India’s Financial Fraud Landscape:
What Changed in 2025 & What’s Coming in 2026
₹36,000 crore in banking fraud losses — a 194% surge. We map the forces behind the spike and the five AI-powered tactics that will define fraud in 2026.

I’m Lokesh Chaudhary, Founder and CEO, KYCKART, and I spend my days thinking about one thing: predicting risk. Not the kind that appears overnight, but the kind that’s engineered, tested, and earned.
In an era of accelerated transactions, trust is never an accident. That’s why we created KYCKART Intel— to cut through the noise and deliver the signals that help you stay ahead. I wanted to share how we’re mapping these shifts.
Scale of the Problem
FY 2024-25 — A Year That Changed the Baseline
India’s banking fraud losses surged to ₹36,000 crore in FY 2024-25, a staggering 194% increase from the previous year[1]. While the headline figure is alarming, understanding what changed and why is critical for organisations building resilient fraud prevention strategies.
In FY2025, the game changed. While institutional fraud values skyrocketed, the methods of attacking retail customers became more psychological and more aggressive.

Source: Reserve Bank of India (RBI) & Indian Cyber Crime Coordination Centre (I4C)
Banking Fraud FY25
₹36K Cr
Total fraud losses reported by Indian banks
RBI · Vajra Mandravi [1]
Year-on-Year Surge
+194%
Increase in fraud value compared to the previous fiscal year
RBI Annual Report FY25
Loan & Advances Share
92%
₹33,148 crore — the dominant fraud category by value
RBI · I4C data
The Volume vs. Value Paradox
High-frequency small losses vs. low-frequency giant ones
67% of fraud cases were digital payment frauds, yet they represented less than 2% of total losses[2]. Meanwhile, loan frauds — though fewer in number — involved massive corporate defaults and fund diversions. Private sector banks reported over 14,000 digital fraud incidents, while PSBs faced high-value corporate fraud.
Digital Payment Fraud
67%
of all fraud cases — but only ~2% of total value lost
High volume · Low per-case value
Loan & Advances Fraud
₹33,148 Cr
92% of total fraud value — corporate defaults & fund diversions
Low volume · Enormous per-case value
“Organizations need dual-track monitoring — high-volume retail fraud detection systems AND intensive due diligence for high-value transactions.”
2026 Fraud Tactics
As of January 2026 — AI-powered & hyper-personalized
As we enter 2026, fraud tactics have evolved from generic scams to AI-powered, hyper-personalized attacks. Here are the five vectors defining the threat landscape right now.
“Sleeping” accounts have become the primary vehicle for Money Mules. Fraudsters reactivate long-dormant accounts to launder proceeds, exploiting gaps in re-KYC processes.
Real-time deepfake technology is now a core fraud tool. Fraudsters use AI-generated video and cloned voices to bypass Video KYC checks at onboarding — defeating liveness detection.
Malware disguised as utility apps intercepts OTPs to facilitate Account Takeover. Once inside a super-app ecosystem (UPI, wallet, lending), attackers can drain multiple linked products.
This 2025 phenomenon persists in 2026 with more sophisticated setups — including fake “virtual courtrooms” and forged digital warrants impersonating CBI, ED, and judiciary officials.
Fraudsters now use Generative AI to analyse victims’ social media, purchase history, and digital footprints to create highly personalised lures — moving far beyond generic phishing templates.
Key Insight
Key Insight: Organizations need dual-track monitoring — high-volume retail fraud detection systems AND intensive due diligence for high-value transactions.
The 194% surge in fraud value is not explained by more fraudsters — it’s explained by better-organised, technically sophisticated fraud rings that have industrialised previously manual attack patterns. The playbook has evolved; risk frameworks must follow.
What This Means for Your Risk Stack
- check_circleRe-KYC cadence on dormant accounts must move from periodic to event-triggered.
- check_circleVideo KYC liveness checks need deepfake-detection layers — static liveness is no longer sufficient.
- check_circleATO signals (unusual device, geo, OTP patterns) must feed collections intelligence, not just fraud alerts.
- check_circleDigital arrest and social engineering attacks require customer-education investment alongside technical controls.
“Trust is never an accident. In an era of accelerated transactions, the signal that separates a good customer from a fraud vector is often a millisecond decision — make sure your stack is built for it.”
Frequently Asked Questions
Stay Ahead of the Curve
Predict Fraud Before It Happens
KYCKART’s real-time KYC and fraud intelligence stack gives your risk team the signals they need to act at onboarding — before a dormant account, deepfake, or ATO becomes a write-off.