Hybrid Email to Deepfake Call Scam — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: High | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →Hybrid Email to Deepfake Call Scam in India 2026: Stay Alert to this High-Risk Fraud
The Hybrid Email to Deepfake Call Scam is an emerging and sophisticated cybercrime threatening Indian businesses and individuals by blending fake emails with advanced voice impersonations.
What Is the Hybrid Email to Deepfake Call Scam?
This scam targets companies, their vendors, and employees who handle payments or sensitive corporate information. Fraudsters gather intelligence from social media profiles, like LinkedIn, business directories, or even leaked data from cyber breaches to design convincing phishing emails. These emails often appear as legitimate internal or external company communications, requesting payment updates, account changes, or urgent vendor information verification.
After building trust via email, scammers escalate the attack by placing phone calls using deepfake technology. These calls replicate a senior executive’s voice or sometimes video, making it seem as if the company’s CEO, CFO, or vendor manager is personally confirming the payment request or vendor bank details. This hybrid approach is particularly effective because victims may feel pressured or reassured hearing an authoritative voice, leading to uninformed wire transfers or UPI payments.
In India, this scam has shown alarming growth since 2024, especially among medium to large enterprises that make frequent vendor payments. Although the Reserve Bank of India (RBI), CERT-In, and the Indian Cyber Crime Coordination Centre (I4C) have issued precautionary advisories about deepfake threats and phishing scams, awareness about this combined email-and-call tactic remains low outside professional security circles. Public complaints filed with cybercrime units indicate a rising number of such incidents, typically involving fraudulent transactions running into lakhs of rupees.
How This Scam Works — Step by Step
Data Collection: Scammers research the targeted company and its key employees on LinkedIn, corporate websites, and online directories. They may also gather sensitive data from past data leaks.
Email Impersonation: Using slightly altered sender email domains (for example, accounts like vendor@companny.com instead of vendor@company.com), fraudsters send payment update requests or vendor information change emails. The tone and formatting closely mimic standard corporate correspondence.
Initial Trust Building: Victims, often finance or procurement staff, respond to the email because it looks authentic and urgent.
Deepfake Voice Call: Shortly after email communication, the victim receives a phone call from a simulated voice of a senior company executive. This call confirms the email instructions, urging the victim to process a payment or provide sensitive bank details without delay.
Payment Execution: Trusting the voice and email, the victim initiates a payment via bank transfer or UPI to the fraudster’s account, often believing the funds are going to a legitimate vendor.
Fraud Detection and Delay: Victims realize the fraud days later, often after vendors deny receiving any payment. UPI payments, once success notifications appear, are mostly non-reversible, and bank transfers are difficult to claw back.
Financial Loss: The company or individual suffers a financial hit, with amounts sometimes exceeding several lakh rupees, alongside potential exposure of confidential vendor or employee data.
Real Warning Signs to Watch For
- Email sender domains with slight misspellings or extra characters (e.g., @companny.com instead of @company.com).
- Requests to update payment or vendor bank details with urgency.
- Multiple communications through different channels (email followed quickly by a phone call).
- Calls asking to bypass normal payment authorization processes.
- Voice on call resembling a known executive but with unnatural tone or slight audio glitches.
- Unsolicited messages from unknown contacts claiming to be company leadership.
- Pressure tactics insisting on immediate payment without standard checks.
What Happens to Victims
Victims of this scam in India often face severe financial and operational consequences. Companies may lose money that isn’t covered by insurance or bank dispute mechanisms, especially since UPI payments to fraud accounts are generally irreversible once settled. Beyond finances, victims can experience reputational damage if vendor relationships break down due to missed payments.
Emotionally, targeted employees report heightened stress and anxiety, worried about losing their jobs or facing legal action for procedural lapses. Cases have also surfaced where fraudsters misuse leaked Aadhaar-linked data in conjunction with these scams for further identity theft or SIM swap frauds, complicating recovery efforts.
What RBI and CERT-In Say
The Reserve Bank of India has repeatedly warned against payment-related frauds involving phishing and social engineering tactics. RBI’s Customer Education initiatives promote verifying payment details through official channels before processing transfers and stress the importance of multi-factor authentication. CERT-In has issued alerts on deepfake audio and video use in financial frauds, encouraging organizations to educate employees on verifying unusual payment instructions via multiple modes.
The Indian Cyber Crime Coordination Centre (I4C) recommends reporting such frauds immediately on the national cybercrime portal (cybercrime.gov.in) and contacting the dedicated cybercrime helpline at 1930 for guidance. The RBI also operates a helpline for banking fraud victims.
How to Protect Yourself
- Always verify email sender domains carefully for subtle changes or misspellings.
- Never process payment updates or vendor changes based solely on an email or a single call.
- When receiving high-value payment requests, confirm the instructions through a second independent channel, such as calling a known company phone number.
- Train finance and procurement staff regularly on spotting phishing and deepfake techniques.
- Use multi-factor authentication (MFA) on financial apps and email accounts to prevent unauthorized access.
- Report suspicious emails or calls immediately to your company’s IT or security team.
- Keep software, email filters, and antivirus tools updated to catch fake domains and phishing attempts early.
What to Do If You've Been Targeted
If you suspect you have been targeted or have fallen victim to this scam after transferring money:
- Immediately inform your bank and request to freeze or trace the transaction if possible.
- Report the incident to your company’s cybersecurity or compliance officer without delay.
- File a complaint with the local police cybercrime cell and register the case on the national cybercrime portal (cybercrime.gov.in).
- Call the cybercrime helpline at 1930 for additional support and follow their guidance.
- Inform the RBI helpline about the fraud to seek possible remediation options.
- Change all credentials related to your email, bank accounts, and company systems to prevent further unauthorized access.
- Keep all evidence including emails, call recordings (if available), and transaction details secure for investigation.
Frequently Asked Questions
Q: How can deepfake calls fool someone if they know the person?
A: Deepfake technology can convincingly reproduce a person's voice, sometimes replicating tone, pitch, and speech patterns. This can mislead even those familiar with the executive's voice, especially under pressure.
Q: Are UPI payments reversible if made in this scam?
A: Generally, UPI payments cannot be reversed once successful because they happen in real-time. Hence, extra caution is needed before authorising any UPI transfer, especially following unusual emails or calls.
Q: How can companies prepare their employees for hybrid email and deepfake call scams?
A: Conduct regular cybersecurity training, simulate phishing attempts, enforce strict policies on payment approvals requiring multi-person verification and multiple communication channels.
Verify any suspicious business messages or calls for payment changes with BharatSecure.app and report frauds immediately to the national helpline by dialing 1930.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Fake Meeting Multi-Executive Deepfake Scam — Severity: CRITICAL
- Human Trafficking by Local Indian Agents — Severity: CRITICAL
- SWIFT LoU Manipulation Banking Scam — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.