Hybrid Email to Deepfake Call Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: High | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Hybrid Email to Deepfake Call Scam in India 2026: Stay Alert to this High-Risk Fraud

The Hybrid Email to Deepfake Call Scam is an emerging and sophisticated cybercrime threatening Indian businesses and individuals by blending fake emails with advanced voice impersonations.

What Is the Hybrid Email to Deepfake Call Scam?

This scam targets companies, their vendors, and employees who handle payments or sensitive corporate information. Fraudsters gather intelligence from social media profiles, like LinkedIn, business directories, or even leaked data from cyber breaches to design convincing phishing emails. These emails often appear as legitimate internal or external company communications, requesting payment updates, account changes, or urgent vendor information verification.

After building trust via email, scammers escalate the attack by placing phone calls using deepfake technology. These calls replicate a senior executive’s voice or sometimes video, making it seem as if the company’s CEO, CFO, or vendor manager is personally confirming the payment request or vendor bank details. This hybrid approach is particularly effective because victims may feel pressured or reassured hearing an authoritative voice, leading to uninformed wire transfers or UPI payments.

In India, this scam has shown alarming growth since 2024, especially among medium to large enterprises that make frequent vendor payments. Although the Reserve Bank of India (RBI), CERT-In, and the Indian Cyber Crime Coordination Centre (I4C) have issued precautionary advisories about deepfake threats and phishing scams, awareness about this combined email-and-call tactic remains low outside professional security circles. Public complaints filed with cybercrime units indicate a rising number of such incidents, typically involving fraudulent transactions running into lakhs of rupees.

How This Scam Works — Step by Step

  1. Data Collection: Scammers research the targeted company and its key employees on LinkedIn, corporate websites, and online directories. They may also gather sensitive data from past data leaks.

  2. Email Impersonation: Using slightly altered sender email domains (for example, accounts like vendor@companny.com instead of vendor@company.com), fraudsters send payment update requests or vendor information change emails. The tone and formatting closely mimic standard corporate correspondence.

  3. Initial Trust Building: Victims, often finance or procurement staff, respond to the email because it looks authentic and urgent.

  4. Deepfake Voice Call: Shortly after email communication, the victim receives a phone call from a simulated voice of a senior company executive. This call confirms the email instructions, urging the victim to process a payment or provide sensitive bank details without delay.

  5. Payment Execution: Trusting the voice and email, the victim initiates a payment via bank transfer or UPI to the fraudster’s account, often believing the funds are going to a legitimate vendor.

  6. Fraud Detection and Delay: Victims realize the fraud days later, often after vendors deny receiving any payment. UPI payments, once success notifications appear, are mostly non-reversible, and bank transfers are difficult to claw back.

  7. Financial Loss: The company or individual suffers a financial hit, with amounts sometimes exceeding several lakh rupees, alongside potential exposure of confidential vendor or employee data.

Real Warning Signs to Watch For

What Happens to Victims

Victims of this scam in India often face severe financial and operational consequences. Companies may lose money that isn’t covered by insurance or bank dispute mechanisms, especially since UPI payments to fraud accounts are generally irreversible once settled. Beyond finances, victims can experience reputational damage if vendor relationships break down due to missed payments.

Emotionally, targeted employees report heightened stress and anxiety, worried about losing their jobs or facing legal action for procedural lapses. Cases have also surfaced where fraudsters misuse leaked Aadhaar-linked data in conjunction with these scams for further identity theft or SIM swap frauds, complicating recovery efforts.

What RBI and CERT-In Say

The Reserve Bank of India has repeatedly warned against payment-related frauds involving phishing and social engineering tactics. RBI’s Customer Education initiatives promote verifying payment details through official channels before processing transfers and stress the importance of multi-factor authentication. CERT-In has issued alerts on deepfake audio and video use in financial frauds, encouraging organizations to educate employees on verifying unusual payment instructions via multiple modes.

The Indian Cyber Crime Coordination Centre (I4C) recommends reporting such frauds immediately on the national cybercrime portal (cybercrime.gov.in) and contacting the dedicated cybercrime helpline at 1930 for guidance. The RBI also operates a helpline for banking fraud victims.

How to Protect Yourself

  1. Always verify email sender domains carefully for subtle changes or misspellings.
  2. Never process payment updates or vendor changes based solely on an email or a single call.
  3. When receiving high-value payment requests, confirm the instructions through a second independent channel, such as calling a known company phone number.
  4. Train finance and procurement staff regularly on spotting phishing and deepfake techniques.
  5. Use multi-factor authentication (MFA) on financial apps and email accounts to prevent unauthorized access.
  6. Report suspicious emails or calls immediately to your company’s IT or security team.
  7. Keep software, email filters, and antivirus tools updated to catch fake domains and phishing attempts early.

What to Do If You've Been Targeted

If you suspect you have been targeted or have fallen victim to this scam after transferring money:

Frequently Asked Questions

Q: How can deepfake calls fool someone if they know the person?
A: Deepfake technology can convincingly reproduce a person's voice, sometimes replicating tone, pitch, and speech patterns. This can mislead even those familiar with the executive's voice, especially under pressure.

Q: Are UPI payments reversible if made in this scam?
A: Generally, UPI payments cannot be reversed once successful because they happen in real-time. Hence, extra caution is needed before authorising any UPI transfer, especially following unusual emails or calls.

Q: How can companies prepare their employees for hybrid email and deepfake call scams?
A: Conduct regular cybersecurity training, simulate phishing attempts, enforce strict policies on payment approvals requiring multi-person verification and multiple communication channels.

Verify any suspicious business messages or calls for payment changes with BharatSecure.app and report frauds immediately to the national helpline by dialing 1930.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.