An AI-generated video of India’s Union Finance Minister, Nirmala Sitharaman, endorsing a high-return trading platform has been running as paid social advertising for at least twelve months. India’s PIB Fact Check Unit has debunked fresh variants of it at least six times in 2026 alone. Victims in Belagavi, Hyderabad and Pune have reported losses from ₹7.9 lakh to a reported ₹1.07 crore. On 30 July 2026, Hyderabad’s Cybercrime Police summoned Meta and asked it to send a technical team to explain the safeguards it deploys against this content.
Read the debunks in date order and a pattern appears that no single one of them shows. Across every dated variant, the entry price the ad asks for is identical — ₹22,000 — while the payoff it promises escalates roughly fourfold, from ₹5.5 lakh a week in April 2026 to ₹22 lakh a month by July. That is not a famous face being reused by unrelated copycats. That is one operation sweeping a variable, with a fixed price point at the top of a stable funnel.
Which locates the defensive problem precisely. The layer that changes is the ad copy, and it is free to regenerate. The layer that does not change is the synthetic face and voice, and it is the only expensive thing the attacker owns. Every control India has deployed against this campaign — per-video fact-checks, statutory takedown notices, FIRs, mule-account freezes — acts on the layer that changes.
- 12 months of continuous circulation — the synthetic Sitharaman persona runs from the OECD AI Incidents Monitor entry of 18 August 2025 to victim reports in August 2026.
- ₹22,000, unchanged in every dated variant, while the advertised return rose from ₹5.5 lakh a week to ₹22 lakh a month — roughly fourfold in ninety days.
- Three invariants across four cities: the fixed entry price, a first contact from a UK country code, and a small real credit before the large fake balance.
- At least six PIB debunks in 2026 did not end it, because a fact-check is a per-artefact instrument and the artefact regenerates at no cost.
- Documented losses of ₹7.9 lakh to ₹1.07 crore across Belagavi, Bengaluru, Hyderabad and Pune; the Belagavi case names two accused.
- Of five attack stages, no deployed control reaches Stage 1 — generating the reusable synthetic asset, the only expensive step in the chain.
An AI-generated video of India’s Union Finance Minister Nirmala Sitharaman endorsing a fake trading platform has run as paid social advertising since at least August 2025. India’s PIB Fact Check Unit has debunked fresh variants at least six times in 2026 alone. Across every documented variant the entry price is the same — ₹22,000 — while the promised payoff rises from ₹5.5 lakh a week to ₹22 lakh a month. On 30 July 2026 Hyderabad’s Cybercrime Police summoned Meta to explain its safeguards.
What is the “Nirmala Sitharaman” deepfake investment scam?
Short answer. It is an AI-generated video of India’s Union Finance Minister appearing to endorse a high-return trading platform, bought as paid advertising on Meta and Google properties. It has circulated continuously since at least August 2025. India’s PIB Fact Check Unit has debunked fresh variants at least six times in 2026.
The video does not exist as a single artefact. It exists as a family of artefacts that share one synthetic performance: the Finance Minister’s face and voice, rendered saying words she never said, dropped into a succession of advertising wrappers. The wrappers change. The performance does not.
The earliest record we could find of the persona in circulation is the OECD AI Incidents Monitor entry for 18 August 2025, which logs AI-generated videos of Sitharaman endorsing high-return investment schemes and notes the Press Information Bureau’s confirmation that they were fabricated. A second OECD record, dated 16 April 2026, logs the same persona advertising a return of ₹5.5 lakh on a ₹22,000 stake within a week — a claim the record characterises as roughly 2,500%. Between those two entries and the present, victims across at least four Indian cities have reported losses running from ₹7.9 lakh to more than a crore.
The Finance Minister herself has acknowledged the problem publicly. Under the headline “‘I have seen deepfakes of myself’”, Deccan Herald reported (PTI, 7 October 2025) her remark that the videos are “just a reminder for the ‘urgency’ with which we need to up our defences against such actors”. Ten months later the campaign was still running, which is the gap this article is about.
This article is not a recap of those losses. It is an argument about why they kept happening for twelve months while a national fact-checking unit, a statutory takedown regime and a city cybercrime police force were all actively working the case. The short version is that all three act on the wrapper, and the wrapper is free to replace.
