Hybrid Deepfake Business Email Compromise Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Hybrid Deepfake Business Email Compromise Scam in India 2026: A Critical UPI & WhatsApp Threat

In 2026, Indian businesses and professionals face a new and highly sophisticated cyber threat known as the Hybrid Deepfake Business Email Compromise (BEC) Scam, targeting UPI payments and WhatsApp communications with alarming success.

What Is the Hybrid Deepfake Business Email Compromise Scam?

The Hybrid Deepfake Business Email Compromise Scam is an advanced form of fraud combining fake but realistic deepfake technology with traditional business email compromise methods. The scam mainly targets Indian companies involved in substantial business transactions, especially those with global linkages or extensive vendor networks. Fraudsters exploit publicly available data from platforms like LinkedIn and leaked corporate databases to understand company structures, real employee identities, and communication styles.

In India, the scam is becoming a growing concern due to the increasing digitisation of payments and corporate correspondence, particularly with the wide use of UPI and WhatsApp for business communications. According to public complaints reported to cybercrime authorities, multiple organisations have faced significant monetary losses when fraudsters impersonate senior executives or trusted vendors using deepfake audio/visual content combined with genuine email threads. While specific official advisories on this exact hybrid scam remain limited, agencies such as RBI, CERT-In, and the Indian Cyber Crime Coordination Centre (I4C) have issued general warnings about the rising threat of deepfake-enabled fraud and sophisticated BEC scams.

How This Scam Works — Step by Step

  1. Reconnaissance Phase: Scammers search LinkedIn, corporate websites, and third-party data leaks to collect information about company employees, roles, email patterns, and recent transaction details. This helps them craft authentic-sounding messages.

  2. Access and Data Theft: Using malware, phishing, or exploiting database vulnerabilities with third-party vendors, the fraudsters gain access to internal email communications or mimic them convincingly.

  3. Deepfake Creation: They produce manipulated audio or video clips resembling key executives or vendor representatives, often in regional Indian accents or Hindi/English bilingual speech, making them highly believable.

  4. Initial Contact via Email: The scammer sends a highly tailored email appearing to come from a senior manager or vendor requesting an urgent payment or change in bank account details for invoices or contracts.

  5. Follow-up on WhatsApp or Call: To add urgency and authenticity, the victim receives a WhatsApp message or a call with deepfake audio reinforcing the payment instruction, sometimes impersonating voice patterns or speech mannerisms identified earlier.

  6. UPI Payment or Bank Transfer: Under psychological pressure, the employee or finance person authorises immediate payment through UPI or traditional methods, often to fraudulent accounts.

  7. Cover-Up: Scammers may request deletion of communications or impose non-disclosure to avoid raising alarms internally.

Real Warning Signs to Watch For

What Happens to Victims

Victims typically lose substantial sums in Indian Rupees, often through UPI payments that cannot be reversed once processed. This scam also exposes them to risks of Aadhaar data misuse if scammers access employee identification details during reconnaissance. Victims face financial strain as well as emotional distress due to breach of trust, reputational damage, and operational disruptions in their organisations. Moreover, cases of SIM swap incidents tied to this scam have been reported, complicating victim recovery and blocking communication channels for official grievance redressal.

What RBI and CERT-In Say

RBI has repeatedly cautioned users about authorising payments only after stringent verification, particularly related to fraudulent fund transfer requests sent via email or calls. CERT-In issues advisories highlighting the surge in cyber frauds leveraging social engineering combined with AI-generated content. The Indian Cyber Crime Coordination Centre (I4C) recommends businesses employ multi-factor authentication and heightened employee awareness training on deepfake and BEC threats. Victims and organisations are encouraged to promptly contact the National Cyber Crime Helpline at 1930 for assistance and report incidents on cybercrime.gov.in to trigger swift action.

How to Protect Yourself

  1. Verify Identity Independently: Always confirm payment requests or change of vendor details via a separate known contact number or in-person verification.
  2. Be Skeptical of Urgency: Question any demand for immediate payment or secrecy—it is often used to pressure victims.
  3. Use Multi-factor Authentication: Enable two-factor or multi-factor authentication on official emails and payment apps like UPI.
  4. Limit Access Privileges: Only finance team members authorised for payments should have access to critical systems and communication channels.
  5. Train Employees Regularly: Educate staff on deepfake scams, phishing, and the importance of verifying suspicious requests.
  6. Check Sender’s Email Carefully: Look for slight differences in email addresses or unprofessional language.
  7. Keep Software Updated: Maintain updated antivirus and malware detection tools to reduce data breach risks.

What to Do If You've Been Targeted

Frequently Asked Questions

Is the Hybrid Deepfake Business Email Compromise Scam only targeting big companies?
No, while big companies with international dealings are prime targets, small and medium Indian businesses dealing with multiple vendors are also at risk. The scammers adapt their tactics to the scale of the organisation.

Can UPI transactions made in this scam be reversed?
Generally, UPI payments are instant and non-reversible. Victims must act quickly by informing the bank and reporting to cybercrime authorities, but recovery is challenging.

How can I differentiate a deepfake audio call from a genuine one?
Deepfake calls may have subtle distortions, unnatural pauses, or robotic intonations. If anything feels unusual, always verify the caller’s identity using official contacts before taking any action.

For every suspicious message or call related to payments, verify immediately with BharatSecure.app’s free verification tools and report fraud to the 1930 helpline to protect yourself and your business.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.