A phone call from a family member's voice, panicked and asking for an urgent transfer. A video call with someone who looks exactly like a bank officer, asking you to "verify" your account. Neither of them may be real. Deepfake and voice-cloning tools have made it cheap and easy to fake a familiar voice or face, and cyber safety groups tracking Nepal have flagged a sharp rise in AI-assisted scams over the past two years. This guide explains how these scams actually work, the specific warning signs to watch for, and the steps that protect your bank account before, during and after a suspicious contact.
- What's actually happening in Nepal
- How deepfake banking scams work
- Common scam formats to know
- Red flags versus normal bank contact
- How to protect your account
- What to do during a suspicious call or video
- If you think you've already been scammed
- What banks and NRB are doing about it
- Spot-the-scam checklist
- FAQs
Quick answer
Deepfake scams use AI-generated voice or video to impersonate someone you trust - a relative, a bank official, or a well-known public figure - to pressure you into moving money or sharing account credentials. Nepal Police's Cyber Bureau has repeatedly warned about rising phishing, vishing (voice phishing) and impersonation scams, and cybersecurity groups tracking the region report a sharp increase in deepfake-related incidents. The best protection does not rely on spotting a fake voice or face - it relies on habits: never act on urgency alone, always verify through a separately dialled number or the official app, and never share an OTP or password with anyone, including someone who sounds or looks exactly like your bank.
What's actually happening in Nepal
Nepal hasn't seen a large wave of publicly confirmed deepfake bank-fraud cases the way some larger markets have, but the building blocks are clearly in place. Nepal Police's Cyber Bureau has repeatedly warned about phishing links disguised as banking alerts, fake loan-repayment offers, and bogus stock market training programmes designed to steal OTPs and banking credentials. Separately, cybersecurity monitoring groups tracking Nepal have reported a significant year-on-year jump in deepfake-related incidents, including at least one case where a fabricated video of a well-known executive nearly triggered market panic. Globally, the same period has seen deepfake-enabled fraud attempts targeting banks rise sharply, with voice-cloning tools now cheap enough for low-skill scammers to use.
The practical takeaway: the underlying scam tactics Nepali banking customers already face - urgent SMS links, fake police impersonation, phone-based social engineering - are the same tactics that get significantly more convincing once AI-generated voice or video is layered on top.
How deepfake banking scams actually work
Two technical building blocks make this possible. Voice cloning needs only a short, clean audio sample - a few seconds pulled from a video call, a voice note, or a public interview is often enough to generate a convincing clone. Video deepfakes need more source material but are increasingly achievable with consumer-grade tools, especially for public figures with plenty of existing footage online. Neither requires the scammer to be technically sophisticated; both are now available as easy-to-use commercial or free tools, which is exactly why cybersecurity groups describe this as a fast-democratising threat rather than a niche one.
Common deepfake scam formats to know
The "relative in trouble" call
A cloned voice of a family member, sounding panicked, claims an accident, arrest or emergency and asks for an urgent transfer - a classic scam given new believability by AI voice cloning.
The fake bank official
A call or video claiming to be from your bank's fraud or KYC department, asking you to "verify" your account by sharing an OTP, PIN or password, sometimes threatening account suspension if you don't comply immediately.
The fake investment endorsement
A deepfake video of a well-known business figure, banker or public official appearing to endorse a stock, crypto scheme or "guaranteed return" investment platform.
The digital-arrest style call
Impersonation of police or government officials, sometimes with fabricated documents or voice, pressuring victims into transferring money to "clear" a fake legal case.
