CERT-In directions require specified cyber incidents to be reported within six hours of noticing them or being brought to notice. Financial entities may also have RBI, SEBI, insurance or sector-specific incident and fraud reporting duties. The exact event, clock, regulator and reporting format must be assessed immediately; internal investigation should not delay urgent containment.
Deepfake fraud usually combines impersonation with urgency, secrecy and a payment exception. The technology is new, but the control failures are familiar: weak callbacks, shared credentials, overridden approval limits and unverified bank changes.
Vendor master changes should be verified using independently held contact details, not the number in the change request. High-risk payments should have cooling periods or secondary confirmation.
Preserve email headers, call logs, device details, payment trails and CCTV or access records. Evidence can disappear when accounts or devices are wiped.
| Issue | Current position | Why it matters |
|---|---|---|
| CERT-In clock | Specified incidents within six hours | From noticing or being informed |
| Control principle | Out-of-band verification | Voice or video alone is not authority |
| Payment design | Maker–checker plus transaction limits | No single-channel override |
A finance manager receives a video call that appears to show the CEO ordering a confidential ₹75 lakh acquisition payment. The request uses a new beneficiary and bypasses procurement. The correct response is to pause, call the CEO through an independently stored number, verify the board or deal record and require the normal second approver. Urgency is a risk signal, not an approval.
Contact the bank immediately to freeze or recall funds, report cyber financial fraud through 1930 and the official cybercrime portal, and assess CERT-In and sector-regulator reporting. Preserve evidence and involve legal, IT, finance and law enforcement together.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
The prior page did not embed a page-specific external source. The category authority above is the minimum verification starting point; a specific instrument should be added during the next substantive editorial review.