Deepfake Scam Explained: How AI Is Being Used for Online Fraud

Artificial intelligence is making digital content increasingly realistic. While this has useful applications, the same technology is being misused by cybercriminals to create fake voices, videos and images that canappear genuine. These deepfake scams can be used to impersonate family members, senior executives, public figures, financial experts or even trusted organisations to trick people into transferring money or sharing sensitive information.

Read more
₹5 Lakh cover starting at ₹2 /day++
Safeguard your digital life from
identity theft & fraud
online financial scams
cyberbullying & harassment
We don't spam
Check your premium now
By clicking on "Check your premium now" you agree to receive assistance and agree to our Privacy Policy and Terms Of Use
  • Wallet-friendly plans
  • 24/7 claim support
  • IRDAI-certified advisors

We don't spam

We don't spam

Key Takeaways

  • Deepfake scams use AI-generated audio, video or images to impersonate real people.
  • Fraudsters can use deepfakes for financial fraud, identity theft and social engineering.
  • A realistic-looking video call or familiar voice does not guarantee that the person is genuine.
  • Always verify unusual requests through a separate, trusted communication channel.
  • Cyber Retail Insurance may provide financial protection against certain cyber losses, depending on the policy's coverage and exclusions.

What Is a Deepfake Scam?

A deepfake scam is a type of fraud in which criminals use artificial intelligence to create or manipulate videos, images or voice recordings to make someone appear to say or do something they never actually did.


For example, a fraudster could use publicly available videos and voice recordings of a company executive to create a fake video call. They may then instruct an employee to urgently transfer money to a particular account. Similarly, scammers may clone the voice of a family member and claim that they need money urgently.


Deepfake technology can be used to:

  • Clone someone's voice
  • Create realistic AI-generated videos
  • Manipulate facial expressions and movements
  • Generate fake images
  • Impersonate trusted individuals

The problem is that modern deepfakes can be difficult to distinguish from genuine content. Many reports also highlight that deepfakes can be used to impersonate people and steal money or data.

How Do Deepfake Scams Work?

Most deepfake scams follow a relatively simple sequence:

  1. Data Collection: Scammers collect publicly available photographs, videos and voice recordings of their intended target.
  2. Deepfake Creation: AI tools are then used to create a fake voice, image or video that resembles the target.
  3. Impersonation: The scammer pretends to be someone the victim already trusts, such as a family member, bank representative, colleague or senior executive.
  4. Victim Contact: The victim may receive a phone call, WhatsApp message, video call, email or social media message.
  5. Fraudulent Request: The scammer creates urgency and asks the victim to transfer money, share credentials, reveal personal information or perform another action.

This combination of AI-generated content along with the impersonation and urgency makes deepfake scams particularly dangerous.

Types of Deepfake Scams

Deepfake fraud can take several forms depending on how the fake content is used.


1. Deepfake Video Scam

Fraudsters use AI-generated video to impersonate a trusted person during a video call. For example, a scammer may pretend to be a senior executive and instruct an employee to make an urgent payment.


2. Deepfake Voice Scam

The scammer uses AI to replicate someone's voice and then makes a phone call requesting money or sensitive information. A familiar voice should therefore not automatically be treated as proof of identity.


3. Deepfake Identity Fraud

AI-generated photographs or videos can be used to create fake identities or bypass certain verification processes.


4. Deepfake Financial Scam

Fraudsters may create videos featuring celebrities, financial experts or public figures promoting fake investments, trading opportunities or other financial schemes.


5. Family or Friend Impersonation Scam

A scammer may clone the voice or appearance of a family member and claim to be facing an emergency. The objective is usually to make the victim act before they have time to verify the request.

Deepfake Scam in India: What the Numbers Say

what treatments are not covered under <a href=group health insurance" loading="lazy" width="100%" height="100%" /> Where indians report seeing deepfakes

Deepfake scams are part of a much larger digital fraud problem in India. McAfee's 2026 State of the Scamiverse report found that:

  • 82% of Indians surveyed said that they are more wary of opening messages from unknown senders than they were a year ago .
  • 51% said they had lost money to a scam.
  • Indians reported encountering 4 deepfakes per day on average.
  • 70% said their social media account had been compromised in the previous year.
  • Indians who lost money reported an average loss of ₹93,915.

