AI voice-cloning scams in India: what reports say and what to do now
If you are a customer of AI voice-cloning scams in India, here’s what is being claimed, and what it would mean for you.
News outlets and Tamil Nadu police have reported AI-generated voice calls that impersonate relatives and press for instant UPI transfers. No company has confirmed a new 2026 breach or a new survey; the 47% and 69% figures now being shared come from a 2023 McAfee study, according to coverage at the time. Here is what those reports actually mean for an ordinary family, and what is still possible to do.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
According to The Hindu, Tamil Nadu Cyber Crime Police issued an advisory on 27 April 2024 describing scammers who use AI to copy the voices of family members or friends, then place urgent, distressed calls that push people into sending money immediately, often over UPI. No company has confirmed a new 2026 data breach or a fresh study behind the statistics now circulating on blogs and bank awareness posts. Those figures — 47% and 69% — were attributed by Times of India, Mint, Business Standard and others in May 2023 to a McAfee survey of about 1,010 adults in India.
Watch AI voice-cloning scams in India
Get alerted the next time AI voice-cloning scams in India files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AI voice-cloning scams in India’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
As those outlets reported the McAfee findings, 47% of Indian adults said they had faced an AI voice scam themselves or knew someone who had (20% personal, 27% knew someone), compared with a reported global average of 25%; 69% said they did not know or could not tell an AI voice from a real one; McAfee said three seconds of audio can be enough to clone a voice; and 83% of Indian victims in the survey reported losing money, with nearly half of those saying they lost more than ₹50,000. The Hindu and the Economic Times reported in October 2024 that Sunil Bharti Mittal publicly described a “perfectly articulated” AI clone of his own voice used in a call that tried to get an executive to transfer funds. In September 2025, the Indian Express reported a Hyderabad incident in which local cybercrime investigators attributed a ₹1.97 lakh loss to an AI voice-cloning call impersonating a relative.
The part that changes what this means for you
Almost every write-up leads with the technology: a voice copied in seconds, a large percentage of Indians, a warning to hang up. That is what the sources above describe. What it quietly leaves out is the question most people actually have after they see this: was I in this? Is my voice on some stolen list?
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
According to the police account reported by The Hindu, this is not a company leak with a roster of names. There is no list anyone can check. Officers described voice samples coming from social-media videos and posts, or from a short “wrong number” call that got someone talking. If you have ever posted a reel, a story, a voice note, or answered an unknown caller, the raw material those reports describe may already be public. A clean result on any “was I breached?” search would not mean you are in the clear. It would only mean this was never that kind of incident.
The other miss is who gets hurt. Coverage talks as if the person whose voice was copied is the victim. In the cases police and the Indian Express described, the person who loses the money is often the parent, spouse or relative who hears a familiar voice in tears and sends a UPI payment before they have time to think. The clone is the costume. The pressure is the emergency. The lock is that UPI, as these incidents are reported, moves the money at once.
One more honest correction: posts in 2026 that call the 47% and 69% figures a “recent study” are, based on the source trail, recycling McAfee’s April 2023 survey. Tamil Nadu police had already issued a formal advisory in April 2024. The Mittal account was already public in 2024. Nothing in the independent reporting supports the idea that an unnamed new 2026 study suddenly discovered this. The pattern those outlets describe is older than the post that recently framed it as new.
What to actually expect
- You should not expect an email, SMS or bank alert that says your voice was cloned. According to the police description, there is no central notice and no customer list.
- The call, as Tamil Nadu police described it via The Hindu, is built to sound like a sobbing child or relative in an emergency and to demand a transfer in the next few minutes — often UPI — before anyone can double-check.
- Bank and awareness posts you see this year may repeat 47% and 69% as if they were new. According to the 2023 McAfee report and the May 2023 news coverage, those numbers are from that older survey, not a newly completed 2026 study.
- If a payment already went out under panic, the reporting on these cases treats the money as very hard to get back. Police have pointed people to 1930 and cybercrime.gov.in; they have not described a reliable reverse button.
What you can and cannot fix
What cannot be undone: any video, reel or voice note already on the open internet. You cannot recall it from every device that saved a copy. If someone already recorded a short call, you cannot delete their clip. A voice model built from that clip cannot be remotely erased. Money already sent by UPI in one of these panics, as the reported cases describe it, is often gone. There is no official switch that marks your voice as “do not clone.”
What actually helps, in order:
- Talk to the people who would pay if they thought you were in trouble — today, before any call. Agree that you will never ask them to send money from a ringing phone, even if it sounds exactly like you. Pick a simple code word that only you share. This is the step that matches how the reported scams actually work.
- If a panicked call comes, hang up and call back on a number you already have saved. That is the specific advice Tamil Nadu police gave, as quoted in The Hindu. Do not use a number the caller reads out. Do not stay on the line to “hear more.”
- Shrink the public mix of your voice plus your family tree. A short clip becomes much more useful to a scammer when it can be joined to people-search pages and social profiles that list relatives, phone numbers, employers and old addresses. Those extra listings, unlike a video that has already been copied, can often actually be removed or limited. That is why tightening tagged family photos, public relative lists and people-search profiles is worth doing even though you cannot unsay an old reel.
- Treat a long chat with an unknown number as a possible voice sample, not only a nuisance. Police, according to The Hindu, said preliminary calls are one way samples are gathered. Keep those calls short. Report attempted scams to 1930 or cybercrime.gov.in.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…