- Home
- Case Studies
- Capillary Tech Loses €3 Million in Deepfake Banking Fraud
Capillary Tech Loses €3 Million in Deepfake Banking Fraud
Capillary Technologies, a Bengaluru-based SaaS company, lost approximately €3 million after fraudsters used deepfake voice cloning, forged signatures, and social engineering to impersonate key managerial personnel at a recently acquired overseas subsidiary. The attackers successfully authorized fraudulent fund transfers to unauthorized third-party bank accounts. 45 million so far and is cooperating with law enforcement to freeze additional accounts.
By Jesse Seaver, Co-Founder, Trust Onion
Published August 26, 2026
Drafted with AI assistance from published news reporting and reviewed before publishing · Our editorial standards
Originally reported by Moneycontrol · Read the original article
Part of our Voice Cloning Scams topic guide.
Analysis of This Incident
€3 Million Gone: How Deepfakes Fooled a Company's Own Bank →Timeline of Events
The Setup
Capillary Technologies had recently completed the acquisition of an overseas step-down subsidiary. Staff at the new unit were still establishing trusted communication channels with leadership and learning to recognize unfamiliar voices and authority figures, which created the opening the attackers needed.
The Attack
Attackers used deepfake voice cloning alongside forged signatures and social engineering to impersonate key managerial personnel at the overseas subsidiary, issuing instructions to transfer funds to unauthorized third-party bank accounts.
The Impact
Approximately €3 million (₹32.7 crore) moved out of the overseas subsidiary's accounts to unauthorized third parties before the fraud was detected.
The Discovery
Capillary Technologies detected the fraud and disclosed it, then engaged law enforcement, cybercrime authorities, and banking institutions to investigate and begin recovery efforts.
The Fallout
Capillary Technologies recovered €0.45 million of the stolen funds. The company continues working with cybercrime authorities and banks to freeze additional accounts and recover the remaining approximately €2.55 million.
Attack Details
Attackers targeted a recently acquired overseas step-down subsidiary of Capillary Technologies, a Bengaluru-based SaaS company. The timing was deliberate. Post-acquisition integration periods are especially vulnerable because employees at newly acquired units are still learning who the real authority figures are, what they sound like, and how they communicate. That uncertainty gave the fraudsters their opening.
The attack combined multiple deception techniques. Fraudsters used AI-generated voice cloning to impersonate key managerial personnel over the phone, lending the fraudulent instructions the vocal familiarity of a real executive. Alongside the cloned voice, they produced forged signatures, adding a document layer that reinforced the appearance of legitimate banking instructions.
Social engineering completed the picture. The attackers knew enough about the company's structure, personnel, and communication patterns to make the scenario feel routine rather than alarming. Staff at the overseas unit received what appeared to be authorized instructions from leadership they recognized by voice and by name, directing them to transfer funds to what turned out to be unauthorized third-party accounts.
Because voice cloning, forged documents, and social engineering each reinforced the others, no single verification failure caused the breach. Each fraudulent element reduced the chance that any one person would stop and question the instructions they were receiving.
How Trust Onion Helps
Our analysis — prevention guidance, not part of the reported facts
When a caller claims to be a company executive and instructs staff to move funds, a single question, "What are the words?", immediately separates a real executive from an AI-generated voice. The real executive knows the current three codewords. A fraudster with a cloned voice does not, and cannot find out. No cloned voice, no forged document, and no amount of social engineering can produce the correct answer.
In a post-acquisition environment like the one Capillary Technologies was navigating, employees at the overseas subsidiary were still familiarizing themselves with leadership. That is precisely the context where voice cloning is hardest to detect and codeword verification is most valuable. If the subsidiary had established a shared codeword system with group leadership before the attack, any instruction to move funds would have required the caller to prove identity with the current words. The fraudsters would have been exposed on the first call.
Trust Onion's three rotating codewords are calculated locally on each authorized device. There is no server to hack, no database to breach, and no way for an attacker to intercept the current words. The words change every few hours, so even if a fraudster somehow learned them, that information would expire quickly. A codeword challenge costs nothing, takes seconds, and stops this attack before a single euro moves.
