{
  "schema_version": "1.0.0",
  "generated_at": "2026-08-20",
  "evidence_level_values": [
    "AI_EXPLICIT",
    "AI_EXPLICIT_CAPABILITY_LEVEL",
    "AI_EXPLICIT_CAMPAIGN_LEVEL",
    "AI_EXPLICIT_MORPHED_IMAGERY",
    "AI_EXTENSION"
  ],
  "implementation_status_values": [
    "RESEARCHED"
  ],
  "vectors": [
    {
      "id": "A01",
      "title": "Digital-arrest extortion",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "IMPS", "NEFT", "RTGS"],
      "channels": ["SPOOFED_CALL", "IVR", "WHATSAPP", "VIDEO_CALL"],
      "genai_role": "Multilingual voicebots, cloned official voice or face, and synthetic notices or backgrounds personalize coercion at scale.",
      "observables": [
        "Long unknown call overlaps the payment session",
        "First-time beneficiary or newly added payee",
        "Large or repeated transfers outside the customer profile",
        "Recipient phone or account appears in fraud intelligence or fan-in patterns"
      ],
      "mitigations": [
        "Display a contextual warning that digital arrest has no legal basis",
        "Require out-of-band agency verification and end the unknown call",
        "Apply step-up authentication or a cooling period to high-risk first-payee transfers",
        "Use FRI and beneficiary-graph checks with one-tap 1930 or NCRP reporting"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/pdf/Advisories/ADVISORYTAU-ADV-003DigitalArrest06.03.2025.pdf",
        "https://sancharsaathi.gov.in/SancharSaathiDocuments/ImportantDocuments/DoT%20combats%20Cyber-frauds%3A%20Central%20system%20to%20stop%20spoofed%20calls%20to%20be%20commissioned%20shortly.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A02",
      "title": "Voice-cloned family or trusted-contact emergency",
      "evidence_level": "AI_EXPLICIT",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "IMPS"],
      "channels": ["PHONE", "VOICEMAIL", "WHATSAPP_AUDIO", "WHATSAPP_VIDEO"],
      "genai_role": "Few-shot voice cloning, social-media facts, accent adaptation, and synthetic video make an urgent trusted-contact request convincing.",
      "observables": [
        "Urgency or secrecy language",
        "First payment to the recipient",
        "Beneficiary name differs from the claimed relative",
        "Amount deviates from normal peer-to-peer behavior"
      ],
      "mitigations": [
        "Call back on a previously saved number",
        "Use a family safe word or challenge question",
        "Show the verified beneficiary name before authorization",
        "Apply risk-based delay or trusted-contact review"
      ],
      "primary_sources": [
        "https://sbi.co.in/documents/16012/14424788/DOs%2B%26%2BDONTs%2BON%2BSOCIAL%2BMEDIA%2B6-VETTED-ENGLISH.pdf/804b4629-f92c-46e4-f2e3-56889836243d?t=1755495561928",
        "https://www.hdfcbank.com/personal/resources/learning-centre/vigil-aunty/deepfake-phishing-how-cybercriminals-use-ai-to-steal-financial-data"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A03",
      "title": "Bank or RBI official impersonation for KYC, account block, or verification",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "CARDS", "NET_BANKING"],
      "channels": ["VOICE_CALL", "SMS", "EMAIL", "WHATSAPP"],
      "genai_role": "Regional-language voicebots, institution-specific scripts, cloned executive voices, and personalized account references increase credibility and scale.",
      "observables": [
        "Unsolicited urgency about KYC or account blocking",
        "Unregistered or look-alike sender and off-domain URL",
        "Request for OTP, PIN, CVV, app installation, or transfer",
        "New beneficiary or payment immediately after a credential reset"
      ],
      "mitigations": [
        "Route support through authenticated in-app channels",
        "Validate DLT sender headers and domains",
        "Step up transactions after reset or beneficiary addition",
        "Use FRI and narrative-specific warnings"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/Scripts/FS_PressRelease.aspx?prid=58595&fn=14",
        "https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11917",
        "https://trai.gov.in/advice-to-senders"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A04",
