The New Wave of AI-Powered Threats
Forget the poorly worded emails from a foreign prince. Today's cyber threats are sophisticated, personalised, and powered by artificial intelligence. Recent analysis shows that these AI-driven attacks are becoming alarmingly common in India. One report
from August 2026 found that 26% of all malicious data breaches in the country were generated by AI. These aren't just minor incidents; the average cost of such a breach for an Indian organisation has surged to an all-time high of ₹25.5 crore. Scammers are using AI to clone voices for fake emergency calls, create deepfake videos of company executives authorising fraudulent payments, and generate hyper-realistic phishing emails that perfectly mimic corporate language. These new attacks bypass traditional security filters by exploiting trust and creating a sense of urgency that is difficult to ignore. The era of easily spotted scams is over; the age of AI-powered deception is here.
What Indian Authorities Are Saying
In response to this evolving threat, India's key cybersecurity agencies have issued advisories highlighting a fundamental shift in defence strategy. A May 2026 blueprint from the Indian Computer Emergency Response Team (CERT-In) warns that traditional, automated security systems are no longer sufficient to combat adaptive AI attacks. The agency noted that AI has lowered the barrier for criminals, allowing even unskilled actors to launch complex, large-scale attacks. The report from CERT-In, along with advisories from the Ministry of Home Affairs, emphasizes that technology alone cannot solve a problem rooted in deception. Instead of focusing solely on bigger firewalls, the guidance urges organisations and individuals to build robust verification procedures and foster a culture of healthy scepticism. The core message is that while the threat is high-tech, the most effective initial defence is human intelligence.
The Human Firewall: Your Brain's Role in Defence
The central recommendation from these reports is to strengthen the 'human firewall'. But what does that mean in practice? It means recognising that your intuition and critical thinking are your best assets. AI can generate a technically perfect email or a flawless voice clone, but it often struggles with true context and emotional nuance. Scams powered by AI are designed to create panic, bypass logic, and pressure you into immediate action. The human firewall works by inserting a crucial pause between the request and the action. It's the moment you ask yourself, "Does this feel right?" or "Would my boss really ask for an urgent fund transfer over WhatsApp?" This cognitive check is something that software can’t replicate. By trusting your gut feeling that something is 'off'—whether it's an unusual request, an unexpected change in tone, or a situation that feels too dramatic—you disrupt the scammer's process. The reports suggest that treating AI literacy as a core security skill is now essential.
How to Spot and Stop an AI-Driven Attack
Strengthening your human firewall involves adopting a few simple but powerful habits. First and foremost, always pause before acting on an urgent or emotional request, especially one involving money or sensitive data. If you receive a suspicious message or call, verify it through a separate, trusted communication channel. For example, if you get a panicked voice message from a family member, hang up and call them back on their known number. For work requests, follow up with a direct call or in-person conversation. Be wary of any communication that creates intense pressure or fear, such as so-called 'digital arrest' scams where fraudsters impersonate police. Look for subtle visual cues in video calls, like unnatural eye movements or mismatched lip-syncing, which can indicate a deepfake. Finally, never share OTPs, passwords, or financial details in response to an unsolicited inbound request. Legitimate organisations will not ask for this information over the phone or via a random link.














