India’s fraud rate is falling. So why isn’t anyone relaxing?

India’s fraud rate is dropping, but AI is making each incident costlier and harder to detect.

India’s suspected digital fraud rate dropped sharply to 7.1% in 2025 from 13.1% the year before, a dramatic improvement by any measure. Yet it still runs nearly double the global average of 3.8%, and the numbers hide an uncomfortable truth: fraud volumes may be shrinking, but the damage per incident is climbing fast. Behind this paradox lies a fast-mutating threat: AI-generated documents, deepfake-assisted video KYC, synthetic identities stitched together from real fragments, and social engineering scams so polished that even seasoned customers struggle to spot them.

In this conversation, Natarajan Ramani, General Manager & Head of TransUnion India Data Analytics & Solutions (TU INDAS), and Anurag Anand, Head of Fraud Solutions at TU INDAS, unpack what’s really driving India’s fraud economics from logistics emerging as the country’s riskiest sector to why “responsible AI” in fraud detection is as much about protecting genuine customers as catching criminals, and what institutions must prioritise now to stay ahead.

Natarajan Ramani,
General Manager & Head
TransUnion India Data Analytics & Solutions (TU INDAS)

CISO Forum: TransUnion’s data show India’s suspected digital fraud rate fell sharply to 7.1% in 2025, down from 13.1% in 2024, yet it remains almost double the global rate of 3.8%. How do you reconcile this improvement with the claim that AI is fundamentally changing fraud economics? Is India losing ground in relative terms even as raw numbers improve?

Anurag Anand: This number has decreased significantly, and we should be proud of that improvement. Yet it is still quite high globally, which highlights the emerging ecosystem we have in India. A lot is being built, and many products have had phenomenal success in India, like UPI, digital onboarding, and real-time payments.

With all these capabilities exposed in the ecosystem, fraudsters have used and misused many of them for various ulterior motives, and now we’re trying to plug those gaps. Ecosystem players across the industry are doing a lot.
This includes private players like us building solutions and capabilities, trying to bridge the gap between the protection we can provide and what the government and regulatory bodies are also providing across many capabilities. We are still well ahead of the global rate, and we are working with the entire ecosystem to reach at least that global rate.

Specifically, your question was: on AI, what are we seeing? We are slowly and steadily seeing changes around this entire ecosystem. We work with many banks and financial institutions, and we are seeing them report more ID documents coming into their ecosystem—Aadhaar, driving licenses, and so on. They haven’t quantified those numbers exactly, but they have started seeing more of those kinds of documents being AI-generated. With AI, this has now become a household name. You have the tools to develop any new kind of imagery and so on. That is one use case. Second, in video KYC, when we talk to banks, they say the number of flagged entities is increasing much more, and we are seeing AI-related or other impersonation, where the background is shifted, and so on.

Raw numbers are improving. Something I would like to call out is that this has come out in RBI reports as well: the total number of frauds happening across the industry has decreased significantly year on year. But the total quantum, basically the impact that a particular fraud perpetrates in the industry, is quite significantly large. Basically, the volume might be decreasing, but the impact per fraud is significantly higher in the industry as well.

CISO Forum: Synthetic identity fraud is often described as harder to detect than traditional identity theft because it blends real and fabricated data. In the Indian context — where digital public infrastructure like Aadhaar and mobile-based verification is widespread what gaps are fraudsters exploiting to construct synthetic identities?

Anurag Anand: When we talk about synthetic identity fraud, the key sign is that each data set looks good on its own. But when you stitch it together, you see the person linked to that Aadhaar, the person linked to that phone, and the person linked to that email; none of those identities matches. That is the typical problem of synthetic identity fraud. In India, Aadhaar and mobile-based verification are commonplace, especially for banking and related use cases. This report tries to identify this fraud across the board.