Why does every version of the ad ask for exactly ₹22,000?
Short answer. Because it is one operation A/B-testing its own copy, not many copycats reusing a famous face. Across four dated variants the entry price is identical — ₹22,000 — while the advertised payoff escalates roughly fourfold, from ₹5.5 lakh a week in April 2026 to ₹22 lakh a month by July 2026.
This is the observation that made us write about this campaign rather than the several other public-figure deepfake ad frauds in circulation this month. Read one of these debunks and you see a scam. Read all of them in date order and you see a product being tuned.
The entry price never moved. The promised payoff quadrupled.
Every documented variant of the “Nirmala Sitharaman” investment ad opens at the same figure — ₹22,000 — while the return it advertises escalates across the year. A fixed price point with a churning payoff claim is the signature of one operation testing its own copy, not of unrelated copycats reusing a famous face.
The layer that changes is the ad copy. The layer that does not change is the synthetic face and voice. Per-video fact-checks and per-URL takedowns act on the copy, which is regenerated for free. The reusable asset is the only component with a stable signal to test — and it is the one component no deployed control in this chain inspects.
Table 1: Documented variants of the Sitharaman investment ad. The entry price is constant across every variant that records one; the advertised return rises about fourfold over three months.
Two things follow from that table, and they point in opposite directions for a defender.
The first is that the copy is disposable. A payoff claim that moves from ₹5.5 lakh a week to ₹70,000 a day in ninety days is not a claim anyone is attached to. It is a variable being swept. Each sweep produces a new video file, a new ad creative, a new landing page and therefore a new thing for PIB to debunk and a new URL for an intermediary to block. The cost of generating the next variant is close to zero; the cost of debunking it is a human analyst, a verification cycle and a published notice.
The second is that the face is not disposable. A fixed ₹22,000 price point across every variant tells you the operators are optimising conversion inside a funnel whose top is stable. They are not re-shooting the Finance Minister for each test, because the whole value of the asset is that it is the Finance Minister — the most authoritative possible endorser of an Indian investment product. Rendering a convincing synthetic performance of a specific, heavily-filmed public figure is the one expensive step in this chain, and it is the one step the operators reuse rather than repeat.
That asymmetry is the whole story. The defence is spending its expensive resource — human verification — on the attacker’s cheap resource, and spending nothing at all on the attacker’s expensive one. Anyone who has looked at why some deepfake generators are harder to detect than others will recognise the shape: a reused generator output carries a reused signal, and a reused signal is the most detectable thing in an attack chain.
The price point is not the only invariant. Two more repeat across victim accounts from different cities, reported by different outlets months apart, and together they are stronger evidence of a single operation than any one of them alone.
A first contact from a UK country code. The Hyderabad retired doctor was approached over WhatsApp “from a number with a UK code”, per Outlook Money. A retired professor in Shankarapuram, Bengaluru was called by a man giving his name as “Abhishek” from a UK number, per The420.in. Same routing, two cities, two outlets.
A small real credit before the large fake balance. The Bengaluru victim was credited ₹3.90 lakh in fabricated “profits” early on, then shown a dashboard holding over ₹1 crore, having transferred ₹65 lakh; ₹61.10 lakh was never recovered. The Pune account describes the same manoeuvre at a smaller scale — ₹1,000 credited as “trading profit” to establish confidence. Paying a victim a little real money to buy a lot of trust is a scripted step, not an improvisation.
Three invariants across four cities is a fingerprint. It is not proof of a single operator and we make no such claim — but it is the reason we treat these as one campaign rather than a genre, and the reason a control keyed to the reused asset would generalise across all of them. The same logic drove our reading of the Sapphire Network’s cloned-newsroom ad supply chain and of the industrialised synthetic-fraud supply chain behind it.
How does the attack run from ad impression to emptied account?
Short answer. In five stages. A synthetic asset is generated once; it is wrapped in ad copy and bought as paid placement; the ad is served at scale; responders are moved off-platform to WhatsApp or Telegram and asked for Aadhaar, PAN and bank details; and a fake trading platform shows a rising balance until withdrawal is blocked behind fees.
