AI Voice Cloning Scams in India: How to Spot a Deepfake Call

A stranger needs your voice for three seconds to fake it convincingly. In India, that has turned into a fraud category worth thousands of crores a year — and the fix has less to do with technology than with one boring house rule.

By Samarjit Kaur

on August 29, 2026

A woman from Mumbai transferred ₹97,500 last month after hearing her “cousin” beg for help over the phone. It wasn’t her cousin. It was an AI voice cloning scam in India, a fraud built on cheap cloning software and India’s instant-payment rails.

Cyber cells across the country are now logging thousands of these calls every quarter, and police say most victims never see it coming. Here’s why it works, and how to make sure it doesn’t work on you.

What Happened?

Voice-cloning fraud has moved from a niche cybercrime story to a mainstream one. Haryana’s cyber cell alone recorded over 2,300 voice-cloning fraud cases in the final quarter of 2025, a jump of roughly 450 per cent over the year before.

A national survey found that 47 per cent of Indian adults had either faced an AI voice or deepfake scam themselves or knew someone who had, and 69 per cent admitted they couldn’t confidently tell a cloned voice from a real one on a phone call.

The mechanics are almost insultingly simple. A scammer needs a short recorded sample of someone’s voice, a WhatsApp voice note, an Instagram reel, a wedding video, a customer-service call that leaked from a badly secured call centre. Off-the-shelf tools can now produce a passable clone from as little as three to five seconds of clean audio. What used to take a recording studio and a specialist now takes a laptop and a stolen clip.

Also Read: India’s Cyber Fraud Surge Puts Focus on AI Security and Digital Identity Reform

Why Does it Matter?

Because the fraud doesn’t rely on hacking your phone or your bank account. It relies on hacking your judgement.

The scammer’s real weapon is urgency: a “child” who has been in an accident, a “police officer” who says a parcel in your name contains contraband, a “CEO” who needs an emergency wire transfer before a deadline.

Government figures show that cyber fraud losses to Indian authorities rose to ₹22,846 crore in 2024, up from ₹2,290 crore in 2022. Hence, voice cloning is one of the fastest-growing slices of that number.

This matters to all those who spend long stretches on calls for work, support teams, finance staff, people managing client accounts from home.

Also Read: AI Deepfake Aadhaar Fraud Busted: Four Arrested in Biometric Bypass Loan Scam

How Does the Scam Actually Work?

The fraud runs on five stages, and understanding each one is what makes the warning signs further down actually make sense, rather than just a list to memorise.

1. Sourcing the voice sample

Fraudsters do not need to hack anything. They mine what’s already available. Our routine lives now involve recording and sharing; most adults already have several seconds of usable, clean audio sitting in public view without realising it.

Investigators have traced samples to leaked call-centre databases, where a single breach can hand fraud rings thousands of voice recordings at once, which is part of why corporate and BPO-linked scams have grown alongside the family-emergency variety.

2. Cloning the voice

The sample is fed into a voice-synthesis model, the same category of text-to-speech technology used legitimately for audiobooks, dubbing and accessibility tools. In 2023, generating a convincing clone needed 10-20 minutes of high-quality audio.

By 2026, three to five seconds is often enough for a usable result. Some tools go further and let the fraudster type any script & have it spoken back in the cloned voice, complete with adjustable emotion, panic, urgency, even forced calm, depending on what the scam calls for.

3. Building a script and wearing a disguise

Scammers pick a personality designed to short-circuit questions rather than invite them. Think of a relative calling you in medical distress, or a police or CBI officer alleging the victim’s identity is linked to a crime.

Another common pattern is workplace-targeted versions: “I am your CEO or MD, and need urgent payment instructions from you”. Bet on it, you will barely take the effort to double-check that information.

4. Placing the call with a spoofed identity

Caller ID spoofing allows the number to appear local, official, or even match a real bank or helpline. The victim’s phone doesn’t raise a red flag before the attendee on the line acts.

5. Collecting the payment before verification happens

This is the step that makes India’s fraud pattern unique. Since UPI settles transfers in seconds rather than days, there is no cooling-off period as with cheques or international wires.

Money can move through two or three intermediary accounts, often “mule” accounts opened with someone else’s stolen identity, before a victim has even hung up the phone, which is precisely why speed of reporting afterwards matters so much.

A concrete example: A finance controller at a Mumbai firm recently authorised a large wire transfer after a call that sounded exactly like the company’s CEO, requesting an urgent payment during quarter-end. The tone, cadence and even a small verbal habit specific to the CEO were all reproduced convincingly. The CEO was in an unrelated meeting the entire time. Every element of the call- the voice, the urgency, the instruction- was synthetic. Only the transferred money was real, and by the time the fraud was discovered, it had already moved through several accounts.

Also Read: Bill Gates Calls for Limits on AI Development, Warns of Job Losses, Cyber Risks and Human Control

Who Benefits and Who Loses?

Losers, overwhelmingly, are ordinary account holders, retirees, parents, small business owners, plus, less obviously, honest companies that rely on the phone channel for legitimate business. Every scam call makes customers more suspicious of the next real one.

Winners are the fraud networks themselves. Several of them operate at an industrial scale, and there is a growing industry of caller-verification and fraud-detection vendors who supply banks and telecom operators with tools to catch synthetic voices before money moves.