What does this tell us? Deepfake fraud should not be viewed as an isolated technology problem. It is becoming another tool within the broader ecosystem of online scams, social engineering and financial fraud.

Examples of Deepfake Scams

1. Arup Engineering Firm Incident

In early 2024, an employee at global engineering company Arup was reportedly tricked into transferring approximately US$25.6 million after fraudsters used deepfake technology to impersonate the company's CFO and other executives during a video conference.


2. Hong Kong Multinational Company Fraud

In 2024, a clerk at a multinational company in Hong Kong was reportedly deceived into transferring HK$200 million after participating in a video conference where fraudsters impersonated senior executives using deepfake technology.


3. UK Energy Company Voice Scam

In 2019, a UK-based energy company CEO received a call from someone who sounded like the CEO of the company's German parent company. The caller requested an urgent transfer of €220,000 to a supplier. The voice was later identified as part of a deepfake scam.


4. Singapore Finance Director Incident

In 2025, a finance director at a multinational company in Singapore reportedly authorised a US$499,000 payment after joining a Zoom call with individuals he believed were senior executives. The meeting was allegedly created using AI-generated visuals and voices.


The above incidents demonstrate an important lesson: seeing and hearing someone is no longer sufficient proof of identity.

How to Protect Yourself From Deepfake Scams

Verify Through Another Channel

If someone asks for money or sensitive information, contact them separately using a known phone number or another trusted communication channel.


Don't Trust Urgency

Pause before acting on an unexpected request. A legitimate emergency does not necessarily mean you should skip verification.


Limit Publicly Available Content

The more photographs, videos and voice recordings publicly available about you, the more material scammers may have to work with. Review your social media privacy settings regularly.


Use Multi-Factor Authentication

Enable MFA on banking, email and other important accounts to add another layer of protection.


Avoid Sharing Sensitive Information

Never share passwords, PINs, OTPs or banking credentials merely because the person on the other end appears familiar.

What to Do If You Become a Victim of a Deepfake Scam?

If you believe you have fallen for a deepfake scam, act quickly.

  1. Contact your bank immediately if money has been transferred.
  2. Block cards or accounts where necessary.
  3. Report the incident through India's National Cyber Crime Reporting Portal.
  4. Change compromised passwords and secure affected accounts.
  5. Preserve evidence, including messages, call records, screenshots, emails and transaction details.

Pro Tip: Don't delete suspicious messages or call records. They may help establish what happened during the investigation.

Can Cyber Retail Insurance Protect You From Deepfake Scams?

Deepfake scams can result in consequences such as theft of funds, identity theft, online financial fraud and other cyber-related losses. Personal Cyber Insurance available through Policybazaar is designed to protect individuals against financial losses arising from cyber threats, including identity theft and online fraud.


However, it is important to understand that not every deepfake-related loss will automatically be covered.


Coverage depends on the specific policy wording, insured event, applicable conditions, exclusions and limits.


What Can Cyber Retail Insurance Potentially Help With?

Depending on the policy, personal cyber insurance may provide protection for risks such as:

  • Theft of Funds: Financial loss resulting from certain covered cyber frauds.
  • Identity Theft: Costs or losses associated with misuse of personal identity.
  • Online Financial Scams: Protection against specified online financial frauds.
  • Cyber-Related Personal Risks: Certain policies may also cover risks such as cyberbullying or harassment.

So, if a deepfake is used as part of a covered cyber fraud, Cyber Retail Insurance may help mitigate the financial impact, subject to the terms of the chosen policy.


Important: Cyber insurance is not a replacement for verification and cybersecurity precautions. Always check whether deepfake-enabled fraud, unauthorised transactions or the specific type of financial loss is covered before purchasing a policy.