The stage sequence is consistent across the victim accounts we read, which matters more than any single account: it is the repetition, not the individual case, that identifies an operation.
The clearest description comes from Outlook Money’s account of a 71-year-old retired doctor in Hyderabad who lost more than ₹20 lakh from late March 2026. The path ran: online ad carrying the Sitharaman video, then a WhatsApp message from a number with a UK country code, then a request for Aadhaar, PAN and bank details from someone presenting as a representative of a firm calling itself “Fin Bridge Capital”, then access to a platform that displayed rising figures to encourage larger deposits. The deception surfaced only at withdrawal, when the operators demanded additional fees before releasing a supposed $80,000 balance held in a wallet labelled “Bitcoin Block”.
Table 2: The five stages of the chain, with the attacker’s cost at each. Only Stage 1 is expensive, and only Stage 1 is reused unchanged.
Stage 4 deserves a note that goes beyond this campaign. The documents harvested there — Aadhaar, PAN, bank details, and in the Pune reporting a full demat account opening — are not collected to complete the fraud. The fraud does not need them; the money moves by transfer. They are collected because a verified Indian identity is independently saleable, and because the same package is what an attacker needs to pass a remote onboarding check somewhere else. That is the hand-off point between this kind of consumer investment fraud and the deepfake pressure on remote video-KYC flows that identity teams see from the other side.
Which of India’s controls actually reach which stage?
Short answer. Four controls are in play: PIB fact-check debunks, statutory takedown notices to intermediaries, police FIRs and arrests, and mule-account freezes. Between them they cover stages 3 and 5 well, stage 4 conditionally, stage 2 barely, and stage 1 not at all.
Four controls, five stages, and the one stage none of them inspects.
Read the top row first. Stage 1 — generating the synthetic Sitharaman asset — is missed by all four controls India has actually deployed against this campaign. Every control fires downstream of it: after the ad is live, after the ad is reported, after the money has moved. That is why six PIB debunks in seven months did not end the campaign.
The blind spot in the top row is not an oversight by any of the four institutions involved. Each control is doing precisely the job it was designed for. The problem is that all four were designed against a threat model in which the expensive part of a fraud is distribution — printing, broadcasting, cold-calling, renting a boiler room — and the cheap part is the lie itself. Synthetic media inverts that. The lie is now the capital asset and the distribution is a card payment to an ad platform.
India’s own account of its instruments makes the point better than we can. The Ministry of Information and Broadcasting’s October 2025 backgrounder, Curbing Cyber Frauds in Digital India, lists what the state has actually deployed. Read the list as a defender: more than “9.42 lakh SIM cards and 2,63,348 IMEIs” blocked; “3,962 Skype IDs and 83,668 WhatsApp accounts” blocked by the Indian Cybercrime Coordination Centre; a Sahyog portal that “enables the automated issuance of removal notices to intermediaries”; and, through the Citizen Financial Cyber Fraud Reporting and Management System, more than ₹5,489 crore saved across over 17.82 lakh complaints.
Every one of those is an identifier control. It blocks a number, an account, a handle, a URL, a transfer. Not one of them inspects a pixel. The document does name the threat — it lists “cases of deepfakes leveraging AI” among the emerging threats it is responding to — but the response it enumerates is entirely a response to identifiers. That gap between the threat named and the instruments listed is, as far as we can tell, the most precise statement of the problem available in an official Indian source.
Why did six PIB debunks in seven months not stop the campaign?
Short answer. Because a fact-check is a per-artefact instrument aimed at an artefact that regenerates. PIB corrects the specific video that has already been seen; it has no reach into the model that produced it, the ad account that bought the placement, or the next render, which can be live before the correction is published.
The scale of what PIB is doing is worth stating precisely, because the unit is often described loosely. Answering an unstarred question from Shri V. K. Sreekandan in the Lok Sabha on 1 April 2026, the Minister of State for Information and Broadcasting, Dr L. Murugan, put on record that the Fact Check Unit had published “a total of 2913 fact-checks” to date, and that it “has identified various fake claims related to the Government of India including deepfakes, AI-generated and misleading videos, notifications, letters and websites”. That is a substantial, functioning national capability — and its output medium is, per the same answer, posts across “X, Facebook, Instagram, Telegram, Threads and WhatsApp Channel”.