      "title": "Executive or vendor impersonation and payment-authorisation BEC",
      "evidence_level": "AI_EXPLICIT",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["NEFT", "RTGS", "IMPS", "CORPORATE_BANKING"],
      "channels": ["EMAIL", "MICROSOFT_TEAMS", "PHONE", "VIDEO_CALL"],
      "genai_role": "Executive voice or video cloning, style-matched email, reconnaissance, and persistent multilingual follow-up pressure payment approvers.",
      "observables": [
        "New or changed beneficiary",
        "Reply-to or domain mismatch",
        "Unusual secrecy, urgency, timing, or approval path",
        "New mailbox rule, device, or supplier account distributing QR or PDF lures"
      ],
      "mitigations": [
        "Call the supplier through a known channel",
        "Require dual control and maker-checker approval",
        "Apply a beneficiary-change cooling period",
        "Monitor email authentication, mailbox rules, and transaction anomalies"
      ],
      "primary_sources": [
        "https://www.hdfcbank.com/personal/resources/learning-centre/vigil-aunty/deepfake-phishing-how-cybercriminals-use-ai-to-steal-financial-data",
        "https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2026-0037&pageid=PUBVLNOTES02"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A05",
      "title": "Deepfake public-figure investment endorsement",
      "evidence_level": "AI_EXPLICIT",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "IMPS", "NEFT"],
      "channels": ["SOCIAL_AD", "SEARCH_AD", "WHATSAPP", "TELEGRAM", "FAKE_APP", "FAKE_WEBSITE"],
      "genai_role": "Deepfake endorsements, synthetic testimonials, investment chat personas, and automated group moderation create a credible investment funnel.",
      "observables": [
        "Prominent-person media paired with guaranteed or unusually high returns",
        "Sideloaded or unregistered trading app",
        "Small inbound credit followed by escalating outbound deposits",
        "Beneficiary name does not match the claimed regulated firm"
      ],
      "mitigations": [
        "Verify SEBI or RBI registration and known official channels",
        "Use media provenance plus app and domain reputation",
        "Warn and step up escalating payments to new beneficiaries",
        "Score shared mule recipients and staged-payment sequences"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/pdf/Advisories/ADVISORY%20TAU-ADV-001%20%2822.04.2024%29.pdf",
        "https://www.rbi.org.in/Scripts/FS_PressRelease59135.html",
        "https://investor.sebi.gov.in/inv_aware_edu_videos.html"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A06",
      "title": "Fake customer-care, search-result, or social-grievance interception",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "CARDS", "NET_BANKING"],
      "channels": ["SEARCH", "MAPS", "SOCIAL_MEDIA", "PHONE", "CHAT", "REMOTE_ACCESS"],
      "genai_role": "AI generates support pages, product-aware scripts, and fluent multilingual agents that monitor and answer public complaints at scale.",
      "observables": [
        "Contact originates outside the official app",
        "Newly created domain or profile responds after a grievance post",
        "Remote-access request or payment to a personal VPA",
        "Phone or account is risky in complaint or FRI intelligence"
      ],
      "mitigations": [
        "Surface verified support only inside the official app",
        "Maintain verified-domain and phone directories with rapid takedown",
        "Block payment when suspicious remote-control state is present",
        "Display recipient-risk warnings and prohibit temporary transfers"
      ],
      "primary_sources": [
        "https://www.cybercrime.gov.in/assets/learning-corner/advisory/pdf/Cybercriminals%20using%20Fake%20Customer.pdf",
        "https://www.npci.org.in/fraud-awareness",
        "https://support.google.com/pay/india/answer/9851787?hl=en"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A07",
      "title": "Military-personnel impersonation in marketplace or rental transactions",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "BANK_TRANSFER"],
      "channels": ["MARKETPLACE", "WHATSAPP", "PHONE", "UPI_COLLECT", "QR"],