Aadhaar remains a strong verification mechanism in the banking and financial ecosystem, but outside it, adoption of Aadhaar-based authentication is very limited. Across the board, there are still chances, or there are still white spaces where this fraud is thriving very extensively. Secondly, Aadhaar alone confirms a person’s ID. But the other fragments of information that the customer submits, for example, the mobile number, might or might not be changing. In some cases, we have also seen that, specifically where there is an identity account takeover of some nature, specifically for specific Aadhaar IDs, the phone number has also been changed. Then mobile number verification or Aadhaar verification has taken place.

In many of these cases, we also have victims, I would like to call them, who deliberately give out their Aadhaar card, or there has been some other kind of mobile account takeover- identity takeover that has happened. And then these kinds of frauds are happening. So there are a lot of cases around those angles as well, outside of Aadhaar verification, that typically prompt these kinds of use cases.

Anurag Anand
Head of Fraud Solutions
TransUnion INDAS

Natarajan Ramani: Earlier, people forged bank statements to show a salary credit of 25,000 when the credit was only 5,000. They would add a 2 in front of it. Today, fraudsters have evolved, given the rightful government and RBI interventions, account aggregation, and the public digital infrastructure helping banks to a large extent. But today, one of the big use cases of synthetic fraud is setup fraud. An artificial company is formed. That company will have 10 employees; each employee will get a genuine salary credit in their account coming from the company. But what’s happening is the salary account is getting routed across these 10 people. So everything is fine. The Aadhaar is perfect. The phone number is perfect. The KYC is perfect. But this is a different sort of synthetic that’s being generated. This is also evolving a lot.

CISO Forum: The report notes that India’s account-creation fraud rate (3.1%) is below global levels, which TransUnion attributes to widespread mobile-number verification. Does this mean synthetic identity risk in India is more concentrated at other lifecycle stages such as login or financial transactions, and if so, why?


Anurag Anand: When we talk about account takeover, and you say synthetic identity is 1 vector of it, it also applies very specifically to account login. Use cases of social engineering fraud where I, using your identity, can log into your account, or reset the password by taking fragments of data from Jagriti or Natarajan, and so on. That is still a pertinent problem in India. The awareness, the education, all of that is.

A little trickier is account creation, whereas most banks have safeguards around that; so, account verification, or account login by resetting the password using someone else’s credentials, also needs to go through the same level of checks.
Because it’s a verified account, if someone gets into it, whatever store of value is there can be lost immediately.

CISO Forum: Beyond the general threat of deepfakes bypassing liveness checks, what’s the most sophisticated AI-enabled fraud technique TU INDAS has observed being deployed against Indian banks or fintechs in the past year?


Natarajan Ramani: One solution does not replace another in fraud. We need a layered approach. Different systems, different parameters, and different forms are needed to identify and triangulate fraud. One of the biggest examples, one of the biggest use cases in fraud, and one of the biggest hurdles we face is a concept called false positives.

Now, there is always customer inconvenience. One business team wants customers to go through, and another fraud risk team wants to prevent fraud. How do you get the right balance? You get the right balance only when you build a detailed, layered mechanism to identify fraud. In terms of what’s happening in the industry, from an India perspective, suspected fraud at account login has almost reached 3.9%, compared to 3.1% in account creation. Overall, a layered approach will help with this. And that’s how we feel institutions are moving towards and garnering.


Anurag Anand: Earlier, you might have heard about the Nigerian scam and so on, where an email used to pop up and people gullible enough were attacked. Nowadays, the rate of creation of these kinds of websites or contents or emailers that look like they are actually originating from a top tier bank, let’s say like an ICICI or a HDFC bank and so on, it’s so very difficult to believe that it is not coming in. You have to be really conscious, you have to be really educated, you have to be really aware to know that this is a fake visa-vis or genuine emailer or a website. A lot of social engineering-led scams where the origin is AI-generated content impersonation in general also seem to be getting into the industry. And the attack vectors are so broad. It’s difficult for anyone, or any single institution, to build a knowledge base around that. Okay, so that is also something that we have seen in the ecosystem.

CISO Forum: How is TU INDAS operationalising AI on the defence side? Specifically, what does “responsible AI” mean in fraud detection when false positives can lock legitimate customers out of essential financial services?

