Editorial

Cybersecurity in daily life: When your own voice can be used against you

Last month, a retired school teacher in Guwahati received a call.

Sentinel Digital Desk

Dr. Lakshmi Niwas Kalwar

 

Last month, a retired school teacher in Guwahati received a call. The voice on the other side was crying: “Baba, I have met with an accident in Delhi. Please send Rs. 50,000 immediately to this UPI ID.” The voice was exactly like his son’s. The teacher, in a panic, was about to transfer the money. Fortunately, his daughter-in-law called his son at the same time, and the son was safe in his office in Noida. What the teacher heard was not his son’s voice but a deepfake voice clone created by cybercriminals using just a 10-second clip from his son’s Instagram reel. This is no longer a science fiction movie. This is our daily life in 2026. We have locked our houses with strong doors, but we have left our digital doors wide open. In India, where 850 million people are online and UPI transactions have crossed 18 billion per month, cybersecurity is no longer an IT department’s job. It is every citizen’s survival skill.

The rise of digital scams: The new face of theft

Earlier, a thief had to come to your house. Today, the thief comes through your phone, and you open the door yourself.

According to the Indian Cyber Crime Coordination Centre (I4C), Indians lost over Rs. 11,000 crore to cyber frauds in 2023–24, and the figure for 2025–26 is expected to cross Rs. 22,000 crore. The National Crime Records Bureau says that a cybercrime is reported in India every seven minutes, and in Assam, cybercrime cases have increased by 180% in the last three years. Let us understand the common scams operating across India:

1. The digital arrest scam: You get a call from someone claiming to be from TRAI, the CBI, or the Mumbai Police. They say, “Your Aadhaar has been used for drug trafficking. You are under digital arrest. Stay on a video call and transfer money to prove your innocence.” In 2024, a senior citizen in Guwahati lost Rs. 1.2 crore in such a scam. No agency in India carries out a “digital arrest” on WhatsApp or Skype. The police will never ask you to stay on a video call for hours.

2. The parcel scam: “Your FedEx parcel containing drugs has been seized in Delhi. To avoid arrest, pay customs duty.” This SMS comes with a link. Once you click it, your phone gets infected with malware that reads your OTPs.

3. The UPI AutoPay scam: You want to sell your old sofa on OLX. The buyer says, “I will pay you Rs. 10,000; just accept my Rs. 5 UPI request to verify.” Many citizens think that receiving money requires accepting a request. In reality, accepting a UPI payment request means you are authorising a payment. UPI never requires you to enter your PIN to receive money.

4. The task fraud/work-from-home scam: Telegram messages offer “Earn Rs. 5,000 daily by liking YouTube videos.” Initially, they pay Rs. 150. Then they ask you to invest Rs. 10,000 to get a bigger task. The money disappears. Thousands of college students in Silchar, Dibrugarh, and Guwahati have lost their savings in such scams.

5. The most dangerous new weapon: Deepfake voice cloning

If digital scams steal your money, deepfake voice cloning steals your identity and trust. Earlier, cloning a voice required hours of recording. Now, with AI tools like ElevenLabs, Play.ht, and free open-source models, criminals need just 3 to 10 seconds of your voice. Where do they get it? From your Facebook videos, Instagram reels, YouTube comments, or even a Truecaller voicemail saying, “Hi, I am busy. Please call later.” Once cloned, AI can make your voice say anything in any language—English, Bengali, Assamese, or Hindi—with the same emotion, pauses, and accent. The impact is devastating:

a) The family emergency scam: As in the Silchar case, criminals clone a son’s or daughter’s voice to ask parents for emergency money. Since parents recognise the voice, they do not verify the caller’s identity. In February 2026, the Delhi Police busted a gang in Jharkhand that had cloned the voices of 40 people from Assam and duped their families of Rs. 3.4 crore in just six months.

b) The boss scam: An employee at a Kolkata company received a WhatsApp voice note in his CEO’s voice saying, “I am in a meeting. Urgently transfer Rs. 2 lakh to this vendor.” He did so. The CEO was never in a meeting.

c) The blackmail scam: Using a photo from Facebook, criminals create a deepfake video call in which the victim appears naked or in a compromising position. They then demand a ransom.