      "genai_role": "Synthetic identity media, cloned voice or video, and automated negotiation scale a trusted military persona across listings.",
      "observables": [
        "New marketplace contact claims a military identity",
        "Small test is followed by a larger request",
        "Payer expects a credit but receives a collect request",
        "One VPA appears across unrelated listings"
      ],
      "mitigations": [
        "Show an explicit pay-versus-collect warning",
        "Display the verified beneficiary name",
        "Use marketplace identity and reputation checks",
        "Block or report abusive VPAs and do not accept identity images as proof"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/theme/resources/advisories/FraudstersusingArmypersonneldetailstoperpetratefinancialcyberfrauds.pdf",
        "https://www.phonepe.com/trust-and-safety/"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A08",
      "title": "Utility, electricity, SIM, or wallet KYC disconnection lure",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "NET_BANKING", "CARDS"],
      "channels": ["SMS", "WHATSAPP", "VOICE_CALL", "MALICIOUS_LINK", "APK", "REMOTE_ACCESS"],
      "genai_role": "Hyper-local account wording, synthetic notices, and regional-language agents rapidly adapt disconnection or KYC narratives.",
      "observables": [
        "Unregistered sender, odd header, or shortened off-domain link",
        "Sideload or accessibility-permission request",
        "Payment occurs during an unknown call",
        "New device or beneficiary is linked to a high-risk phone or IMEI cluster"
      ],
      "mitigations": [
        "Verify status in the official provider app",
        "Enforce DLT sender and content controls",
        "Block risky apps and accessibility states",
        "Use FRI or Chakshu intelligence and step up post-change payments"
      ],
      "primary_sources": [
        "https://www.sancharsaathi.gov.in/SancharSaathiDocuments/ImportantDocuments/Press%20Release-DoT%20takes%20action%20against%20Electricity%20KYC%20Update%20Scam.pdf",
        "https://trai.gov.in/advice-to-senders"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A09",
      "title": "Matrimonial or romance persona leading to investment or crypto payment",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "BANK_TRANSFER", "CRYPTO_ON_RAMP"],
      "channels": ["MATRIMONY_APP", "DATING_APP", "CHAT", "VIDEO_CALL"],
      "genai_role": "Synthetic profile media, long-memory chat, multilingual affectionate dialogue, and generated voice sustain a persistent relationship persona.",
      "observables": [
        "New relationship is followed by an investment-category payment",
        "Long grooming precedes escalating transfers",
        "Multiple beneficiaries are introduced by one persona",
        "Identity inconsistencies or recipients shared across victims"
      ],
      "mitigations": [
        "Use reverse-image and identity verification",
        "Score recipients across the entity graph",
        "Warn on relationship-originated investment payments",
        "Apply a cooling period to high-value first-payee transfers"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/theme/resources/advisories/ADVISORY-Matriminy%20Scam.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "A10",
      "title": "Fake job, task, or CAPTCHA work with deposits and withdrawal-unlock fees",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IMPERSONATION_COERCION_TRUST",
      "rails": ["UPI", "BANK_TRANSFER"],
      "channels": ["JOB_PORTAL", "SOCIAL_MEDIA", "SMS", "EMAIL", "CHAT", "FAKE_APP", "FAKE_WEBSITE"],
      "genai_role": "AI creates personalized recruiter outreach, synthetic companies and agreements, conversational coaching, and fabricated earning dashboards.",
      "observables": [
        "Upfront registration or training fee",
        "Unrealistic earnings for minimal work",
        "Small early payout followed by repeated deposits",
        "Beneficiary is unrelated to the claimed employer and reused across applicants"
      ],
      "mitigations": [
        "Verify employer and domain independently",
        "Warn that legitimate recruitment should not require an upfront fee",
        "Score escalating payments and shared recipients",
