India alerts on deepfake threats as AI cybersecurity shifts from machines to minds

India’s Computer Emergency Response Team warns about AI-driven impersonation attacks, urging a focus on educating the public to recognise synthetic threats amid rising digital fraud and expanding AI capabilities.

India’s Computer Emergency Response Team issued a warning in late May about AI-assisted attacks on digital infrastructure, but the deeper significance of the advisory lies elsewhere: the state is now spelling out procedures for spotting a fabricated colleague. According to the advisory, organisations should treat deepfake impersonation as a practical security threat, building verification steps for video calls in the same way they maintain firewalls and patch systems. That shift reflects a wider reality that cybersecurity is no longer only about defending machines; it is also about defending judgement.

The scale of the problem is becoming easier to measure. Microsoft’s Digital Defense Report 2025 said AI-generated phishing messages achieved click-through rates up to 4.5 times higher than conventional attempts, while AI-generated identities were increasingly used to defeat selfie checks and other verification tools. The report frames artificial intelligence as both a weapon and a defence, but the immediate lesson is stark: attackers are using AI to make deception cheaper, faster and more convincing than traditional fraud.

That matters because the fraud is no longer confined to clumsy emails or obvious scams. A now well-known case involving Arup, the British engineering group, showed how a worker in Hong Kong was persuaded into authorising transfers after joining a video call in which every other participant was synthetic. Nothing was hacked. No password was stolen. The attack succeeded because the employee did what security culture usually encourages: he checked. The problem was that the check itself had been forged.

This is why the idea of cognitive cybersecurity is gaining ground. It describes the protection of people, not just networks, against manipulation that targets how information is perceived and acted upon. The danger reaches beyond financial fraud. The same tools that can clone a finance chief’s voice can also manufacture a politician’s statement or create false images that appear to show public disorder. In that sense, the most vulnerable point in the system may be the human being asked to make a rapid decision under pressure.

India is especially exposed because its digital economy is expanding so quickly. Unified Payments Interface transactions have surged, bringing enormous convenience but also a wider surface for abuse. The Reserve Bank of India has also reported thousands of digital payment fraud cases, while CERT-In has logged millions of cyber incidents and identified AI-driven reconnaissance and deepfake-enabled fraud among the main risks. Add to that India’s linguistic diversity and the growing number of first-time internet users, and it becomes clear why synthetic scams can travel so effectively.

The policy response is beginning to reflect that challenge. The IndiaAI Mission has already pushed AI literacy into school curricula through the Skilling for AI Readiness programme, and the government’s “YUVA AI for All” course is designed to give millions of citizens a basic grounding in the technology. Yet awareness programmes will only go so far unless they teach people how deception actually works: to treat urgency and secrecy as warning signs, to verify unusual requests through a separate channel and to use the 1930 cyber-fraud helpline quickly when something feels wrong.

Technical safeguards still matter. The European Union’s AI Act is set to require machine-readable labelling of synthetic content and disclosure of deepfakes. But such rules have limits, especially when scams originate outside the jurisdiction or unfold in real time over a phone call. That is why the next frontier of cybersecurity is not just better software. It is a better-trained public, able to recognise when a voice, a face or a message is not what it claims to be.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.