
Fighting Fire with Fire: AI on Defence
The good news is that AI is not just a tool for attackers; it is also a crucial part of the defence. Banks and financial institutions are increasingly using AI and machine learning to detect fraud in real-time. These systems analyse transaction patterns, identify unusual behaviour, and flag suspicious activity before money leaves an account. The Reserve Bank of India's Innovation Hub has even developed an AI platform called 'MuleHunter.AI' to identify fraudulent mule accounts. Government agencies and regulators are also stepping up, urging banks to adopt AI-based security measures to counter the evolving threats.
What You Can Do to Stay Safe
While institutions work to bolster security, user awareness remains the first line of defence. Be extremely cautious of unsolicited messages or calls, even if they seem to be from a known contact. Always verify requests for money, especially urgent ones, through a different communication channel. Never share your UPI PIN or OTP with anyone. Use strong, unique passwords and enable multi-factor authentication wherever possible. A key rule for UPI: you never need to scan a QR code or enter your PIN to receive money. If someone asks you to do this, it is a scam.














