AI voice scams.
A schoolteacher in Madhya Pradesh received a call from someone who sounded exactly like her cousin. The caller claimed to be in trouble and needed money transferred at once. The voice sounded authentic, and the teacher transferred the funds immediately.
The call was a fraud. The relative's voice had been cloned using AI. No suspicious links, stolen passwords, or warning signs were involved. The teacher did nothing wrong. Yet, the transaction need not have proceeded unexamined. Her bank could see that it sharply deviated from her usual pattern. It was an unusually large, urgent payment to a new payee.
Meanwhile, the receiving bank held information about the recipient's account history, including whether it resembled the rapid-in, rapid-out behaviour typical of a mule account. No single institution had the complete picture, yet together, they held sufficient signals to justify a warning, additional verification, or temporary review. Instead, the transfer went through without intervention.
Every stage of the fraud was visible to a different institution. A telecom network carried the call, and the bank processed the payment. The receiving account existed within the financial system. Each institution could see part of the risk, but no one was tasked to connect those signals or act on them.
Fraud networks have industrialized deception using AI impersonation, spoofed identities, mule accounts, and sophisticated social engineering. They exploit the gaps between institutions far more effectively than institutions cooperate with one another.
Banks remain the closest line of defence because they sit at the point of transaction. Yet the scale of exposure is significant. RBI data shows that digital payment fraud cases involving cards and internet banking run into the tens of thousands each year. MSC's research across India, Bangladesh, and Kenya shows that 55% of low- and moderate-income respondents receive fake calls or messages that impersonate legitimate institutions. A growing share of these losses stems from authorized push payment (APP) fraud, where victims themselves authorize transfers under coercion or deception. These cases often bypass conventional fraud controls designed to detect unauthorized activity.
The warning signs, however, are often visible before victims lose their savings. Earlier this year, in Visakhapatnam, a retired nurse arrived at her bank to transfer INR 50 lakh after fraudsters who posed as cybercrime officials threatened her with arrest. She arrived at her bank to initiate the payment. There, the bank manager recognized the warning signs, alerted authorities, and stopped the payment. This intervention required neither breakthrough technology nor perfect fraud detection. It required trained people who could recognize suspicious patterns and act.
The contrast with the Madhya Pradesh teacher is striking. In both cases, victims were manipulated into authorizing a payment. In one case, the transaction proceeded without intervention. In the other, human intervention prevented a loss.
In the teacher's case, the fraud began long before the payment was made. The cloned voice reached her through a telecom network. Caller ID spoofing and SIM-swap fraud increasingly allow criminals to impersonate banks, regulators, and law enforcement agencies. Telecom providers can often detect suspicious patterns before payments occur. India has already shown that such intervention is possible. Bharti Airtel, for example, uses AI systems to flag suspected spam calls and malicious links in real time.
Digital platforms have become another major channel for fraud distribution. Fake investment schemes, impersonation accounts, and fraudulent advertisements can reach thousands of potential victims before removal. Fraud today moves seamlessly across telecom networks, banking systems, and digital platforms, but accountability remains siloed. India, therefore, faces less of a detection problem than an accountability problem. The response requires action on three fronts.
The first step is a mandatory reimbursement framework for APP fraud backed by enforceable fraud-risk controls. In October 2024, the UK's Payment Systems Regulator introduced rules requiring sending and receiving banks to share liability for qualifying APP fraud losses, capped at GBP 85,000 (approximately INR 90 lakh) per claim. When institutions bear part of the financial consequences, prevention becomes a business priority rather than a compliance exercise.
Second, accountability must extend beyond banks. Australia's Scams Prevention Framework requires banks, telecommunications providers, and digital platforms to implement anti-scam controls or face financial penalties of up to AUD 50 million (INR 344 crore). Fraud prevention cannot stop at institutional boundaries because fraud crosses them.
Third, fraud detection must become collaborative. India's MuleHunter.AI initiative demonstrates that mule account detection at the network level is technically feasible. Patterns visible to one institution can become actionable across the system before funds disappear.
No fraud-detection system can fully distinguish coercion from legitimate urgency in real time, especially in a country processing billions of low-friction digital transactions. However, that cannot justify a system where institutions face little consequence for failing to act on visible warning signs.
The Madhya Pradesh teacher could not have known the voice on the call was fake. The institutions around her knew more than she did. The question is why none of them were required to act on it.