        "Report suspect identifiers and transfers promptly to 1930 or NCRP"
      ],
      "primary_sources": [
        "https://www.cybercrime.gov.in/assets/learning-corner/advisory/pdf/Advisory%20on.pdf",
        "https://www.cybercrime.gov.in/assets/learning-corner/advisory/pdf/Fraudsters%20sending%20Fake.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B01",
      "title": "UPI collect request disguised as incoming money, refund, or verification",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI"],
      "channels": ["UPI_COLLECT", "CHAT", "VOICE_CALL"],
      "genai_role": "Personalized support dialogue, localized transaction notes, and adaptive scripts make a debit request resemble an expected receipt.",
      "observables": [
        "User context indicates an expected receipt but the action is a debit",
        "First-time VPA or payee-name mismatch",
        "Repeated collect attempts from one requester",
        "Small-test-then-large request sequence"
      ],
      "mitigations": [
        "Display an unmissable message that the user is paying",
        "Show verified payee and amount before PIN entry",
        "Risk-score and rate-limit abusive VPAs",
        "Provide immediate block and report controls"
      ],
      "primary_sources": [
        "https://rbidocs.rbi.org.in/rdocs/content/pdfs/BEAWARE07032022.pdf",
        "https://www.npci.org.in/PDF/npci/upi/circular/2018/Circular%2057.pdf",
        "https://www.npci.org.in/product/bhim"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B02",
      "title": "QR scan-to-receive refund or cashback deception",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI"],
      "channels": ["QR", "CHAT", "SOCIAL_MEDIA"],
      "genai_role": "Branded creative, a personalized amount or pretext, and multilingual support make a malicious or misdirected QR appear legitimate.",
      "observables": [
        "QR arrives through an unknown channel",
        "Expected receipt conflicts with debit authorization",
        "QR resolves to an unrelated or first-time VPA",
        "Pre-populated amount or repeated use across complaints"
      ],
      "mitigations": [
        "State clearly that QR plus UPI PIN sends money",
        "Show payee, amount, and direction prominently",
        "Apply QR and VPA reputation checks",
        "Reject QR-led app downloads or credential pages"
      ],
      "primary_sources": [
        "https://www.npci.org.in/fraud-awareness",
        "https://www.phonepe.com/blog/trust-and-safety/stay-safe-from-qr-code-fraud/",
        "https://rbidocs.rbi.org.in/rdocs/content/pdfs/BEAWARE07032022.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B03",
      "title": "Fake cashback, loyalty points, prize, or reward redemption",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI", "CARDS"],
      "channels": ["AD", "SMS", "EMAIL", "VOICE_CALL", "LINK", "QR"],
      "genai_role": "AI personalizes the reward, clones a brand agent, and creates polished regional-language landing pages and follow-up dialogue.",
      "observables": [
        "Expiring or too-good-to-be-true offer",
        "Off-domain link or QR and PIN used for receiving",
        "Request for CVV or OTP",
        "Merchant, recipient, device, or session mismatch"
      ],
      "mitigations": [
        "Redeem only through the official app or site",
        "Use domain, app, and merchant reputation",
        "Display payment direction and merchant name",
        "Never request PIN, OTP, or CVV through support"
      ],
      "primary_sources": [
        "https://www.npci.org.in/fraud-awareness",
        "https://sbi.co.in/documents/136/1364568/110523-HiveBooklet_Dec%2B2022_HighRes.pdf/03182d7d-3d66-c8cc-9a2f-14bc79271670?t=1683811782109"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B04",
      "title": "UPI AutoPay mandate disguised as one-time verification or small payment",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI_AUTOPAY"],
      "channels": ["SMS", "CHAT", "FAKE_SUPPORT"],
      "genai_role": "Context-specific support narratives and realistic mandate descriptions conceal recurrence, cap, or validity.",
      "observables": [
        "Description conflicts with recurring frequency or maximum amount",
        "Long validity or unusually high cap",