Note what that architecture implies. The correction is distributed through the same channels as the fraud, competes for the same attention, and arrives strictly later. A defender who wanted to beat a regenerating asset with corrections would need to publish faster than the attacker can render, forever. On the evidence of Table 1, the attacker rendered at least four times in the window PIB was correcting.
The dates make this concrete. PIB debunked a variant on 14 November 2025, per DD News, calling the video “fake and digitally altered” and confirming that “no such platform has been endorsed by the Government”. It debunked another in mid-April 2026, per Gulf News, stating that “neither the Finance Minister nor the Government of India is promoting such schemes”. It debunked another on 22 May 2026 and another on 30 July 2026. The Hyderabad doctor’s losses began in late March 2026 — in the gap between two debunks, to an artefact neither of them named.
This is the same structural failure we described in the context of what changed in deepfake regulation in 2026: rules that attach to a published item cannot bind an unpublished render.
What did Hyderabad’s Cybercrime Police actually ask Meta for?
Short answer. Not a takedown. According to The420.in, on 30 July 2026 Hyderabad’s Cybercrime Police asked Meta to send a technical team to explain the safeguards it deploys to detect, monitor and prevent such content from spreading. That is a question about architecture, not about a particular advertisement.
The distinction matters, and it is the most consequential development in this campaign to date. Every prior intervention asked a platform to remove a thing. This one asks a platform to account for a process. The420.in’s report states that police requested Meta “explain the safeguards it deploys to detect, monitor and prevent such content from spreading”, that a Meta representative has already appeared before investigators, and that the deepfaked figures at issue span Sitharaman, Amitabh Bachchan, Hyderabad MP Asaduddin Owaisi, Sachin Tendulkar, Ratan Tata and Mukesh Ambani. The report cites Section 79 of the Information Technology Act and amendments to the IT Rules made in October 2025 as the legal backdrop, and quotes the former IPS officer Prof Triveni Singh as a cybercrime expert on the matter.
Section 79 is the safe-harbour provision: an intermediary is not liable for third-party content provided it meets the due-diligence conditions the IT Rules set out. Reading the Rules themselves rather than the commentary on them is instructive, because two separate clocks appear, and both of them start after publication.
Rule 3(1)(d) requires an intermediary, “upon receiving actual knowledge in the form of an order by a court of competent jurisdiction or on being notified by the Appropriate Government or its agency under clause (b) of sub-section (3) of section 79”, to remove or disable access “as early as possible, but in no case later than thirty-six hours”. Rule 3(2)(b) is tighter and, for our purposes, more interesting: within “twenty-four hours from the receipt of a complaint”, an intermediary must take reasonable and practicable measures to remove content that “is in the nature of impersonation in an electronic form, including artificially morphed images of such individual”.
India, in other words, already has a synthetic-media-specific takedown obligation with a 24-hour clock. It is a genuinely strong instrument and it is precisely the wrong shape for this campaign. The clock starts on receipt of a complaint about a specific item. Twenty-four hours after a complaint, that item is gone — and the render that replaced it two days earlier is not covered by that complaint, because it is a different item. A per-item clock against a per-item-regenerating attacker is a treadmill with a legally mandated speed limit.
Table 5: India’s deployed instruments, read from the IT Rules 2021 text and the government’s own October 2025 backgrounder. Every clock starts after publication; none reaches Stage 1.
The Hyderabad request is the first intervention in this campaign that could in principle escape that treadmill, because a question about detection architecture is a question about Stage 2 — the moment the creative is submitted for paid placement and, uniquely in the whole chain, is held by a party with both the artefact and a commercial relationship with the buyer. Readers who followed the AI Act Article 50 and eIDAS 2 transparency obligations will recognise the same argument arriving from the European side: the enforceable moment is the one before publication, not the one after complaint.
We should be careful about what is and is not established here. A summons asking for an explanation is not a charge, a finding or a penalty. No Indian court has ruled on whether Meta’s ad review meets the due-diligence standard for synthetic political-endorsement advertising. What changed on 30 July 2026 is the question being asked, not the answer.
What has the campaign cost the victims on record?