Deepfake Scam vs Traditional Online Scam

Factor Traditional Online Scam Deepfake Scam
Main technique Fake links, messages or websites AI-generated voice, video or images
Impersonation Usually text or basic caller impersonation Can replicate a person's appearance or voice
Trust factor Depends on convincing messages Uses realistic digital identity
Common objective Steal money or credentials Steal money, information or impersonate someone
Detection Often easier through links or spelling errors Can be significantly harder to identify

The important difference is how convincingly the scammer can imitate a trusted person.

Conclusion


Deepfake scams are changing the way online fraud works. A scammer no longer needs to rely only on a convincing message or phone call; they can potentially recreate a person's face, voice and mannerisms to make a fraudulent request appear genuine.


As AI-generated content becomes more sophisticated, the safest approach is to verify before trusting. Don't transfer money simply because a familiar face appears on a video call or a familiar voice is heard on the phone.

Frequently Asked Questions
  • Can a deepfake scam steal money?

    Yes. Deepfake scams can be used to convince victims to make unauthorised or fraudulent payments.
  • How can I identify a deepfake video?

    Look for unusual facial movements, poor lip-syncing, unnatural voice patterns, inconsistent lighting and unusual behaviour. However, visual checks alone may not always be reliable.
  • What should I do after a deepfake fraud?

    Immediately contact your bank if money is involved, secure your accounts, preserve evidence and report the incident through the appropriate cybercrime reporting channels.
  • Does Cyber Retail Insurance cover deepfake scams?

    It depends on the policy. If the resulting loss falls within a covered cyber event, the policy may provide financial protection, subject to its terms, conditions, limits and exclusions
We don't spam
View plans
By clicking on "" you agree to receive assistance and agree to our Privacy Policy and Terms Of Use
Continue
Get quick help
Cyber Retail Insurance Articles
SIM swap fraud occurs when hackers take over the target's mobile number by obtaining a new SIM card using the...Read more
18 Apr 2025 by Policybazaar 4373 Views
Multi-Factor Authentication (MFA) is a security mechanism that requires users to verify their identity through two...Read more
23 Jan 2026 by Policybazaar 988 Views
A drive-by download attack is a stealthy cyber threat where malicious software is automatically installed on a...Read more
27 Jan 2026 by Policybazaar 959 Views
Artificial intelligence is making digital content increasingly realistic. While this has useful applications, the...Read more
23 Jan 2026 by Policybazaar 908 Views
Modern cyberattacks are no longer carried out by a single computer or hacker. Instead attackers often rely on vast...Read more
26 Jan 2026 by Policybazaar 860 Views
A credential stuffing attack is a specialized form of account takeover where cybercriminals use automated botnets...Read more
27 Jan 2026 by Policybazaar 840 Views
Synthetic Identity Fraud is one of the fastest-growing and most difficult-to-detect forms of financial fraud...Read more
27 Jan 2026 by Policybazaar 823 Views
Cybercriminals are constantly evolving their techniques to bypass traditional security controls One of the most...Read more
27 Jan 2026 by Policybazaar 806 Views
A Zero-Day exploit is a specialized cyberattack that targets a software vulnerability previously unknown to the...Read more
27 Jan 2026 by Policybazaar 778 Views
As organisations strengthen their cybersecurity defenses, attackers increasingly turn to low-noise techniques that...Read more
27 Jan 2026 by Policybazaar 768 Views
Cyberattacks are no longer random. Today’s attackers carefully study their targets, understand their habits...Read more
23 Jan 2026 by Policybazaar 758 Views
Some cyberattacks are loud and disruptive, while others are designed to stay invisible for as long as possible. A...Read more
27 Jan 2026 by Policybazaar 743 Views
Rogue software, commonly known as scareware, is a form of malicious software that uses social engineering to...Read more
28 Jan 2026 by Policybazaar 740 Views
DNS Spoofing, often used interchangeably with DNS Hijacking, is a deceptive cyberattack where an intruder...Read more
27 Jan 2026 by Policybazaar 726 Views
Smishing, a portmanteau of "SMS" and "phishing," is a cyberattack where criminals send deceptive text messages to...Read more
26 Jan 2026 by Policybazaar 725 Views
Rogue software, commonly known as scareware, is a form of...Read more
28 Jan 2026 by Policybazaar 740 Views
An Internet of Things (IoT) cyber attack targets the network of...Read more
28 Jan 2026 by Policybazaar 616 Views
As organisations strengthen their cybersecurity defenses...Read more
27 Jan 2026 by Policybazaar 768 Views
As digital services become more interconnected, user sessions...Read more
27 Jan 2026 by Policybazaar 635 Views
Synthetic Identity Fraud is one of the fastest-growing and most...Read more
27 Jan 2026 by Policybazaar 823 Views
A drive-by download attack is a stealthy cyber threat where...Read more
27 Jan 2026 by Policybazaar 959 Views
Cybercriminals are constantly evolving their techniques to...Read more
27 Jan 2026 by Policybazaar 806 Views
A credential stuffing attack is a specialized form of account...Read more
27 Jan 2026 by Policybazaar 840 Views
DNS Spoofing, often used interchangeably with DNS Hijacking, is...Read more
27 Jan 2026 by Policybazaar 726 Views
Some cyberattacks are loud and disruptive, while others are...Read more
27 Jan 2026 by Policybazaar 743 Views
A Zero-Day exploit is a specialized cyberattack that targets a...Read more
27 Jan 2026 by Policybazaar 778 Views
A Cross-Site Scripting (XSS) attack is a prominent web security...Read more
27 Jan 2026 by Policybazaar 588 Views
Cloud computing has changed the way in which businesses conduct...Read more
26 Jan 2026 by Policybazaar 650 Views
Vishing, or "voice phishing," is a sophisticated social...Read more
26 Jan 2026 by Policybazaar 653 Views
Smishing, a portmanteau of "SMS" and "phishing," is a...Read more
26 Jan 2026 by Policybazaar 725 Views
  • Disclaimers+