        "First-time merchant or repeated mandate attempts",
        "User arrived from an untrusted support channel"
      ],
      "mitigations": [
        "Display recurrence, cap, start, end, and total exposure prominently",
        "Warn on semantic mismatch between narrative and mandate",
        "Delay or step up risky first-time mandates",
        "Provide simple revocation and decline unsolicited requests"
      ],
      "primary_sources": [
        "https://paytm.com/blog/payments/upi/upi-frauds/"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B05",
      "title": "Marketplace buyer or seller request-money manipulation",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI"],
      "channels": ["MARKETPLACE", "CHAT", "UPI_COLLECT"],
      "genai_role": "Automated conversations, tailored personas, synthetic identity evidence, and multilingual negotiation scale the deception across listings.",
      "observables": [
        "New marketplace contact",
        "Payer expects an incoming payment but receives a collect request",
        "First-time VPA with repeated requests",
        "Same VPA appears across unrelated listings"
      ],
      "mitigations": [
        "Use direction-aware confirmation",
        "Prefer marketplace escrow where available",
        "Display verified payee name and VPA reputation",
        "Rate-limit abusive requests and explain that a PIN is not needed to receive"
      ],
      "primary_sources": [
        "https://rbidocs.rbi.org.in/rdocs/content/pdfs/BEAWARE07032022.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B06",
      "title": "Fake refund or wrong-transfer rerouting",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI", "IMPS", "NEFT"],
      "channels": ["SMS", "CHAT", "VOICE_CALL"],
      "genai_role": "Synthetic receipts, personalized references, cloned merchant support, and rapid follow-up pressure an independent return transfer.",
      "observables": [
        "No matching original ledger event",
        "Return destination differs from original sender",
        "Urgent request to a new beneficiary",
        "Screenshot-only proof or recipient linked to complaints"
      ],
      "mitigations": [
        "Use only a ledger-linked reversal through the original rail",
        "Do not manually transfer to an alternate account",
        "Warn on beneficiary mismatch",
        "Hold or review unusual incoming-then-outgoing sequences"
      ],
      "primary_sources": [
        "https://paytm.com/blog/payments/upi/upi-frauds/",
        "https://www.cybercrime.gov.in/webform/video-category.aspx"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B07",
      "title": "AI-generated fake payment screenshot, receipt, or confirmation audio",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI"],
      "channels": ["MERCHANT_COUNTER", "CHAT", "SCREENSHOT", "AUDIO_CONFIRMATION"],
      "genai_role": "Generative tools create localized receipts, plausible names and transaction references, and synthetic payment-confirmation audio.",
      "observables": [
        "Claimed transaction reference is absent from the ledger",
        "OCR fields mismatch the real transaction",
        "Duplicate or nonexistent transaction reference",
        "No authenticated merchant-app or Soundbox credit event"
      ],
      "mitigations": [
        "Treat the server ledger as the source of truth",
        "Verify in the merchant app, bank, or authenticated Soundbox",
        "Use signed or verifiable receipts",
        "Never release goods or cash from a screenshot alone"
      ],
      "primary_sources": [
        "https://paytm.com/blog/payments/upi/upi-frauds/"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B08",
      "title": "Merchant QR sticker replacement or beneficiary substitution",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI"],
      "channels": ["PHYSICAL_QR", "SOCIAL_QR", "MERCHANT_PAYMENT"],
      "genai_role": "AI generates convincing branded QR surrounds, landing pages, and synthetic merchant support for targeted substitution campaigns.",
      "observables": [
        "Merchant name or location does not match the VPA",
        "Abrupt change in receiving account",
        "One VPA appears at unrelated locations",