Short answer. Individually documented losses in this campaign shape run from ₹7.9 lakh to a reported ₹1.07 crore, across Belagavi, Hyderabad and Pune. The Belagavi case produced a registered case against two named individuals, which makes it the firmest legal anchor in the set.
These are the cases we could corroborate by reading the reporting directly. They are not a total, and no source we found publishes a campaign-level loss figure for the Sitharaman persona specifically. Treat the table as a floor.
Table 3: Documented losses in the Sitharaman deepfake-ad campaign shape. Not a campaign total — no source publishes one.
The shape will be familiar to anyone who followed the ASIC investigation into deepfaked Albanese investment ads in Australia or the fabricated Zoom conference that cost one Singaporean victim S$4.9 million: a public figure’s authority, an ad-bought funnel, and a loss figure that lands long after the artefact has been replaced. What differs here is duration. The Australian and Singaporean cases were campaigns with beginnings and ends. This one has run for a year without interruption.
For scale rather than attribution, the same October 2025 government backgrounder records that cybersecurity incidents in India “rose from 10.29 lakh in 2022 to 22.68 lakh in 2024”. We are deliberately not deriving a share of that figure for deepfake-led investment fraud: no source we read breaks it out, and inventing the breakdown would be exactly the kind of number that gets repeated for years.
One adjacent case is worth naming because it shows what enforcement against Stage 2 looks like when it succeeds. In October 2025, the Free Press Journal reported that Mumbai’s Western Cyber Cell arrested four people — named in the report as Gigil Sebastian, Deepayan Banerjee, Chandrashekhar Naik and Danial Arumugham — over a share-market fraud that used deepfaked Indian business-news anchors. The report ties them to an intermediary, Value Leaf, which it says provided social-media advertising access to the fraudsters for ₹3 crore “even after being aware that these advertisements were being used to deceive people”, against roughly ₹400 crore in losses across 640 complaints that year. That is a different campaign from the Sitharaman one and we are not merging them. It is evidence that the ad-buying layer is reachable, and that when investigators reach it they arrest people rather than delete files.
Where do the sources disagree, and what are we not claiming?
Short answer. On the Pune case, materially. Reports differ on the victim’s age, the platform the video was seen on, whether the money moved through 36 accounts or 36 transactions, and the loss figure itself — ₹1.07 crore in most coverage against ₹2.3 crore in one 26 August headline. We present the disagreement rather than pick a winner.
Naming real people and real losses obliges us to be explicit about what is solid and what is not. Below is every load-bearing point of conflict we hit, and how we handled it.
Table 4: Source conflicts encountered and how each was resolved. Where we could not settle a figure, both versions appear.
Three further limits on this article, stated plainly.
- We did not analyse any of this media. DuckDuckGoose has not been given the Sitharaman videos and has run no detection on them. Every artefact observation here comes from PIB’s published findings or from the reporting; the argument about reuse is an argument about attacker economics, not a detection result.
- The “six debunks” count is a floor. It counts the PIB notices we could date from sources we read. PIB publishes primarily to social platforms, and the unit’s own total of 2,913 fact-checks is not broken down by subject, so there may well be more.
- No source attributes the campaign to a named operator. The fixed-price signature is consistent with a single operation; it does not prove one, and we make no claim about who is behind it.
What would a control that reaches Stage 1 actually look like?
Short answer. It would test the media, not the identifier, and it would run at ad submission rather than after complaint. Three properties matter: it inspects the artefact before paid distribution, it produces a reusable signature for the synthetic asset, and it survives the copy changing around that asset.
Nothing in this section is a policy proposal India has adopted. It is what follows from the gap matrix if you take the matrix seriously.
Screen at submission, not at complaint. The only party that holds the artefact before it reaches a victim is the platform receiving the ad buy. Every other control in Table 2 necessarily acts later. This is the same conclusion a Warsaw appellate court reached from the opposite direction when it held that Meta could not claim the EU hosting shield over deepfake ads — the existence of a pre-publication inspection stage is what makes pre-publication duties coherent.
Fingerprint the asset, not the file. A per-file hash is defeated by re-encoding. What is durable across the variants in Table 1 is the synthetic performance itself: the generator’s characteristic artefacts, the same voice model, the same rendered face under different crops and captions. Detection that keys on generator traces rather than file identity is the difference between blocking one upload and recognising the twelfth. We have written separately on the traces deepfake generators leave behind and why they persist through the transformations that break hashing.