Now, the question is: How can an ordinary citizen protect their data? Cybersecurity is not about buying expensive antivirus software. It is about changing daily habits. Just as we teach children to look both ways before crossing the road, we must teach citizens to look twice before clicking.

Here is a practical 10-point Suraksha Kavach for every citizen, especially our elders and young people:

1. Create a family safe word: Every family should have a secret word, such as “Maa-Kamakhya 1962”, that is never shared online. If you get an emergency call in your son’s or daughter’s voice asking for money, ask for the safe word. If the caller cannot tell you the word, it may be a fake. This simple trick has saved many American families and can save ours, too.

2. Follow the 3-second rule for calls: If you get a call saying, “I am in trouble,” immediately disconnect and call back on the original number saved in your phone. Never call back on the number from which the emergency call came. Verify the caller’s identity through another channel, such as a WhatsApp video call or a call to their friend.

3. Lock your digital footprint: Go to your Facebook and Instagram settings and make your voice and video posts visible to “Friends Only”. Remove your phone number from your public bio. On Truecaller, delete your voice-based voicemail and use a simple text message instead. Remember, every reel in which you say “Hello, friends” is raw material for a voice-cloning AI.

4. Never share your OTP, PIN, or screen: No bank, police officer, or government official will ever ask you to share your OTP or UPI PIN or to share your screen through AnyDesk. If someone asks you to do so, it is a fraud attempt. The Reserve Bank of India repeatedly states that it will never call you to ask for your OTP.

5. Use two-factor authentication (2FA) correctly: Activate 2FA on WhatsApp (Settings > Account > Two-step verification), Gmail, and Facebook. Where supported, use an authenticator app like Google Authenticator rather than SMS-based OTPs, because SMS messages can be intercepted through SIM-swapping.

6. The link test: Before clicking any link, press and hold it on your mobile phone to see the full URL. If it says sbi-bank-kyc-update.com instead of onlinesbi.sbi, it is fake. Government links often end with .gov.in. Bank links should be checked carefully against the bank’s official website, as their domain endings can vary. Never trust a link simply because it appears to be official.

7. Freeze your credit information: Most people do not know that they can place restrictions on access to their credit information. If you are not taking a loan, check the options available through CIBIL and Experian. This may help reduce the risk of fraudsters misusing your leaked PAN and Aadhaar details to apply for loans in your name.

8. Update and separate: Always update your phone’s operating system. Older Android phones may be more vulnerable to security threats. Also, consider using separate UPI IDs for different purposes, keeping only a limited balance in the account used for daily transactions and using your main savings account carefully for larger transfers.

9. Report to 1930, not just to the Police Station: The Government of India has established a dedicated helpline, 1930, for reporting cyber financial fraud. You can also report incidents through the website cybercrime.gov.in. If you report the fraud quickly, the authorities may be able to freeze the money in the fraudster’s account. Many people go to the local police station first and lose valuable time. Call 1930 promptly and follow the instructions provided by the authorities.

10. Digital sanskar for children: In our schools, we teach moral science. Now, we must teach digital science, too. Tell children: “Do not share your school’s name, your location, or your daily routine in public reels. Do not accept video calls from unknown numbers. If someone threatens you with a morphed photo, tell your parents immediately and do not pay.”

Conclusion: From digital consumer to digital citizen

We have become great consumers of the digital world, but we have not yet become responsible citizens of it. We put a lock on our almirah, but we keep the same password—123456—for our bank accounts. The fight against deepfakes and scams cannot be won through the police or AI filters alone. It has to be won in our homes, in our drawing rooms, and through our common sense. When our trust runs low because of scams, our awareness must rise. The technology used to clone your voice can also be used to protect you, but only if you are aware of the risks. Let us make a promise today: we will not forward a message without verifying it, we will not transfer money without calling back, and we will not post our entire lives on social media for criminals to exploit. In the digital world, simplicity and honesty are still the best firewalls. A simple habit of verification can save your life’s savings. Stay safe, stay aware, and treat your data as sacred as your home.

 (The author is former Principal, educationist and cyber awareness campaigner in Barak Valley. He is running ‘Digital Suraksha Chaupal’ for senior citizens. Views are personal.)