Fraud has always followed technology. What is different today is that artificial intelligence gives fraudsters tools that once needed a film studio: a cloned voice from a 30-second clip, a live deepfake face on a video call, a flawless forged document, or thousands of perfectly written phishing messages in minutes. Banks, their staff and their customers are all targets.
This article explains the most common AI-powered fraud patterns seen recently, and the practical measures that stop them, both for customers and for banking operations.
1. Recent AI-powered fraud patterns
Voice cloning: "It sounded exactly like my son"
Scammers take a short voice sample from social media videos or a brief phone call and use AI to clone it. The victim gets an urgent call from a "family member" in trouble, or a "senior officer" asking for an immediate transfer. The emotion and urgency are designed to stop you from thinking.
Deepfake video calls and "digital arrest"
Fraudsters pose as police, customs or investigating officers on video calls, sometimes with AI-generated faces, fake uniforms and fake office backgrounds. The victim is told they are under "digital arrest" and must transfer money to "verify" their accounts. There is no such thing as a digital arrest. No genuine agency collects money over a video call.
Deepfake meetings targeting businesses
In a widely reported 2024 case in Hong Kong, an employee transferred about US$25 million after a video meeting in which the "chief financial officer" and other colleagues were all deepfakes. Business email compromise has evolved into business video compromise, and payment approvals are the target.
AI-written phishing that looks perfect
Spelling mistakes used to be a giveaway. Today AI writes polished, personalised messages in any language, including regional languages, that copy a bank's tone, logo and format. The link leads to a fake login page or a malicious app (APK) that reads your SMS and OTPs.
Synthetic identities and forged documents
AI can generate realistic photographs of people who do not exist, and edit or create salary slips, bank statements, utility bills and identity documents. Fraudsters use them to open accounts, obtain loans or create mule accounts that later receive stolen money.
Attacks on video KYC and face checks
Some attackers try to fool remote onboarding by replaying videos, using face-swap software or injecting a fake camera feed. The goal is to open accounts in someone else's name or in a synthetic name.
Deepfake investment and loan offers
Fake videos of well-known business personalities or celebrities "recommend" an investment app or trading group. Victims are shown fabricated profits on a dashboard until they try to withdraw. Similar fake ads promise instant loans and then harass borrowers with morphed images.
Fake customer care and chatbots
Fraudsters run AI chatbots and fake helpline numbers that appear in search results and on social media. They sound professional, "resolve" your complaint, and then ask for your card details, OTP or a screen-sharing app.
2. Measures for customers and families
- Pause and verify. Urgency is the fraudster's main weapon. Hang up and call the person or the bank back on a number you already know.
- Agree on a family code word that only close family members know, and ask for it in any emergency call asking for money.
- Never share OTP, PIN, CVV or passwords, and never install apps or screen-sharing tools because a caller asked you to.
- Remember: no digital arrest exists. Police and agencies do not demand money on video calls.
- Treat investment tips on social media as suspicious, especially with celebrity videos and guaranteed returns. Check that the entity is registered with the relevant regulator.
- Download banking apps only from official app stores, and find customer-care numbers only on the bank's official website.
- Limit what you share publicly. Long videos of your voice and face, your family details and your travel plans all help a scammer.
- Set transaction limits and turn on alerts in your banking and UPI apps.
3. Measures for banking operations
For banks and financial teams, AI fraud is a process problem as much as a technology problem. Controls that do not depend on "recognising" a face or voice are the strongest.
- Call-back verification on known numbers for any unusual payment instruction, change of beneficiary, or request to change a registered mobile number or email, whatever the channel it arrived on.
- Maker-checker and dual authorisation for high-value or out-of-pattern transactions, with no exceptions for "urgent instructions from seniors".
- Liveness detection and injection-attack checks in video KYC and face-match systems, plus random challenge-response steps during the call.
- Verify documents at the source instead of trusting uploaded copies: digital document repositories, consent-based account aggregator data, and direct verification with employers and issuers.
- Mule account monitoring: watch for new accounts that suddenly receive many small credits followed by rapid withdrawals or transfers.
- AI to fight AI: behavioural analytics, device fingerprinting and anomaly detection can flag sessions and transactions that look automated or out of character.
- Regular staff awareness sessions with real examples of cloned voices and deepfake calls, so that front-line staff feel confident to pause and escalate.
- Customer awareness at the counter. A branch employee who gently asks "Did someone call and ask you to send this money?" can stop a fraud that no system would catch.
4. If you suspect a fraud
- Call the national cyber crime helpline 1930 immediately, or report at cybercrime.gov.in. The first hour matters most for freezing money.
- Inform your bank through official channels and block cards, UPI or net banking access.
- Report suspicious calls, SMS and WhatsApp messages through the Chakshu facility on the government's Sanchar Saathi portal.
- Save evidence: screenshots, phone numbers, transaction references and links.
Quick answers
Can AI really clone someone's voice?
Yes. A few seconds to a minute of clear audio is often enough to produce a convincing clone. That is why a call-back on a known number, or a family code word, is more reliable than recognising a voice.
How can I spot a deepfake video call?
Look for unnatural blinking, blurred edges around the face, lip movements slightly out of sync, and reluctance to turn the head or move a hand across the face. But deepfakes are improving quickly, so verify through a separate channel rather than relying on your eyes.
Will my bank ever ask for my OTP or PIN?
No. Genuine banks never ask for OTP, PIN, CVV or passwords over calls, SMS, email, chat or video.