Impact Assessment
The direct financial loss totaled approximately €3 million, equivalent to roughly ₹32.7 crore, taken from accounts held by Capillary Technologies' overseas subsidiary. Of that amount, €0.45 million has been recovered through coordination with banks and law enforcement, leaving an outstanding loss of approximately €2.55 million at the time of disclosure.
Beyond the direct monetary loss, the incident triggered significant operational disruption. Capillary Technologies had to engage law enforcement agencies, cybercrime authorities, and multiple banking institutions across jurisdictions to freeze accounts and begin recovery proceedings, consuming management attention, legal resources, and time that would otherwise support normal business operations.
The public disclosure, while necessary and responsible, places the incident in the permanent record and raises questions about internal controls, verification protocols at acquired entities, and the company's readiness to defend against AI-generated fraud.
Lessons Learned
Newly acquired subsidiaries are high-value targets during integration periods when employees are still learning to recognize and trust unfamiliar leadership voices.
AI voice cloning combined with forged documents and social engineering creates a layered deception that is difficult to detect without a pre-established verification protocol.
Any process that authorizes fund transfers over the phone needs a challenge-based identity step that cannot be satisfied by a cloned voice or a forged signature.
Key Takeaways
Capillary Technologies lost €3 million (₹32.7 crore) in a deepfake voice cloning attack targeting a recently acquired overseas subsidiary.
Attackers combined AI voice cloning, forged signatures, and social engineering to impersonate executives and authorize fraudulent wire transfers.
Only €0.45 million of the €3 million stolen has been recovered despite coordination with law enforcement, cybercrime authorities, and banks.
Post-acquisition integration periods are a documented vulnerability window for executive impersonation attacks.
A codeword verification protocol applied before any fund transfer authorization would have exposed the cloned voice before the money moved.
Frequently Asked Questions
What happened in the Capillary Technologies deepfake fraud incident?
Fraudsters used AI-generated voice cloning, forged signatures, and social engineering to impersonate key managerial personnel at a recently acquired overseas subsidiary of Capillary Technologies. Staff were deceived into authorizing fund transfers totaling approximately €3 million to unauthorized third-party bank accounts.
How much money did Capillary Technologies lose?
Capillary Technologies lost approximately €3 million, equivalent to roughly ₹32.7 crore. As of the time of disclosure, €0.45 million had been recovered, leaving an outstanding loss of approximately €2.55 million.
How could this deepfake banking fraud have been prevented?
A codeword verification protocol would have stopped this attack before any funds moved. If staff at the overseas subsidiary were required to ask any caller authorizing a fund transfer, "What are the words?", the AI-generated voice impersonating an executive could not have provided the correct answer. Trust Onion's three rotating codewords are shared only among verified team members, change every few hours, and are calculated locally with no server to hack. The fraudster would have been exposed on the first call.
Why was the overseas subsidiary especially vulnerable?
The subsidiary had been recently acquired, placing it in an integration period where employees were still learning to recognize the voices and communication styles of new leadership. Fraudsters exploited this familiarity gap, knowing that staff would be less confident questioning instructions from executives they had not yet worked with directly.
What methods did the attackers use beyond voice cloning?
In addition to AI voice cloning, attackers used forged signatures to add documentary legitimacy to their fraudulent instructions, and applied social engineering to make the overall scenario feel routine and authorized. The combination of all three methods made the fraud harder to detect than any single method alone would have been.
More case studies
AI-Powered Farm Equipment Scams Target Georgia Farmers
The Georgia Department of Agriculture issued a warning in July 2026 about AI-assisted scams targeting farmers searching ...
AI-Powered 'Hi Mum' Scam Targets Australian Families
Australian scammers have added AI voice cloning and message impersonation to the long-running 'Hi Mum' text scam, making...
Houston Man Loses $15,000 After AI Clones His Son's Voice
Charles Lafkoff, a 71-year-old Houston resident, lost $15,000 after scammers used AI voice cloning to impersonate his so...