Red flags versus normal bank contact
| Signal | Legitimate bank contact | Likely scam |
|---|---|---|
| Requests your OTP or full password | Never asks for this over call, SMS or video | Asks for it directly, often urgently |
| Creates time pressure | Gives you time to verify independently | Insists you act "right now" or lose access/funds |
| Contact channel | Matches the number/app you already have on file | Comes from an unfamiliar number, spoofed caller ID, or new video-call link |
| Voice or video quality | Consistent, natural pacing | Slightly off timing, unnatural pauses, mismatched lip movement, or audio that cuts out at odd moments |
| Asks you to move funds to a "safe account" | Never does this | Common line used to get victims to self-transfer funds out of reach |
The one rule that beats every deepfake
You do not need to be able to spot a fake voice or face. No legitimate bank, police officer or family member emergency requires you to share an OTP, password, or move money within minutes without independent verification. If a contact demands secrecy or speed, treat that demand itself as the red flag - regardless of how real the voice or video looks.
How to protect your bank account before anything happens
- Set a family safe word. Agree on a private word or phrase with close family that a scammer impersonating them wouldn't know, to use in any real emergency call.
- Turn on all available banking alerts. SMS and app notifications for every transaction give you the fastest possible warning if something moves without your knowledge.
- Save your bank's real numbers. Store the official customer-care number from your bank's card, passbook or official website, not a number given to you during a call.
- Limit what's public. Voice and video clips posted publicly, especially long clear ones, are exactly what voice-cloning tools need as source material. This doesn't mean going silent online, just being mindful of what's freely scrapeable.
- Use strong, unique banking PINs and passwords. And never store them in unencrypted notes or messaging apps where a compromised device could expose them.
What to do during a suspicious call or video
- Pause before reacting. Urgency is the scam's main weapon. A few seconds of calm buys you the ability to think clearly.
- Hang up and call back independently. Use the number saved from your bank's card or official app - never a number given to you during the suspicious call itself.
- Ask a question only the real person would know. For a "relative in trouble" call, use your family safe word or ask something a scammer's script wouldn't cover.
- Never share an OTP, PIN or password. No legitimate party - bank, police, or family - needs you to read out an OTP over a call.
- Don't act on payment instructions from the call itself. Verify any request to transfer funds through your bank's official app or branch, not through instructions given during the same contact.
If you think you've already been scammed
- Contact your bank immediately. Ask them to freeze the account or block further transactions the moment you suspect fraud - speed matters more than anything else at this stage.
- Change your passwords and PINs. Do this from a device you're confident is not compromised.
- File a complaint with Nepal Police's Cyber Bureau. Keep screenshots, call logs, transaction records and any recording as evidence when you report.
- Warn your contacts. If a messaging or social account was compromised as part of the scam, alert your contacts so the same scam isn't reused against them in your name.
- Be alert to "recovery" scams. A second scam often follows the first - someone offering to "recover" your stolen funds for an upfront fee. No legitimate bank, police unit or recovery service asks for advance payment to return stolen money.
What banks and regulators are doing about it
Banks are investing in AI-powered fraud detection of their own - the same pattern-recognition technology used to build scams is also used to catch them, flagging unusual login locations, transaction patterns or device changes faster than manual review ever could. Liveness detection during video KYC (asking a user to blink, turn their head, or follow an on-screen prompt) is becoming a standard defence against simple pre-recorded deepfake videos, though sophisticated real-time deepfakes remain a harder problem industry-wide. On the regulatory side, Nepal Rastra Bank's new Artificial Intelligence Guidelines specifically call out AI-generated synthetic media, including deepfakes, as a risk institutions must assess and mitigate - covered in more depth in our guide to what NRB's AI guideline means for banks.
Spot-the-Scam Checklist
Before you act on any urgent call, video, or message claiming to involve your bank account, check off what applies. Any single item checked is reason enough to pause and verify independently.
Frequently asked questions
Conclusion
Deepfake scams are unsettling because they attack the one thing we've always trusted by instinct - recognising a familiar voice or face. The good news is that the defence doesn't depend on getting better at spotting fakes. It depends on habits that already work against ordinary phone scams: never sharing an OTP, always verifying through a separately initiated contact, and treating urgency itself as a warning sign. Build those habits once, and it stops mattering how convincing the fake gets.
Want to understand how regulators are responding to AI risk in Nepal's financial sector? Read Nepal Rastra Bank's New AI Guideline: What Banks Must Know.
Discussion