        "Payment QR opens a URL, app, or complaint-linked identifier"
      ],
      "mitigations": [
        "Validate merchant registry and geolocation consistency",
        "Use signed or dynamic QR where feasible",
        "Show verified payee prominently",
        "Inspect physical displays and alert on beneficiary remapping"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/theme/resources/advisories/CybercriminalsTamperingwithQRCodestodefraudCitizens.pdf",
        "https://www.npci.org.in/PDF/npci/press-releases/2018/NPCI%20launches%20Unified%20Payments%20Interface%202%200.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "B09",
      "title": "Synthetic storefront, fake shopping offer, or cloned payment page",
      "evidence_level": "AI_EXTENSION",
      "cluster": "UPI_MERCHANT_INTERACTION_DECEPTION",
      "rails": ["UPI", "CARDS", "NET_BANKING"],
      "channels": ["SEARCH", "SOCIAL_AD", "ECOMMERCE", "FAKE_WEBSITE", "FAKE_APP"],
      "genai_role": "AI instantly creates catalogs, product images, reviews, policies, support bots, and cloned brand experiences across rapidly changing domains.",
      "observables": [
        "Young or look-alike domain",
        "Unrealistic discount or beneficiary mismatch",
        "No delivery history or credible fulfilment",
        "Shared device or account across multiple storefronts"
      ],
      "mitigations": [
        "Use domain, app, and merchant reputation",
        "Verify merchant onboarding and beneficiary name",
        "Sign payment links",
        "Monitor fulfilment and graph-link cloned storefronts for takedown"
      ],
      "primary_sources": [
        "https://www.npci.org.in/fraud-awareness",
        "https://www.phonepe.com/pulsestatic/791/pulse/static/de6e24681bde9e12a54de1361d914c84/Pulse_Report_2021_M_B.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C01",
      "title": "Hyper-personalized multilingual smishing or phishing",
      "evidence_level": "AI_EXPLICIT_CAPABILITY_LEVEL",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "CARDS", "NET_BANKING"],
      "channels": ["SMS", "EMAIL", "RCS", "WHATSAPP", "SOCIAL_MEDIA", "PHISHING_SITE"],
      "genai_role": "LLMs automate reconnaissance, institution- and language-matched copy, low-cost variants, follow-up dialogue, and fake-site content.",
      "observables": [
        "Sender, header, or domain mismatch",
        "Newly registered URL or shared campaign infrastructure",
        "Credential entry followed by a new device, login, or payee",
        "High-volume message variants with common intent"
      ],
      "mitigations": [
        "Validate DLT headers, domains, and app reputation",
        "Use phishing-resistant MFA and device binding",
        "Apply session and behavioral detection",
        "Classify malicious intent and rapidly share suspect identifiers"
      ],
      "primary_sources": [
        "https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2026-0020&pageid=PUBVLNOTES02",
        "https://cybercrime.gov.in/Webform/CrimeCatDes.aspx",
        "https://arxiv.org/abs/2305.06972"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C02",
      "title": "Malicious APK or accessibility-overlay takeover",
      "evidence_level": "AI_EXTENSION",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "NET_BANKING", "CARDS"],
      "channels": ["SMS", "CHAT", "AD", "APK", "ACCESSIBILITY_SERVICE"],
      "genai_role": "AI creates convincing app branding and adaptive multilingual installation support while rapidly localizing lure variants.",
      "observables": [
        "Sideloaded or untrusted app",
        "New accessibility, overlay, or device-admin permission",
        "Payment during an unknown call",
        "Scripted interaction, new beneficiary, or risk-linked IMEI"
      ],
      "mitigations": [
        "Use device and app attestation",
        "Block payments with suspicious accessibility state",
        "Require call termination and warn against sideloading",
        "Invalidate sessions and change PIN after detection"
      ],
      "primary_sources": [
        "https://support.google.com/pay/india/answer/17165523?hl=en",
        "https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11917",
