Deepfake of Prime Minister Narendra Modi Surfaces

Deepfake of Prime Minister Narendra Modi Surfaces

In July 2025, Athenian Tech (AT) identified a coordinated AI generated deepfake campaign of Prime Minister Narendra Modi, which showed him promoting a fraudulent online investment platform which was circulated on Facebook. The manipulated video falsely portrayed the PM Modi endorsing an automated wealth‑generation scheme, while additional synthetic assets misused the identities of senior public figures, including Nirmala Sitharaman, Narayana Murthy, and Sudha Murty, to create a further perception of legitimacy. Paid advertisements amplified the operation, directing users to scam websites hosted on .top domains that harvested personal and financial information before funnelling victims into organised investment‑fraud networks.

In July 2025, Athenian Tech (AT) identified a coordinated AI generated deepfake campaign of Prime Minister Narendra Modi, which showed him promoting a fraudulent online investment platform which was circulated on Facebook. The manipulated video falsely portrayed the PM Modi endorsing an automated wealth‑generation scheme, while additional synthetic assets misused the identities of senior public figures, including Nirmala Sitharaman, Narayana Murthy, and Sudha Murty, to create a further perception of legitimacy. Paid advertisements amplified the operation, directing users to scam websites hosted on .top domains that harvested personal and financial information before funnelling victims into organised investment‑fraud networks.

AT’s threat‑intelligence platform, Prime, detected the campaign through continuous monitoring of the Dark Web, Deep Web, Surface Web, Telegram channels and paid-social-media ad inventories. Prime identified the deepfake source assets, traced associated syndicate accounts, and mapped TTP patterns linking the operation to Southeast Asian fraud groups specialising in deepfake‑enabled investment scams. AT’s analysis produced evidence packages that supported rapid takedown requests, platform‑level escalations, and regulatory notifications.

Impact

AT’s reporting directly contributed to the removal of fraudulent domains and Facebook ad assets, enabling coordinated action between law enforcement agencies and regulatory bodies. The case highlighted the growing national‑security implications of AI‑generated impersonation campaigns and reinforced the need for stronger public‑awareness and digital‑literacy initiatives to counter deepfake‑driven financial fraud.

Share

Related Case Studies

Deepfake of Narayan Murthy SurfacesDeepfake
CASE STUDY01 August 2025

Deepfake of Narayan Murthy Surfaces

In August 2025 a coordinated financial fraud campaign which leveraged AI-generated deepfake technology to impersonate Infosys Founder Narayana Murthy, falsely portraying him as endorsing a fictitious government-backed investment platform surfaced across social media platforms. The manipulated video circulated across Facebook, Instagram, and WhatsApp, claimed that citizens could earn over ₹1.9 lakh per month by making a one time investment of ₹ 21,000 through an “AI-powered automated smart investing” scheme.

Read Case Study →
BSNLTelecom
CASE STUDY20 May 2024

Breach at Telecom Major BSNL

On 20 May 2024, government owned telecom major BSNL and a critical part of India’s national communications infrastructure, was hit by a major cybersecurity incident. The same day, a threat actor—kiberphant0m—claimed responsibility of the attack and advertised the sale of approximately 278 GB of sensitive telecom data on the dark web. The exposed data included IMSI numbers, SIM subscriber details, Home Location Register (HLR) records, and internal Solaris server snapshots, all of which are vital for telecom operations and subscriber identity management.

Read Case Study →
Breach in the Department of DefenceCybercrime
CASE STUDY

Breach in the Department of Defence

On 10 March 2025, Athenian Tech (AT) identified a significant security breach affecting a sensitive national defence division after the ransomware group Babuk Locker 2.0 claimed to have exfiltrated nearly 20TB of classified defence data. The leaked dataset reportedly included sensitive information like VVIP evacuation procedures.

Read Case Study →

Get the next one in your inbox.

The Month in Threats, Read by the People Who Have to Answer for It.

Free. Unsubscribe any time. We never sell or share your address.