Cybersecurity 2026

INDIA Trends and Developments Contributed by: Amit Jaju and Amol Pitale, Ankura Consulting Group, LLC

From Deception to Accountability – India’s Cyber Paradigm Shifts in 2026 Introduction The Indian cybersecurity landscape has undergone a fundamental transformation in 2025–2026, mark - ing the transition from awareness to accountability. The activation of the Data Protection Board of India in late 2025 and the enforcement of the Digital Personal Data Protection (DPDP) Act have elevated cyberse - curity from an IT function to a boardroom governance imperative. This shift arrives at a critical juncture: India is simultaneously experiencing unprecedented cyber threats from AI-powered deepfake fraud costing the nation an estimated INR70,000 crore (1 crore equals 10 million) in 2025, and co-ordinated attacks on criti - cal infrastructure driven by geopolitical tensions. The convergence of regulatory enforcement, advanced threats, and India’s status as the second-most target - ed nation for email-based attacks globally creates an urgent mandate for organisations to shift from reactive defence to forensic readiness and systemic resilience. Trend one – the deepfake epidemic – financial fraud at scale Deepfake-enabled fraud has emerged as the most disruptive cybersecurity challenge in India’s digital economy. According to research by pi-labs, deepfake- related cybercrime cases have grown by 550% since 2019, with projected losses reaching INR70,000 crore in 2025 alone. This explosion is not merely technical – it reflects a weaponisation of generative AI tools to industrialise fraud at unprecedented scale and speed. The mechanics of deepfake attacks in India have evolved significantly. The term “Jamtara 2.0” now describes a new category of fraud where sophisticat - ed deepfake technology is deployed to manipulate video KYC (know-your-customer) processes, imper - sonate corporate executives, and create fabricated digital evidence for extortion. With over INK11 lakhs (1 lakh equals 100,000) video KYC calls conducted daily in India, this vulnerability creates a massive attack sur - face. A high-profile case illustrates the stakes: an Indi - an industrialist was defrauded of INR7 crore through a fake Supreme Court hearing orchestrated entirely using deepfake technology.

The financial impact extends beyond individual cas - es. Global research reveals that 55% of organisations experienced deepfake-related fraud losses in the past year, with an average loss per incident of USD280,000. In India, the targeting is sector-specific and relentless: • finance and BFSI institutions face video deepfakes impersonating senior executives to authorise unau - thorised fund transfers; • manufacturing and export companies encounter voice cloning attacks mimicking C-suite approval for wire transfers; • healthcare providers confront identity theft through forged provider credentials; and • government agencies experience “digital arrest” scams where deepfake video impersonates CBI or police officers, coercing victims into financial transfers. A particularly alarming development is the rise of real- time deepfake attacks, where manipulation occurs during live video calls – a frontier that traditional veri - fication methods cannot counter. Nearly 65% of deep - fake incidents in India remain unreported, leaving a massive enforcement and mitigation gap. Trend two – DPDP Act enforcement – from grace period to penalties The landscape for data protection in India shifted decisively when the Data Protection Board of India became operational in late 2025. The grace period for theoretical compliance has ended, and 2026 marks the beginning of active enforcement with serious financial consequences. Organisations can no longer rely on compliance theatre; the regulator is now focused on demonstrable, verifiable and auditable data protection practices. The penalty structure under the DPDP Act is unprece - dented in Indian business regulation. Maximum penal - ties can reach INR250 crore per violation for failure to implement reasonable security safeguards that result in a personal data breach. Significant Data Fiduciar - ies – entities identified based on data volume, risk to individuals, use of new technologies, or impact on national interest – face penalties up to INR150 crore for non-compliance with enhanced obligations. Failure to notify the Data Protection Board and affected indi -

207 CHAMBERS.COM

Powered by