I4C Warns of AI Deepfakes Being Used to Bypass Facial and Biometric Authentication
The Indian Cybercrime Coordination Centre (I4C), operating under the Ministry of Home Affairs (MHA), has issued an advisory warning individuals, banks, and fintech firms about the escalating threat of AI-generated deepfakes being used to bypass biometric and facial authentication systems.
Cybercriminals obtain facial recordings through deceptive video calls, fake online job interviews, and social engineering — tricking victims into blinking, turning their head, or speaking specific phrases, which are then processed using AI-powered deepfake generation tools.
These synthetic facial replicas can bypass liveness detection, Video-KYC (Know Your Customer) procedures, and facial recognition authentication used by digital financial platforms.
I4C has advised consumers to lock biometric credentials, avoid sharing facial recordings with unknown parties, and monitor account activity closely.
Banks, NBFCs, and fintech companies are advised to incorporate deepfake and synthetic content detection into their customer onboarding and verification systems.
Indian Cybercrime Coordination Centre (I4C): Structure and Mandate
The Indian Cybercrime Coordination Centre (I4C) was established in 2018 as a scheme under the Ministry of Home Affairs (MHA) to create a comprehensive, coordinated framework for prevention, detection, investigation, and prosecution of cybercrime. It was designated as an Attached Office of MHA with effect from 1 July 2024. I4C does not directly investigate crimes but provides the coordination architecture for law enforcement agencies across states.
I4C's deepfake advisory is precisely within its mandate — it is the coordinating body for all financial cybercrime, and AI-driven authentication bypass directly threatens digital financial infrastructure.
Deepfakes: Technology, Legal Framework, and Regulatory Response
A deepfake is AI-generated synthetic media — video, audio, or images — that realistically replicates a real person's appearance, voice, or behavior using techniques like Generative Adversarial Networks (GANs) and diffusion models. In authentication bypass, deepfakes are used to fool liveness detection algorithms (which check for blinking, head movement, lip sync) used in Video-KYC and facial recognition systems.
The I4C advisory specifically calls out deepfakes defeating liveness detection in Video-KYC — the exact intersection of IT Act provisions (66C/66D), RBI's V-CIP guidelines, and AI governance gaps.
Biometric Authentication and Liveness Detection Systems
Biometric authentication uses unique physiological or behavioral characteristics — fingerprints, iris patterns, facial geometry, voice — to verify identity. In digital KYC, liveness detection is a critical anti-spoofing layer that checks whether the biometric being presented is from a live person (not a photo, video replay, or deepfake). Modern liveness detection requires active challenges (blink, turn head, speak a phrase) — exactly the behaviors fraudsters are now harvesting through social engineering.
Key Details
- India's Aadhaar-based biometric authentication (managed by UIDAI) uses fingerprint and iris — less vulnerable to deepfake video attacks, but facial-recognition based systems (private sector) are directly targeted.
- RBI's Video-KYC (V-CIP) guidelines require a live video interaction with a bank officer — deepfake injection attacks target the video feed in this interaction.
- The Payments Vision 2025 (RBI) and Digital India initiative drive rapid expansion of digital onboarding — increasing the scale of potential exposure to authentication fraud.
- The NCRB (National Crime Records Bureau) tracks cybercrime statistics annually; cybercrime cases have grown substantially year-on-year, with financial fraud being the dominant category.
As deepfake quality improves, the gap between attack capability and liveness detection capability widens — the I4C advisory is a recognition that current biometric onboarding systems require urgent upgradation.
- I4C established: 2018 (as MHA scheme); Attached Office of MHA from 1 July 2024
- I4C Helpline: 1930 (Citizen Financial Cyber Fraud Reporting)
- Cybercrime portal: cybercrime.gov.in (National Cybercrime Reporting Portal)
- CERT-In: Under MeitY; established 2004 under IT Act Section 70B; handles cyber security incidents
- IT Act Section 66C: Identity theft (imprisonment up to 3 years + fine)
- IT Act Section 66D: Cheating by personation using computer resources (imprisonment up to 3 years + fine up to ₹1 lakh)
- IT Rules 2021 (Intermediary Guidelines): Deepfake/synthetic content takedown within 24–72 hours of complaint
- Deepfake technology: GAN-based and diffusion-model-based synthetic media; capable of bypassing liveness detection checks
- Attack vectors identified by I4C: Fake job interviews, deceptive video calls, social engineering to harvest facial recordings
- Systems targeted: Video-KYC (V-CIP), facial authentication, account recovery mechanisms
- RBI V-CIP: Video-based Customer Identification Process — mandatory for digital financial product onboarding
- NCRB: National Crime Records Bureau — tracks cybercrime statistics; financial fraud is dominant subcategory