> Fresh Take > Synthetic Reality Risks: Deepfakes, Voice Cloning, and Brand Vulnerability

Synthetic Reality Risks: Deepfakes, Voice Cloning, and Brand Vulnerability

POSTED BY: Prasad Ramasubramanian 11 August 2026

In 2023, a video swapping actress Rashmika Mandanna’s face onto a British Indian influencer went viral before anyone at any platform had a chance to react. Mandanna called it “extremely scary.” Delhi Police eventually arrested the person behind it, but not before India had its first national conversation about what a deepfake costs a real person’s reputation, and how little Indian law was built to handle it at the time. The IT Rules amendments that followed came out of that single video.

That case involved a celebrity, which is why it made headlines. What’s followed over the last couple of years has been the advent of deepfake endorsements that have targeted the late Ratan Tata, Virat Kohli, and Aamir Khan, public figures whose faces and voices carry exactly the kind of trust that makes an endorsement work. A consumer who sees “Ratan Tata” recommending an investment scheme doesn’t pause to verify. That’s the whole point of using his face.

The financial fraud angle is where this gets genuinely dangerous for corporate India, not just celebrity reputations. In May 2025, a Mumbai finance executive received a video call from what appeared to be their CEO, instructing an urgent transfer of ₹1.5 crore. The real CEO was in a board meeting at the time. This isn’t a one-off; it’s the same playbook behind the $25 million Hong Kong bank fraud in 2024, where an employee joined what looked like a normal video call with senior colleagues and wired funds based on instructions from faces and voices that weren’t real. Roughly 47% of Indian adults report having experienced, or knowing someone who’s experienced, an AI voice scam, according to figures cited in recent cybersecurity reporting. That number should worry any company that still relies on a phone call or a video ping as sufficient authorisation for a wire transfer.

Most PR and communications teams are simply not built for this. Crisis communications playbooks are written around things a company said, did, or failed to prevent: a product recall, a data breach, an executive’s bad tweet. A deepfake crisis is different in kind: the company didn’t do anything, and yet it’s the one that must explain, in real time, that the video isn’t real. That’s a harder message to land than an apology, because you’re asking the public to disbelieve their own eyes and ears, against an algorithm that’s specifically engineered to be convincing. By the time forensic teams confirm a video is synthetic, using cues like unnatural blinking or lighting mismatches between a face and its background, the fake has often already achieved its damage: a dip in stock prices, a run of cancelled bookings, or a fraud transfer that’s already left the account.

India’s legal response is real but still catching up. Sections 66C and 66E of the IT Act cover identity theft and privacy violations, and the Digital Personal Data Protection Act adds another layer, but there’s still no dedicated deepfake statute. The Ministry of Electronics and Information Technology’s November 2023 advisory requires platforms to remove flagged deepfake content within 36 hours, which sounds fast until you remember a fraudulent CEO instruction only needs about ninety seconds on a phone call to trigger a wire transfer. The Indian Cybercrime Coordination Centre has issued hundreds of advisories and named Rashmika Mandanna herself as a cyber safety ambassador; evidence the government sees this as a public awareness problem as much as a legal one.

For companies, the practical response must sit outside the communications department entirely, even though comms will be the one managing the fallout when it happens. That means callback verification protocols for any large wire transfer request that arrives by video or voice, no matter how senior the requester appears to be. It means a pre-built rapid-response process for identifying and reporting a synthetic media attack on the brand or its executives within hours, not days. And it means treating “our CEO’s face and voice could be weaponised against us tomorrow” as a boardroom risk conversation now, before it’s a headline, rather than after.

_______________________________________________________________________________________________________________________

The views and opinions published here belong to the author and do not necessarily reflect the views and opinions of the publisher.

SHARE POST

Prasad Ramasubramanian

Prasad Ramasubramanian is the Senior Manager – PR & Communication at Veranda Learning Solutions, a listed enterprise offering end-to-end solutions in the education space. With over two decades of experience, he is a seasoned communications professional with a strong background in media and corporate communications. Before joining Veranda, Prasad held senior editorial and communication roles at leading organizations such as The Times of India, CyberMedia, and Deccan Chronicle. His expertise spans media strategy, reputation management, and stakeholder engagement across dynamic sectors. At Veranda, he leads strategic communication efforts that enhance brand visibility and reinforce the company’s position as a key player in India’s education landscape.

READ MORE ARTICLES