How Do Live Deepfakes Steal Money From Users?
A textile industrialist lost ₹7 crore to a fake video call featuring a fake Supreme Court judge in a fake courtroom. Real-time face-swapping now runs on consumer hardware, and India's actual Supreme Court is demanding criminal law to catch up. Your face is the new attack surface.
Real-time deepfake software can now replace a face on a live video call using a mid-range gaming laptop, which means seeing someone on screen proves nothing. India's Supreme Court has asked the Union government to draft dedicated criminal provisions for deepfake fraud and "digital arrest" scams, because existing law was written for a world where video was evidence. Your defense is not spotting the fake. It is refusing to act on any video call, ever, without out-of-band verification.
The Fake Courtroom That Cost ₹7 Crore
SP Oswal, chairman of Vardhman Group and one of India's better-known textile industrialists, lost about ₹7 crore in 2024 to people who built him a courtroom.
Not a metaphorical one. The callers claimed to be CBI officers investigating a money-laundering case. They kept him on video for hours, and at one point patched him into what appeared to be a live Supreme Court hearing, complete with a person presenting as then Chief Justice D.Y. Chandrachud, a courtroom backdrop, and a verbal order to transfer funds into a "secret supervision account." He transferred the money in installments. Police later recovered roughly ₹5.25 crore, which is unusually lucky.
Think about who this happened to. A man who runs a multi-thousand-crore company, who deals with lawyers and regulators constantly, who is not naive about money. He was not fooled by a badly written email. He was fooled because he watched a judge's face move and speak in real time.
That case is the reason this stopped being a technology story and became a legal one. In hearings through early 2026, India's Supreme Court pushed the government to stop treating deepfake fraud as an ordinary cheating offence and write law that names the technique.
How a Face Gets Hijacked in Real Time
The engine behind this is the GAN, a generative adversarial network. Two neural networks are pitted against each other: a generator produces fake frames, a discriminator tries to catch them, and they train in a loop until the generator's output survives inspection. Newer diffusion-based pipelines have improved quality further, but the adversarial principle is what made face swapping practical.
The attack chain is depressingly short:
1. **Harvest.** Scrape 30 to 60 seconds of the target's face from LinkedIn videos, YouTube interviews, wedding reels, news clips. Public figures need no scraping at all. 2. **Train or fine-tune.** Off-the-shelf pipelines now do this in hours on a single consumer GPU. Older DeepFaceLab-style training took days. That gap closed. 3. **Inject.** A virtual camera driver feeds the swapped output into Zoom, Teams, WhatsApp video, Google Meet. The app cannot tell the difference between a real webcam and a synthetic feed. 4. **Pressure.** Voice cloning runs alongside, so the mouth and the voice match. Then the demand arrives, always urgent, always confidential.
The honest caveat: real-time output is still weaker than pre-rendered video. Fast head turns, a hand crossing the face, harsh side lighting, these still produce artifacts. But on a compressed 480p call over patchy mobile data, nobody notices. Bad connections hide bad deepfakes. Scammers know this and often blame the "network" for exactly that reason.
Why Smart People Hand Over the Money
Most explanations blame gullibility. That is lazy and it leaves you undefended, because the mechanism is authority plus isolation plus a clock.
"Digital arrest" scams work by never letting you off the call. Victims are told to stay on video continuously, sometimes for eight or ten hours, forbidden from contacting family or lawyers because the "investigation is confidential." That is not a con trick, it is interrogation methodology. Sustained pressure without outside contact degrades judgment in anyone. Sleep-deprived, frightened, watching a uniform on screen, you comply.
Add the second layer. Indians are trained to defer to the CBI, the ED, the Income Tax Department, and above all the courts. A judge's face carries something close to absolute authority. The scammers did not need Oswal to believe a stranger. They needed him to believe an institution.
