A Gold Company Lost $1.2 Million To A Deepfake. Here Is What Security Leaders Should Take From It.

Key takeaways
- Starmangalsutra Private Limited, a jewelry subsidiary of Mumbai-listed Sky Gold & Diamonds, disclosed a loss of roughly ₹10.7 crore (about $1.2 million) after an employee authorized a fund transfer following a combination of a compromised corporate device and what the company described as AI-enabled deception.
- India's SEBI had already warned listed companies about the "boss scam" pattern before Sky Gold's disclosure went public — fraudsters impersonating an executive over WhatsApp, Microsoft Teams, email, or a cloned voice to demand an urgent transfer.
- The Reserve Bank of India's FY2025-26 annual report recorded ₹48,021 crore in fraud losses across more than 10,000 cases, while the FBI's IC3 2025 report logged $3.04 billion in business email compromise losses and, for the first time, broke out AI-enabled fraud as its own category — over 22,000 complaints and close to $900 million in losses.
- Dartmouth forensics researcher Hany Farid, who spent decades building tools to detect manipulated audio and video, said this month that deepfakes have grown good enough to evade the very detection methods he built his career on: "I feel like I'm going blind."
- The recommended defense is layered rather than relying on any single control: a second approver above a set transfer threshold, a mandatory delay window on high-value or first-time payees, and callbacks placed only to a number pulled from an internal directory — never one supplied by the person making the request.
- A Carnegie Mellon study led by Lorrie Faith Cranor found that embedded, just-in-time phishing training delivered at the moment an employee clicks a bad link outperforms standard security notices sent by email — the same logic applies to deepfake voice calls, where practiced recognition in a safe simulation transfers directly to spotting a live attempt.
What Sky Gold Disclosed
Starmangalsutra Private Limited, a jewelry subsidiary of Mumbai-listed Sky Gold & Diamonds, disclosed this month that it lost approximately ₹10.7 crore, close to $1.2 million, after an employee authorized a fund transfer. According to public filings, the incident involved compromise of a corporate device alongside what the company described as AI-enabled deception. The full forensic detail behind that description has not been made public, and that gap is worth stating plainly instead of filled in with speculation.
Shares in the parent company fell on the news, a reminder that a fraud loss carries a second cost beyond the transfer itself. Public disclosures like this one are still uncommon. Most companies that experience a loss like this absorb it quietly. Sky Gold's decision to disclose gives the market something specific to study: a documented account of impersonation fraud inside a working finance department, grounded in a concrete set of facts a security team can plan around.
Part of a Larger Pattern
India’s market regulator flagged this pattern before Sky Gold's disclosure became public. The Securities and Exchange Board of India warned listed companies about a scheme security researchers call the boss scam, in which fraudsters impersonate an executive over WhatsApp, Microsoft Teams, email, or a cloned voice, then demand an urgent transfer. The Reserve Bank of India's most recent annual report recorded ₹48,021 crore in fraud losses across more than 10,000 cases during the 2025-26 financial year, a figure that spans many fraud types beyond AI impersonation.
The pattern extends well beyond India. The FBI's Internet Crime Complaint Center logged $3.04 billion in business email compromise losses across nearly 25,000 incidents in its 2025 report, and for the first time gave AI-enabled fraud its own category, tracking more than 22,000 complaints and close to $900 million in losses tied specifically to AI-assisted schemes.
Researchers who spend their careers trying to detect manipulated media are now saying openly that the tools are catching up to them. Hany Farid, a professor at Dartmouth College who has spent decades building forensic tools to spot manipulated video and audio, told public radio program Here & Now this month that deepfakes have grown good enough to evade the detection methods he built his career on. “I feel like I'm going blind,” Farid said.
Vincent Conitzer, a computer science professor at Carnegie Mellon University, has pointed to the broader consequence of that shift. “That's one big worry, that none of us are going to be able to trust what we see anymore,” Conitzer told Carnegie Mellon's Heinz College. The tools that once tipped off a careful observer, like unnatural blinking or a flat vocal cadence, are disappearing as the models improve.
Building Defenses That Hold Up
“There has to be some sort of vetting and verification mechanism, because the average user will just assume it's real,” said Ari Lightman, a professor at Carnegie Mellon's Heinz College who studies digital media and emerging technology. His point cuts to the center of the Sky Gold case: once detection by eye or ear can no longer be trusted, the fix has to live inside a process employees follow every time.
Fraud like this gets stopped by layering controls, so that one employee's judgment in a stressful moment is never the last line of defense. Any advice built around a single control is worth a second look.
1. Process controls come first.
- A second approver should sign off on any transfer above a set threshold.
- A mandatory delay window should apply to high-value or first-time payee transfers, even when the request carries urgency.
- A callback should go to a number pulled from an internal directory, never a number supplied by the person making the request, since attackers routinely provide a number that rings straight back to them.
2. Technical controls reinforce those steps.
- Reconciliation checks should run on outgoing wires.
- Alerts should fire when payment details on a recurring vendor change.
- Escalation paths should stay clear, so a suspicious request gets a second set of eyes without requiring the original employee to be the one who raises the flag.
3. Human verification rounds out the stack, and research backs up why it has to be practiced through repetition.
- Carnegie Mellon researchers led by Lorrie Faith Cranor built and tested an embedded training system that puts employees through realistic phishing simulations and delivers instruction at the moment they click the wrong link. Their study found this approach outperforms standard security notices sent through email.
- The same logic applies to a deepfake phone call: an employee who has practiced spotting one in a safe simulation recognizes the pattern faster when a live attempt reaches them.
- Adaptive Security builds exactly this kind of simulation across voice, SMS, and email, so the training matches the channels attackers rely on today.
The Takeaway for Every Finance Team
Bruce Schneier, a fellow and lecturer at Harvard's Kennedy School, has argued for two decades that transparency about security failures makes everyone safer than silence does. “Public scrutiny is the only reliable way to improve security, while secrecy only makes us less secure,” Schneier wrote, a principle developed around software vulnerabilities that applies just as directly to a disclosed fraud loss. Every detail a company shares becomes a data point the next finance team can plan around.
The lesson from this incident travels well beyond one gold company in Mumbai. Finance leaders everywhere are one urgent message away from the same decision Starmangalsutra's employee faced. The companies that build layered verification now, calmly and without overcorrecting into distrust of every phone call, will already have these defenses in place the next time a deepfake wire fraud makes headlines.
Get started with Adaptive Security
Get started