Assume the human check has already failed. The advice given to the Indian public through this campaign has been to look for tells. It is reasonable advice and it did not save a retired doctor, a retired professor, a 76-year-old or a businessman, because by the stage the tells mattered the victim had already accepted the premise. Our own guide to how to spot a deepfake is explicit that visual inspection is a fallback, not a control, and we have argued separately that security training on its own cannot stop deepfake fraud. The population being targeted here — older, financially active, trusting of the Finance Ministry — is the population least served by a tells-based defence, and the romance-and-investment fraud playbook is built precisely around that.
Watch the reuse, because reuse is the tell that scales. The finding in Table 1 is available to a platform far more cheaply than to us. A platform can see that the same synthetic performance is being resubmitted with new copy at a stable price point across many accounts. That correlation is the single strongest signal in this entire campaign, and it is visible only at Stage 2, only to the ad platform, and only if someone is looking at the media rather than at the account.
What this campaign says about reusable synthetic personas
Short answer. That the deepfake has stopped being an event and become an asset. A synthetic persona of a sufficiently authoritative public figure is durable capital: rendered once, amortised across twelve months of campaigns, and immune to every control that acts on the copy wrapped around it.
The four lessons we would take from it:
- Treat a public figure’s likeness as infrastructure under attack, not as a reputational issue. The asset here is India’s Finance Minister’s authority over investment decisions. It has been under continuous exploitation for a year, and the institution whose authority it is has no instrument that reaches the exploitation.
- Count the attacker’s costs before designing the control. If the cheap step is the one being regenerated and the expensive step is the one being reused, a control aimed at the cheap step will lose on economics no matter how fast it runs. Six debunks in seven months is a lot of institutional effort applied to the wrong layer.
- A 24-hour statutory clock is a ceiling on damage, not a defence. India’s Rule 3(2)(b) is a better synthetic-media takedown obligation than most jurisdictions have. It still cannot win a race against zero-cost regeneration, because it is triggered per item.
- The ad-buying layer is where enforcement has actually landed. The Mumbai arrests over Value Leaf and the Hyderabad summons to Meta are the only two interventions in this space that reached upstream of distribution. Both went after the party that held the artefact before publication.
For identity and fraud teams the transferable point is narrower and more practical. If a synthetic persona can be amortised across a year of consumer fraud, the same asset can be amortised across a year of onboarding attempts, which is why a detection layer that only checks whether a session is live misses the reused artefact entirely. That distinction — liveness detection versus deepfake detection — is the same one this campaign has been exploiting at national scale, and the injection-attack route into verification flows is how a reused asset arrives at a KYC check without ever passing in front of a camera.
Why a finance minister and not a film star?
Short answer. Because the fraud being sold is an investment product, and a finance minister is the only public figure whose endorsement carries transferable authority over exactly that decision. A celebrity lends attention. A finance minister lends the appearance of sovereign approval, which is what the pitch actually needs.
This is worth separating out, because it explains why the persona is worth a year of reuse when a cheaper face would do. Deepfake ad fraud generally reaches for whoever is most recognisable. The reporting on the Hyderabad summons lists exactly that spread — Amitabh Bachchan, Sachin Tendulkar, Ratan Tata, Mukesh Ambani, Asaduddin Owaisi. Each of those buys a click.
Sitharaman buys something different. The specific objection a cautious Indian investor raises to an unregulated trading platform is is this allowed? — and the Union Finance Minister is the person whose apparent endorsement answers that objection rather than the attention one. Read the ad copy in that light and the fixed ₹22,000 makes more sense too: the entry price is set low enough to be a trial stake and high enough to be worth the operators’ handling, and the thing being optimised above it is not attention but permission.
It also explains why PIB is structurally the wrong respondent even though it is the correct one institutionally. PIB’s remit is to correct claims about the Government of India, so a fake ministerial endorsement is squarely its business. But the harm is not that citizens believe a false thing about the government; it is that they act on an investment pitch. The correction lands in the misinformation channel while the damage happens in the financial one. Whether a likeness used this way is separately actionable by the person depicted is a live question we have looked at in the context of the legality of deepfaking a public figure, and it is a different lever from either fact-checking or intermediary takedown.