And the deepfake does something subtler than trick your eyes. It removes doubt. Before this, a suspicious phone call left an escape hatch: ask for a video call. That hatch is now a trap. The verification step people were taught to use became the delivery mechanism.
If you are still telling your parents "ask them to video call you," you are actively teaching them the wrong lesson. Stop.
Four Defenses That Actually Hold Up
Forget artifact-spotting checklists. Counting blinks and looking for weird ear shadows worked in 2019. Against a 2026 real-time pipeline on a compressed call, you will fail, and worse, you will feel confident because you checked.
What works is procedural, not perceptual.
| Defense | What it costs you | Why it survives deepfakes |
|---|---|---|
| Callback on a number you already have | 2 minutes | The attacker controls their channel, not yours |
| Family or company safe word | One awkward conversation | No amount of video fidelity supplies a secret |
| Two-person rule on all transfers above a set limit | Slight process friction | Isolation is the scam's core requirement |
| Hang up and wait 30 minutes | Feels rude | Urgency is manufactured; real institutions can wait |
Do these today:
- **Agree a safe word** with parents, spouse, and your finance team. Something no scraped video contains. Never store it in a chat thread. - **Write the rule down:** no money moves on the strength of a video call, a WhatsApp message, or a voice, period. Only after a callback to a saved number. - **Know the ground truth about Indian law enforcement:** no agency arrests you over Zoom. No court orders funds into a "supervision account." No genuine officer forbids you from calling a lawyer. Any one of those three is proof of fraud. - **Report fast.** India's cybercrime portal (cybercrime.gov.in) and helpline 1930 can trigger transaction freezes. Oswal's ₹5.25 crore came back because police moved within days. Hours matter more than shame does.
Since February 2026, India's amended IT rules have tightened synthetic-media labelling obligations on platforms. Useful, but labelling does nothing for a private call. That gap is yours to close.
Key Takeaways
FAQ
Q: Can I tell a live deepfake by asking the person to turn their head or wave a hand across their face?
A: Sometimes, because fast occlusion and extreme profile angles still break many real-time pipelines, producing a smear or a flicker at the jawline. But treat it as a weak signal, not proof: a competent operator will simply blame the lag, freeze, and reconnect, and you have now taught them what to fix.
Q: Does India's new law actually protect me, or is it just headlines?
A: It helps at the platform level, since the amended IT rules in force from February 2026 push labelling and takedown duties onto intermediaries, and the Supreme Court has pressed the government for specific criminal provisions on deepfake and digital arrest fraud. It does nothing during a private WhatsApp video call at 11pm, which is precisely where the money is lost.
Q: What is the first thing I should do if I am on a call like this right now?
A: Hang up. Then call the person or agency back on a number you looked up yourself, and if any money has already moved, dial 1930 or file at cybercrime.gov.in immediately, because transaction freezes work in hours, not weeks.
Conclusion
The single change worth making today takes ten minutes: pick a safe word with your family and your finance team, and write down one rule that no transfer happens on the strength of a face on a screen. India's courts are finally forcing the law to name this crime, but a statute arrives after your money is gone. Verification on a channel you control arrives before.
💡 Lucas's Insight
Related Posts
- How Are AI Deepfakes Stealing Billions From You?
A CFO in Hong Kong wired $25 million after a video call with people who didn't exist. AI deepfakes now clone voices from 3 seconds of audio and generate real-time video of anyone. This is happening to ordinary people right now — not just executives. - How Are AI Deepfakes Targeting Your College?
AI voice clones and deepfake video calls now impersonate students and university leaders to steal financial aid, redirect tuition, and crack into campus accounts. A 15-second voicemail of you is enough. Here's how the scam runs and how to shut it down. - How Are AI Deepfakes Impersonating Real Doctors?
Scammers are using AI to clone real doctors' faces and voices, then using those deepfakes to sell fake treatments, steal patient data, and drain bank accounts. The technology is cheap, the fakes are convincing, and most people have no idea it's even possible. Here's what you need to know right now.