Indian financial firms turn to simulation drills amid rising fraud risks and AI-enabled scams

As bank frauds surge and AI-driven scams proliferate in India, financial institutions are adopting forensic-style crisis simulations to enhance fraud resilience and meet tightening regulatory demands.

On Monday, 7 September 2026, Algoritha Security said it was rolling out fraud-crisis tabletop exercises for Indian financial firms, arguing that banks and other financial groups now need to rehearse fraud the way they rehearse cyber attacks. The timing is notable: Business Standard, citing Reserve Bank of India annual-report data, said the value of bank frauds in FY26 rose 46.4% to ₹48,021 crore even as the number of cases fell sharply, with much of that increase driven by 314 legacy cases worth ₹30,199 crore that were reclassified and reported afresh. (the420.in)

The regulatory pressure behind that pitch is real. RBI’s revised fraud-risk directions, issued on 15 July 2024, set out a framework for prevention, early detection and timely reporting of fraud to law-enforcement agencies, the central bank and NABARD, and apply to commercial banks, foreign banks operating in India, local area banks, small finance banks, payments banks, regional rural banks, State Bank of India and all-India financial institutions including Exim Bank, NABARD, NaBFID, NHB and SIDBI. RBI also said the 2024 directions superseded the older 2016 reporting framework, and its accompanying press release said institutions must follow principles of natural justice before classifying persons or entities as fraudulent, reflecting the Supreme Court’s judgment of 27 March 2023. (systemhealth.rbi.org.in)

Cyber rules have made the picture more complicated still. CERT-In’s 28 April 2022 directions require qualifying cyber incidents to be reported within six hours, and the agency’s FAQ says organisations can file what they know first and send additional details later. Meanwhile, SEBI issued its Cybersecurity and Cyber Resilience Framework on 20 August 2024, set compliance deadlines of 1 January 2025 or 1 April 2025 depending on the category of regulated entity, and later followed up with clarifications published on 31 December 2024, 30 April 2025 and 28 August 2025. That means a ransomware attack followed by rogue transfers or a data leak can trigger several regulatory clocks at once. (cert-in.org.in)

In material published by The420.in, Algoritha said its answer is to put banking, financial services and insurance teams through a one-hour crisis simulation rather than a conventional awareness session. According to the company, senior management, fraud teams, security staff, operations, legal, compliance and communications are fed new facts in stages and must decide, in real time, whether to stop transactions, attempt a fund freeze or recall, preserve logs, open a forensic investigation, escalate internally or contact regulators and police. The concept fits the broader regulatory trend because both RBI’s fraud framework and CERT-In’s incident rules emphasise rapid action, documented escalation and timely reporting. (the420.in)

The AI threat that sits behind some of those scenarios is no longer hypothetical. Business Standard reported in June that industry participants were already seeing synthetic bank statements, manipulated video-KYC sessions and deepfakes that had helped produce frauds of ₹15 crore to ₹20 crore at an NBFC. Sandesh GS, chief technology officer at Bureau, told the paper that criminals were not relying on the biggest frontier systems but on smaller models that could run on local consumer hardware “like a gaming computer”, with tailored fraud tools circulating through Telegram channels and dark-web marketplaces. (business-standard.com)

Real cases show how quickly funds can disperse once a victim starts paying. Hindustan Times reported in April that Punjab’s State Cyber Crime Police Station in Mohali was investigating a complaint from Ludhiana industrialist Jagdeep Singhal, who said he had been lured into supposed cryptocurrency trading through a website resembling a well-known exchange and ended up losing nearly ₹20 crore. The newspaper said investigators were examining roughly 76 mule accounts and multiple Indian and international phone numbers, exactly the sort of maze that makes the first hour of response crucial for tracing money and securing evidence. (hindustantimes.com)

Algoritha says it wants the exercise to be measurable, with participants scored on detection, containment, loss prevention, evidence handling, communications, business continuity and governance, followed by an after-action review and remedial plan. That focus on preserving evidence echoes CERT-In’s own guidance, which tells organisations to avoid tampering with potential evidence even while they are containing an incident and preparing a report. For financial institutions, that is a practical tension: operational teams may want systems cleaned and restored quickly, while investigators and regulators need logs, devices and a defensible chronology preserved. (the420.in)

The wider point is that Indian financial firms are being pushed towards rehearsal, not just paperwork. RBI data cited by Business Standard show that while cards, internet banking and digital payments had generated the highest number of frauds in earlier years, loans and advances accounted for 85.5% of the amount involved in FY26; at the same time, reporting rules have tightened and AI has lowered the cost of impersonation and document manipulation. Taken together, those shifts suggest demand may grow for consultants that can turn compliance requirements into decision-making drills for boards, executives and operational teams. (business-standard.com)

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.