What should an Indian bank or broker do differently tomorrow?
Short answer. Stop treating this as a customer-education problem. Every case on record had a bank in it: the victim opened a demat account, passed KYC, and made transfers that cleared. The detectable sequence is not the deepfake, which the institution never sees. It is the pattern of a first-time investor funding an unregistered counterparty in escalating tranches.
The institutions in this chain never see the ad. That is the point that makes the problem tractable: they do not need to. What they see is a customer whose behaviour matches a script, and the script is now documented in enough cases to be operationalised.
Table 6: Observables available to Indian financial institutions in the documented cases, none of which requires seeing the deepfake.
None of this replaces detection at Stage 2; it is what a defender does while Stage 2 remains uncovered. Institutions running remote onboarding have the additional exposure discussed in our work on how deepfakes bypass KYC, because the identity package harvested at Stage 4 of this campaign is the input to that attack.
Frequently asked questions
Did Nirmala Sitharaman endorse any investment platform?
No. India’s PIB Fact Check Unit has stated repeatedly that the videos are AI-generated and that neither the Finance Minister nor the Government of India has endorsed, approved or promoted any such scheme. The 14 November 2025 notice called the video “fake and digitally altered”.
How long has the deepfake Sitharaman investment ad been circulating?
At least twelve months. The earliest record we found is the OECD AI Incidents Monitor entry dated 18 August 2025; the most recent PIB debunk we could date is 30 July 2026, and victim reports continued into August 2026.
How much money has been lost to the Sitharaman deepfake ads?
No source publishes a campaign total. Individually documented losses run from ₹7.9 lakh in Belagavi to a reported ₹1.07 crore in Pune, with more than ₹20 lakh reported by a retired doctor in Hyderabad. Treat those as a floor rather than a total.
Why do fact-checks not stop this kind of deepfake advertising?
Because a fact-check corrects one published artefact and the artefact regenerates for free. Each new render is a new item, outside the scope of the previous correction, and the correction is distributed through the same feeds as the fraud but always arrives later.
Is Meta legally liable for deepfake investment ads in India?
Unresolved. Section 79 of the IT Act gives intermediaries safe harbour subject to the due-diligence duties in the IT Rules 2021, which include a 36-hour removal clock on government or court notice and a 24-hour clock on complaints about artificially morphed impersonation. Hyderabad’s Cybercrime Police have asked Meta to explain its safeguards; no court has ruled on whether they suffice.
What is the ₹22,000 figure in these ads?
It is the entry investment the ad asks for, and it is identical across every dated variant we found while the promised return escalated roughly fourfold. A fixed entry price with a churning payoff claim is characteristic of one operation testing its copy rather than of unrelated copycats.
Which public figures besides Sitharaman have been deepfaked in these scams?
The420.in’s report on the Hyderabad police summons to Meta names Amitabh Bachchan, Hyderabad MP Asaduddin Owaisi, Sachin Tendulkar, Ratan Tata and Mukesh Ambani alongside the Finance Minister.
What has Nirmala Sitharaman said about the deepfakes of her?
In remarks reported by PTI on 7 October 2025 she said she had seen deepfakes of herself, and described them as “just a reminder for the ‘urgency’ with which we need to up our defences against such actors”. The campaign was still running ten months later.
What can a bank or broker detect if it never sees the deepfake?
The behavioural script. In every documented case the victim received a small real credit framed as profit, then made escalating transfers to multiple unrelated beneficiaries, then hit withdrawal friction. Fan-out to unrelated beneficiaries is a mule-network signature rather than a trading pattern, and it is visible on the rails without any view of the advertisement.
Has anyone been arrested over deepfake investment ads in India?
Yes, in related cases. Two individuals were named in a registered case over the Belagavi loss, and in October 2025 Mumbai’s Western Cyber Cell arrested four people over a share-market fraud using deepfaked business-news anchors, tied to an ad intermediary that had sold social-media advertising access to the fraudsters.