Also Read: ED Busts Pan-India Cyber Fraud Network: ₹2,904 Crore Cash Deposited Through 61,448 Machines Across 20 States

How to Spot a Deepfake Call: WARNING SIGNS

No single sign can prove that a call is fake. Cloned voices are good enough now that voice alone isn’t a reliable test. What works better is watching for a cluster of signals across three areas: how the call sounds, how the caller behaves, and what the situation is actually asking of you.

Audio & technical signals

  • Slightly flat or overly even tone, especially across the entire emotional sentence. Real distress rarely sounds consistent, word by word.
  • Odd pacing: Unnatural pauses, words crammed together, or breathing patterns that barely feel normal.
  • A faint robotic or “processed” quality under stress words, where the model struggles most to match emotion to sound.
  • Call quality that doesn’t match the story, a “hospital corridor” with no ambient hospital noise, or a “police station” that sounds too quiet.
  • Background noise that is on loop or repeats identically. This indicates a pre-recorded ambient track layered under the synthetic voice.

Behavioural and conversational signals

  • The caller resists or flatly refuses a video call, or claims the camera is “broken” or “not allowed” during an emergency or arrest.
  • Vague or generic answers to a specific personal question only the real person would know, a childhood nickname, a shared inside joke, a recent private conversation.
  • The caller keeps redirecting you back to the demand for money whenever you ask a clarifying question, rather than actually answering it.
  • Unusual or slightly “off” word choices, phrasing, or a persona that doesn’t quite match how that person actually speaks day to day.
  • The call becomes aggressive or tearful, or it disconnects abruptly the moment you say you want to verify or call back.

Situational and contextual signals

  • Extreme time pressure: “pay in the next ten minutes,” “the surgeon needs the deposit right now,” “the file closes today.”
  • A payment method that is instant and hard to reverse; UPI, wire transfer, or cryptocurrency- rather than anything that leaves a paper trail or cooling-off period.
  • An unfamiliar number, one that’s spoofed to look local, or a caller claiming to be from an official helpline that doesn’t match the number that helpline actually publishes.
  • The story involves secrecy: “don’t tell anyone else in the family,” “don’t discuss this with your bank,” “this must stay confidential”, a common pressure tactic to stop you from getting a second opinion.
  • A request that skips normal process entirely: a genuine bank, court or employer rarely asks you to resolve something serious over a single unscheduled phone call.

The single most reliable test: hang up and call the person or organisation back using a number you already have saved. Never call back on a number the caller gives you, texts you, or that appears on your screen.

A cloned voice cannot survive a callback. The fraudster is not on the other end of your saved contact.

If it’s a workplace call involving a payment, add a second reliable test. Verify the instruction through a separate channel entirely. E.g., an internal chat message or a colleague who can pitch and personally confirm the request, rather than replying to the same call.

Also Read: SBI Flags ₹6,300 Crore Banking Fraud: UPI Emerges as Biggest Scam Gateway

Comparison: Real Call vs Deepfake Call

SignalGenuine emergency callLikely deepfake scam call
UrgencyPresent, but caller can answer follow-up questionsExtreme, designed to prevent verification
Payment method requestedRarely demanded instantly by phoneImmediate UPI/wire transfer insisted upon
Caller IDMatches a saved contact or verified numberUnfamiliar, spoofed, or blocked
Willingness to call backNot an issueActively discouraged or call disconnects if you try
Personal verificationCan answer a private, pre-agreed questionEvasive, vague, or repeats generic details

Government and Regulatory Response

The Reserve Bank of India has repeatedly stated that neither it nor any bank will ever ask for an OTP, PIN, password or CVV over a phone call.

It has specifically warned against callers impersonating RBI officials.

Complaints and financial losses can be reported through the national cybercrime helpline at 1930 or the National Cyber Crime Reporting Portal (cybercrime.gov.in).

Investigators stress that reporting within the first hour improves the odds of freezing a transaction before the money moves through multiple accounts.

Separately, the Telecom Regulatory Authority of India (TRAI) is rolling out CNAP so that a verified name, rather than a bare number, will eventually appear on incoming calls.

Also Read: Beyond OTP: 7 Ways to Mitigate Digital Fraud in 2026

Securing the Future: Paths to Safety

Expect three trends to continue. Voice-cloning tools will keep getting cheaper and require even less sample audio.

Regulation will keep tightening around synthetic content & caller identity. The 2026 IT Rules amendments are an early version of a framework likely to expand. Banks, telecom operators & workplaces are increasingly building “verify before you pay” habits into official processes, just as OTP-based verification became routine after an earlier wave of phishing fraud.

What You Can Do Today?

  • Agree on a family code word that only real family members know, and use it whenever money or an emergency comes up over the phone.
  • Make “hang up and call back on a saved number” a household rule, not a suggestion for later.
  • Never share OTPs, PINs or CVVs over a call, regardless of who the caller poses to be.
  • Limit public voice samples where practical; long, clear audio clips on public social accounts are the raw material scammers use.
  • Report immediately: call 1930 or file at cybercrime.gov.in the moment you suspect fraud, even before you’ve lost money.

The technology behind these calls is genuinely new, but the defence against them isn’t. It’s the same discipline that has always protected people from confidence tricks: slow down, verify independently and don’t let urgency decide for you.

A CLONED VOICE CAN BE NEARLY PERFECT. A CALLBACK TO A NUMBER YOU ALREADY TRUST STILL ISN’T.

News Image