India grapples with rapid spread of deepfake scams targeting public figures and businesses

A high-profile deepfake involving Rashmika Mandanna has highlighted the growing dangers of synthetic videos, revealing vulnerabilities for individuals and corporations and prompting India’s legal reforms to catch up with technological threats.

The deepfake that placed Rashmika Mandanna’s face on to another woman’s body in late 2023 did more than embarrass a celebrity. It exposed how quickly synthetic video can spread before platforms or police are able to intervene, and it forced India into a wider debate about reputation, privacy and the legal tools available to deal with digitally altered content. Mandanna described the episode as “extremely scary”, and Delhi Police later registered an FIR as the case drew national attention. According to reports at the time, the government also moved to remind social media companies of their obligations to remove harmful content.

What made the incident especially significant was not simply that a well-known actor was targeted, but that it showed how deepfakes can be used to exploit trust. Reports since then have described fabricated endorsements purporting to feature public figures such as Ratan Tata, Virat Kohli and Aamir Khan, with the obvious aim of making a false claim seem credible enough to influence behaviour. That same logic underpins the newer threat to businesses: a voice or video that appears to come from a chief executive, finance head or client can be enough to push an employee into acting before the deception is discovered.

The risk is no longer theoretical. In one widely cited case, a Mumbai finance executive was persuaded by a video call that appeared to come from a company chief and was instructed to send ₹1.5 crore. The real executive was in a meeting at the time. Similar frauds have been reported elsewhere, including a Hong Kong banking case involving $25 million, where an employee joined what seemed to be a routine call with senior colleagues. Cybersecurity reporting has also suggested that about 47% of Indian adults say they have experienced, or know someone who has experienced, an AI voice scam, a figure that underlines how familiar the threat is becoming.

India’s legal and regulatory response has begun, but it is still catching up with the speed of the technology. Sections 66C and 66E of the Information Technology Act cover identity theft and privacy violations, while the Digital Personal Data Protection Act adds another layer of protection. The Ministry of Electronics and Information Technology’s November 2023 advisory told platforms to act quickly on flagged deepfakes, including removing offending material within 36 hours of a court or government order. Delhi Police eventually tracked down several suspects in the Mandanna case, though reporting indicated the investigation was complicated by deleted account data and questions around who had uploaded the video versus who created it.

For companies, the lesson is that this is not only a communications problem. A deepfake attack can become a financial, legal and reputational crisis within minutes, which means firms need verification procedures for urgent payment requests, along with a rapid response plan for synthetic-media incidents involving executives or brands. The central challenge is that the falsehood may be obvious only after the damage is done. By then, the fake has already circulated, the public has already reacted and the company is left trying to explain that what people saw and heard was never real.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.