Methodology
Short answer. Sixteen sources, all opened and read for this article: four primary government documents, two OECD AI Incidents Monitor records, and ten news reports across fourteen distinct publishers. Every figure in the body is traceable to one of them. Where sources conflict, Table 4 records the conflict instead of resolving it silently.
The four primary documents are the Press Information Bureau’s 1 April 2026 release recording the Fact Check Unit’s output in answer to a Lok Sabha question; the Ministry of Information and Broadcasting’s October 2025 backgrounder Curbing Cyber Frauds in Digital India, read as a PDF and quoted directly; the official text of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as published by MeitY, from which Rules 3(1)(d) and 3(2)(b) are quoted; and DD News, the Government of India’s broadcaster, for the 14 November 2025 PIB notice.
The two OECD AI Incidents Monitor records are used for dating the persona’s circulation and for the April 2026 return claim. They are curated incident records rather than reporting, which is why they are cited for existence and date rather than for detail.
Four deliberate omissions. We did not cite the Punekar News, Pune Pulse, CSR Journal or Time Maharashtra reports on the Pune case, because those pages would not load for us and we do not cite sources we have not read; the Pune figures in this article are therefore marked as reported and carried in Table 4 as unresolved. We did not derive any deepfake-specific share of India’s aggregate cybercrime figures, because no source we read breaks that out. On the Finance Minister’s own remarks we quote only the headline and standfirst of the Deccan Herald report, which is all of that page we were able to read, and we do not name the venue those remarks were made at. And we ran no detection on any media, because none was provided to us.
This article is updated when the case advances. The next material development to watch is whether the Hyderabad enquiry produces a finding about Meta’s ad-review process, which would be the first ruling anywhere in India on pre-publication duty for synthetic endorsement advertising. Last update: Q3 2026.
Sources
- Press Information Bureau, Government of India — Government Counters Misinformation; PIB Fact-Check Unit Issues Over 2,900 Fact Checks (1 April 2026, Lok Sabha answer)
- Ministry of Information & Broadcasting, Government of India — Curbing Cyber Frauds in Digital India (backgrounder, 8 October 2025, PDF)
- MeitY, Government of India — Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, official consolidated text (PDF)
- DD News / newsonair.gov.in — PIB Fact Check: viral video of Finance Minister promoting investment scheme is fake (14 November 2025)
- OECD AI Incidents Monitor — AI-Generated Deepfake Videos Falsely Endorse Investment Scam Using Indian Finance Minister’s Image (record 2025-08-18-e830)
- OECD AI Incidents Monitor — AI-Generated Deepfake Video Falsely Portrays Indian Finance Minister Endorsing Fraudulent Scheme (record 2026-04-16-6971)
- The420.in — Hyderabad Cybercrime Police Summon Meta Over AI Deepfake Investment Scams
- Outlook Money — Deepfake Of Finance Minister Used In Investment Scam: Hyderabad Doctor Loses Over Rs 20 Lakh
- Outlook Money — PIB Fact Check Flags Fake AI Video Of Nirmala Sitharaman Promoting Investment Scheme (22 May 2026)
- Organiser — Fact Check: PIB debunks AI deepfake falsely showing FM Nirmala Sitharaman endorsing Rs 70,000 a day investment scam (31 July 2026)
- Gulf News — PIB Debunks AI Deepfake: Viral Video of FM Nirmala Sitharaman Promoting High-Return Scheme Is Fake (17 April 2026)
- Asianet Newsable — Deepfake Scam: Belagavi Man Loses ₹7.9 Lakh After Watching Fake Nirmala Sitharaman Video
- Deccan Chronicle — Deepfake of Nirmala Sitharaman Used in ₹7.9 Lakh Online Investment Scam (8 May 2026)
- The420.in — Retired Professor Loses ₹61.10 Lakh in Deepfake Investment Scam Using Fake Nirmala Sitharaman Advertisement (Bengaluru)
- Deccan Herald / PTI — ‘I have seen deepfakes of myself’: FM Nirmala Sitharaman urges stronger defences to protect public trust (7 October 2025)
- Free Press Journal — Mumbai Cyber Cell Arrests Four In Chinese Share Market Scam Using Deepfake Videos Of Indian Business Anchors (October 2025)