Natarajan Ramani: Responsible AI would mean different things to different enterprises, and even for us, but generally I can answer this right. Responsible AI means that the right customer is not getting impacted and the fraudulent customer is identified properly. That is responsible AI in terms of our understanding, our relief. Because what does it help banks or any financial institution?  A bank wants to improve its capability to make decisions correctly and improve decision quality.

So, not increasing, for example, or not increasing detection rate, because increasing detection rates will also come with high false positives. And when you have high false positives, rightful customers, from a customer-convenience perspective, go through much more stringent checks.

Responsible AI is about improving decision quality for fraudulent transactions and, from a customer perspective, too. Now, in terms of what the organisation is doing to operationalise AI on the defence side, we feel AI is at the crux of everything we do. For example, many of our solutions now capture multiple aspects of behavioural data sets and device data sets.

It’s triangulated information that helps us stay ahead of what’s happening there. Because as I said, it’s a layered approach. We have to keep on improving.
What we do today won’t remain in vogue next year. Next year, when we come out, we’ll have to improve even more because fraudsters keep changing the game in near real time. And that’s why enterprises like us also have to keep evolving. Anurag.

Anurag  Anand: I’ll talk about some specific examples from the product side as well. We have a couple of product sets where we get data sets on what is fraud, what is non-fraud, and so on.


When we look at AI/machine learning models, we try to err on the side of caution; we don’t want to inconvenience any rightful customers. In fact, so much so that our default recommendation in many of those cases is.


Please put this in a review bucket rather than declining the customers outright. Okay, so review could be handled in any of the other manners. It could be a branch review, an OTP-based review, or a secret question password. Again, it depends on what the bank wants to do. But those are the most common ways we allow reauthentication rather than outright declining service, given India as an example.

CISO Forum: The report identifies logistics as India’s highest-risk digital fraud sector at 16.3%, ahead of telecom, insurance and even gaming. That’s a departure from the global pattern, where video gaming leads. What’s driving fraudsters toward logistics in India, and what should logistics and ecommerce players do differently?

Anurag Anand: Of all the names that were there, Telco, BFSI, and Insurance are heavily regulated industries. Okay. So, the prevalence of guidelines, the order, and the checks and balances put in place by the regulator are very stringent. And obviously, that affects the numbers as well, and so on. Logistics as a whole is a much more diversified industry. If you’re talking about players like Shiprocket coming into delivery, you also have players like Uber, Ola, and Rapido coming into that entire space. It’s much wider, and fraud happens in multiple cases. I’m sure you’ve had use cases where you booked an Ola and got a different vehicle.
You got a different driver; you were asked to pay in a different mode of payment than the use case. So, this is the kind of fraud happening in the industry. Obviously, the volume is very large, but the percentage point, so the blips in the overall ecosystem by hit would be small.

Okay, so if $100 gets lost in a BFSI fraud, the loss in a logistics fraud might be $5 or $10, just for reference. That’s why, but overall the percentage point or the volume is quite large. What can be done in this particular case? Yes, most institutions are trying to work through that—a single solution that looks at identity —because they’re all trust-based institutions.

Whenever you’re booking an e-commerce delivery or whenever you are booking across a ride-sharing app. All of those are based on trust factors. Okay, you expect someone to turn up whose photograph, whose details you have. Okay, so again, identity verification, driver-to-vehicle mapping, and identity mapping- all of those are crucial factors that, if the players are looking to reinstate trust in this entire ecosystem, they will have to start on. Without a stringent regulator, the timing depends on individual organisations, which will likely happen in due course.


Natarajan Ramani
One of our understandings is that the logistics sector has multiple touchpoints. Wherever there is a human touchpoint or a human involved, there is a chance of fraud happening in whatever form and fashion.

Today, in logistics, there is a delivery, an engagement, and a courier call. And today, all of us, at some point, have got a fake SMS saying your blue dot parcel is stuck. Why don’t you call, and why don’t you click on this link? So wherever it links directly to a person, that’s where something will happen.