        "https://www.sancharsaathi.gov.in/SancharSaathiDocuments/ImportantDocuments/Press%20Release-DoT%20takes%20action%20against%20Electricity%20KYC%20Update%20Scam.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C03",
      "title": "Screen-sharing or remote-control support scam",
      "evidence_level": "AI_EXTENSION",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "MOBILE_BANKING", "CARDS"],
      "channels": ["PHONE", "CHAT", "REMOTE_ACCESS", "SCREEN_SHARING"],
      "genai_role": "Always-on multilingual support bots and cloned call personas deliver product-specific troubleshooting narratives.",
      "observables": [
        "Remote-control app is installed or open",
        "Screen-sharing permission is active",
        "Unknown call overlaps mobile banking",
        "Beneficiary addition or credential reset occurs in the same session"
      ],
      "mitigations": [
        "Pause payments during risky remote-control state",
        "Use authenticated in-app support",
        "Re-authenticate transactions on a trusted UI",
        "Apply device-integrity scoring and prominent warnings"
      ],
      "primary_sources": [
        "https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2020-0003&pageid=PUBVLNOTES02",
        "https://www.npci.org.in/PDF/npci/press-releases/2019/NPCI%20Press%20release%20-%20Digital%20Payments%20Safety%20%282%29.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C04",
      "title": "SIM-swap or eSIM takeover followed by payment-account reset",
      "evidence_level": "AI_EXTENSION",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "CARDS", "NET_BANKING", "PPI"],
      "channels": ["SIM_PROVISIONING", "ESIM", "SMS_OTP", "MOBILE_APP"],
      "genai_role": "Synthetic KYC documents, cloned customer calls, and personalized telecom scripts strengthen fraudulent replacement or port-out attempts.",
      "observables": [
        "Sudden SIM or IMSI change",
        "OTP, reset, and new-device sequence",
        "Beneficiary addition or payment immediately after SIM change",
        "Geolocation or IP jump"
      ],
      "mitigations": [
        "Bind the account to device and SIM",
        "Apply a cooling period and out-of-band notice after SIM change",
        "Share telecom risk with banks",
        "Use step-up authentication independent of SMS"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/CrimeCatDes.aspx",
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C05",
      "title": "Card, OTP, CVV, or reward-point vishing leading to card-not-present fraud",
      "evidence_level": "AI_EXTENSION",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["CARDS", "PPI"],
      "channels": ["PHONE", "SMS", "EMAIL", "ECOMMERCE"],
      "genai_role": "Voice cloning, voicebots, synthetic bank messages, and product-specific scripts scale credential capture.",
      "observables": [
        "Unsolicited call overlaps an OTP",
        "New merchant, device, IP, geography, or MCC",
        "Multiple low-value probes",
        "Recent card-setting or account change"
      ],
      "mitigations": [
        "Never request or disclose OTP, CVV, or PIN",
        "Use additional-factor authentication and device risk",
        "Apply velocity, MCC, and geolocation controls",
        "Let customers set card limits and decline anomalous CNP payments"
      ],
      "primary_sources": [
        "https://sbi.co.in/documents/136/1364568/110523-HiveBooklet_Dec%2B2022_HighRes.pdf/03182d7d-3d66-c8cc-9a2f-14bc79271670?t=1683811782109",
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C06",
      "title": "Social-account takeover or clone followed by trusted-contact payment asks",
      "evidence_level": "AI_EXTENSION",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "IMPS"],
      "channels": ["SOCIAL_MEDIA", "WHATSAPP", "CHAT"],
      "genai_role": "AI imitates message style, tailors a story per contact, generates voice notes, and manages simultaneous conversations.",
      "observables": [
        "New linked device or session",
        "Burst of outbound payment requests",
        "Many contacts pay the same new VPA",
        "Beneficiary differs from the profile owner"
      ],
      "mitigations": [
        "Alert on linked-device and session anomalies",