    +Disclaimer: The starting premium is ₹2 per day for a ₹5 lakh Sum Insured under an individual plan. The actual premium may vary based on the chosen plan type and selected add-ons. Standard terms and conditions apply. Please refer to the sales brochure for detailed information on risk factors, terms, and conditions before making a purchase.
    ++Disclaimer: The premium of Rs 112100/year is the starting price for sum insured of Rs 1 Crore that may vary depending on the business activity and services rendered, company turnover, and its geographical split, industries/customers to whom the product/service is being provided, website and domain network features, business continuity plan, and data protection measures. STANDARD TERMS AND CONDITIONS APPLY. For more details on risk factors, terms and conditions, please read the sales brochure carefully before concluding a sale.
    By clicking on "View Plans" you agree to receive assistance and agree to our Privacy Policy and Terms Of Use and also provide us a formal mandate to represent you to the insurer and communicate to you the grant of a cover.
    The details of insurance coverage, inclusions and exclusions are subject to change as per solutions offered by insurance providers. The content has been curated based on the general practices in the industry. Policybazaar is not responsible for the factual correctness of these details.

icon Expert advice made easy icon
  • Date
  • Time

When do you want a call back?

  • Today
  • Tomorrow
  • 23 Sep
  • 24 Sep
  • 25 Sep
  • 26 Sep
  • 27 Sep

What will be the suitable time?

  • 11:00am - 12:00pm
  • 12:00pm - 01:00pm
  • 01:00pm - 02:00pm
  • 02:00pm - 03:00pm
  • 03:00pm - 04:00pm
  • 04:00pm - 05:00pm
  • 05:00pm - 06:00pm

Tell us the number you want us to call on

Your privacy matters. We wont spam you

Call scheduled successfully!

Our experts will reach out to you on Today between 2:00 PM - 3:00 PM

Thank you
Our experts will provide you assistance with your
insurance coverage. Be assured, all your questions
will be answered
Claude
top
Close
Download the Policybazaar app
to manage all your insurance needs.
INSTALL