And there, I would say it’s not only about the fraud solution; but it is also about how you bring back trust to the consumer when they are engaging with a logistics partner, right? So that also becomes very, very important because as long as the consumer trusts who they’re dealing with, fraud will go down by default, and everything else they deal with is a non-trusted source. A mix of fraud and communication solutions will also help significantly in addressing this segment.

CISO Forum: Can you walk us through how TransUnion INDAS’ fraud and identity solutions are architected? Specifically, how do device intelligence, behavioural signals and consortium data work together to flag identity-based fraud before it results in loss?

Anurag: Anand: When we look at identity, there is a physical identity of who you are, what you are represented through an Aadhaar database or PAN database or any of those ID documents in general; what’s your age and gender?
Banks and financial institutions look at this very specifically because it is the equivalent of meeting a person, knowing who they are, and registering that for any banking transaction. We also strongly believe there is a need for digital identity as well.

For example, you would use your mobile phone, a laptop, or possibly a tablet to access the external world, log into your bank accounts, and log into your insurance accounts; that device is your digital identity for that particular ecosystem. If they are automatically seeing you from this particular laptop, the chances are slim that someone is trying to impersonate Jagriti and take over the account. That is something we strongly believe in and operate on. A similar kind of behaviour pattern we also try to look at. These kinds of infrastructural themes. What is a typical IP that you’re logging in from? If you are logging in from an IP based in India, chances are it is Jagriti. But the same laptop may be registering this transaction from North Korea. Styling it as probable that someone is travelling to North Korea might require a second factor of authentication to verify, validate, and so on. Third point, again on the digital identity framework itself: we are also talking about things like what intelligence is available on the phone number.

The phone number is the gateway to all kinds of financial services access in India. If your phone number is tampered with, everything related to UPI payments, banking logins, insurance logins, mutual funds, all of that becomes a risk. So we also look at the riskiness of particular phone numbers across the board. If a SIM swap happened recently, or a device swap happened recently, all of these become threat factors for any bank or financial institution when they deal with you. So these are some of the digital identity rails that can’t be impersonated. These are infrastructure-level things: device, IP, phone; you cannot replicate them, the behaviour pattern just like that.


AI can’t come in and change the entire signature just like that. Okay, so that is what we try to identify and flag. These are the various layers. Again, I’m reiterating this, but it’s crucial to this entire theme. Identity detection for fraud prevention is a layered approach. We have various layers around that. Yeah, physical identity might be one of them, but digital identity also has layers that are becoming increasingly significant over time.

Natarajan Ramani: From a consortium perspective, it becomes very important that a fraudster who’s done fraud in one set of a company or in one set of a sector,
If he comes back into the ecosystem through some other means, the other enterprise can identify him. So we are a strong proponent of the consortium aspect, and we have seen it work brilliantly in all the markets where TU is present. And that’s what we’re trying to do in India as well.

CISO Forum: With 59% of Indian consumers reporting being targeted by fraud in the last few months and phishing remaining the top scheme, how much of India’s fraud problem is a technology gap versus a consumer awareness and financial literacy gap?


Natarajan Ramani: We can’t pick one against the other. Both go hand in hand. The technology gap does exist, with a lot of improvised solutions, but the government and the RBI have done a lot in the right frame and the right way, at least in the banking and financial services space.


But as Anurag was mentioning, in the non-regulated space, like the logistics department, there’s still a lot to do from that perspective. There is obviously a gap there, but consumer evidence also goes hand in hand. We cannot solve fraud, for example, today; you look at every organisation, and they run ads that say, “Hey, please don’t share your OTP with anyone else”. And still you have OTP fraud. Still you have all these cyber attacks, or still you have digital arrests, for example. Until then, broad-based consumer awareness and literacy are done by
all enterprises. I would not say one. It has to be the government, it has to be a regulator, it has to be the enterprises. That would be an important part of solving this more holistically. Technology can only solve to a certain extent, but literacy and consumer awareness will only help justify what we are doing. The crux remains the same. How do enterprises have trust in dealing with consumers, and how do consumers have trust in dealing with enterprises? If you can solve for both, I think we have achieved a lot in the fraud space.

