India faces rising cyber threats as AI-generated scams accelerate and literacy becomes a security priority

India’s expanding digital economy faces new risks from AI-driven scams, prompting authorities to emphasise AI literacy as a crucial layer of cybersecurity amidst escalating fraud cases and sophisticated impersonation techniques.

India’s cyber authorities are increasingly treating AI as more than a productivity tool. In late May, CERT-In issued guidance on reducing exposure to AI-assisted attacks, including advice on verifying video calls and checking for deepfake impersonation. That shift matters because the threat is no longer just about bad code or weak passwords; it is also about convincing people to trust something false.

The change is visible in the numbers. Microsoft’s latest Digital Defence Report said AI-generated phishing messages were far more likely to be clicked than manually written ones, while identity fraud built on synthetic documents has risen sharply. The Stanford AI Index also logged a jump in publicly documented AI-related incidents in 2025, including more romance scams and other frauds built on cloned voices and faces. In simple terms, the scammer’s job has become cheaper, faster and easier to scale.

The Arup case remains a useful warning. An employee at the engineering group’s Hong Kong office was drawn into a video call with what appeared to be senior colleagues, including the company’s chief financial officer, and authorised a string of transfers worth about US$25.6 million. The apparent safeguard , a live call to check a suspicious request , was exactly what the fraud depended on. Nothing in the network had been breached; the deception worked by exploiting human confidence in a familiar face and voice.

That is why some experts are now talking about cognitive cybersecurity: the protection of people as much as systems. Firewalls, patching and encryption still matter, but they cannot stop a convincingly generated voice message, a forged instruction or a synthetic clip dropped into a fast-moving work process. The European Union’s AI Act is trying to add a layer of disclosure for synthetic content, but labelling rules and detection tools will struggle to keep pace with models that improve every few months, especially in situations where someone must answer immediately.

India has particular reasons to worry. UPI has turned everyday payments into mass behaviour, which is great for convenience but also gives fraudsters more chances to strike. The Reserve Bank of India’s latest annual report showed digital-payment fraud cases making up a large share of reported banking frauds, with losses running into hundreds of crores. Add India’s linguistic diversity, the spread of first-time internet users and the government’s push to train millions of citizens in basic AI skills, and the next step is fairly clear: AI literacy is becoming a financial safety issue, not just a classroom topic. For households, traders and firms alike, the practical lesson is the same , treat urgency, secrecy and unusually polished digital communication as warning signs, and verify them through a separate channel before money or data moves.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.