CISO Forum: Looking beyond the sectors already flagged in the report, which parts of India’s digital economy do you see as the next frontier for AI-enabled fraud, such as UPI-linked services, buy-now-pay-later or embedded finance, and why are they currently under-defended?


Anurag Anand: Fraud will be prevalent across all of these spaces. But we feel account origination is where cutting even 5-10% of fraud has much larger ramifications across the entire ecosystem. That’s what we feel. And what we see is that any new kind of account origination might be buy now, pay later, any embedded finance we offer, embedded insurance, and so on. Account origination will still play the biggest role.

We have, and this is also based on the fact that when we talk about UPI link services, UPI payments, and so on in general, those frauds are very much in the fore. There is a lot of good work being done by the government, by NPCI, but
by private players as well in building fraud detection and so on services. It’s about a catch-up game to get over there. But I still feel that in the other areas of fraud, there is much more exploration that needs to be done. It needs to come to the fore, and we need to tackle those problems at the outset.

Natarajan Ramani: Most UPI fraud today happens because of an OTP share. Otherwise, there’s no way you can have a new UPI kind of an element because it’s so integrated into the infrastructure, right? And attached to your mobile, attached to…
Now, obviously, NPCI has done multiple things. Right now, India was not the first country to start two-factor authentication, right? Many years ago, right? No one had thought about two-factor authentication either, right? And now you have two-factor authentication; you have a lot of other stuff that keeps coming in.

Hand on heart, we really don’t know how this will change. We don’t know what new fraudsters are going to think through because, with AI- and a lot of your questions were on AI- AI enables fraudsters to think even more out-of-the-box, which we can’t even think of right now. And with AI, it can come from the same device or from the same person. You can have multiple AI attacks together at the same point in time. So what happens is 100 activities happen, maybe one click. A fraudster makes money from it. Today we don’t know how this is, but AI is enabling a lot of system-level attacks that can be done in a fraction of a second now.

CISO Forum: If you had to prioritise one investment for Indian financial institutions and digital platforms over the next 12 months to stay ahead of AI-powered fraud, what would it be? What is the cost of inaction?


Anurag Anand: This is something we have been calling out in our discussions. Identity risk assessment, or the identity-centred risk assessment at the outset, at the account origination point, is the most crucial. Gone are the days when you only looked at physical identity. It has reached a maturity point as well. You need to look at newer dimensions of risk threat; that’s where our entire concept of digital identity, the infrastructure over which you are doing business, all of that is coming into picture. Our recommendation is to stop doing this in daily batches and so on. Make sure it is completely ingrained and fully real-time, so you know the pace of fraud in India, which is unheard of in the industry. You can get a loan within 15 minutes, you can get a new account open within 15 minutes, and you can start transacting on all such kinds of accounts or start withdrawing money within the next two hours. This is a reality in India which is still very unheard of in most parts of the world.


Obviously, this poses several challenges, and we are building those safeguards as we go. Having these kinds of safeguards in real time, something that works absolutely when it is required, point in time, would be a priority investment for any of the banks, financial institutions and so on to stay ahead of the curve. Okay, this is required immediately.


Natarajan Ramani: And to end that, I would feel two things. We need greater collaboration between the different entities in the country. It could be across banks, insurance companies, logistics, and all to curtail fraud holistically. We cannot look at it as industry-wide or industry-specific fraud.


The same person can commit fraud in logistics as well as in banks. An industry-wide collaboration is a must to solve it. The RBI and the government have taken good steps. They recently formed IDPIC, which is a good step forward.
But we need more collaboration among enterprises, such as through a consortium. And one thing you also said, Nukuli: customers have to invest in customer education. That’s a must. It cannot happen just by creating defences and care. It has to be customer education as well.

Author