        "Verify through an independent callback",
        "Use recipient graph and velocity scoring",
        "Warn on payee-name mismatch and revoke compromised sessions"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/theme/resources/advisories/Mule%20Whatsapp%20V1.4.pdf",
        "https://cybercrime.gov.in/webform/cyber_suspect.aspx"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C07",
      "title": "Trusted-supplier QR, PDF, or device-code phish leading to BEC payment",
      "evidence_level": "AI_EXPLICIT_CAMPAIGN_LEVEL",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["NEFT", "RTGS", "IMPS", "CORPORATE_BANKING"],
      "channels": ["SUPPLIER_EMAIL", "QR", "PDF", "OAUTH_DEVICE_CODE", "CLOUD_ACCOUNT"],
      "genai_role": "AI creates contextual supplier email and documents, imitates style, automates reconnaissance, and adapts conversation after compromise.",
      "observables": [
        "Unexpected QR in a business PDF",
        "Unusual OAuth device authorization or rogue device",
        "Impossible travel or hidden inbox rules",
        "Changed supplier beneficiary or lateral mail burst"
      ],
      "mitigations": [
        "Use phishing-resistant MFA and managed-device identity",
        "Restrict risky authorization flows",
        "Analyze QR and attachments and monitor mailbox rules",
        "Call back on beneficiary change and enforce maker-checker"
      ],
      "primary_sources": [
        "https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2026-0037&pageid=PUBVLNOTES02"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "C08",
      "title": "AI-assisted credential harvesting and automated banking account takeover",
      "evidence_level": "AI_EXPLICIT_CAPABILITY_LEVEL",
      "cluster": "DEVICE_CREDENTIAL_ACCOUNT_COMPROMISE",
      "rails": ["UPI", "IMPS", "NEFT", "CARDS"],
      "channels": ["WEB_LOGIN", "MOBILE_LOGIN", "API", "AUTOMATED_RECONNAISSANCE"],
      "genai_role": "AI accelerates attack-surface discovery, credential harvesting, attack-path planning, social pretexts, and multi-stage orchestration.",
      "observables": [
        "Unusually fast enumeration or login activity",
        "Distributed failed logins or unfamiliar scripts",
        "New device or IP",
        "Rapid reset-payee-payment chain or multiple accounts converging on one recipient"
      ],
      "mitigations": [
        "Use rate limits and bot detection",
        "Require phishing-resistant MFA and device attestation",
        "Apply session-risk analytics and post-reset delays",
        "Use entity-graph and transaction-velocity controls"
      ],
      "primary_sources": [
        "https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2026-0020&pageid=PUBVLNOTES02",
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D01",
      "title": "Deepfake V-CIP or liveness bypass for account, card, or loan onboarding",
      "evidence_level": "AI_EXPLICIT",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["PPI", "CARDS", "LOANS", "UPI"],
      "channels": ["VIDEO_KYC", "DIGITAL_ONBOARDING"],
      "genai_role": "Real-time face swaps, voice cloning, synthetic backgrounds, prompted answers, and repeated variants target liveness and identity checks.",
      "observables": [
        "Liveness or presentation-attack anomaly",
        "Audio-video inconsistency or randomized-question failure",
        "Pause, reconnection, or visible prompting",
        "Device or IP reuse followed by immediate post-opening velocity"
      ],
      "mitigations": [
        "Use active randomized liveness and face matching",
        "Validate geolocation and IP integrity",
        "Train human reviewers to reject prompted or prerecorded interaction",
        "Apply graph collision checks and delayed high-risk capability release"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566",
        "https://www.phonepe.com/blog/trust-and-safety/deepfake-impersonations-how-to-stay-safe-from-ais-dark-side-of-reality/",
        "https://arxiv.org/abs/2307.01426"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D02",
      "title": "Morphed photo or GenAI-forged KYC document creating a synthetic identity",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["UPI", "PPI", "CARDS", "LOANS"],
      "channels": ["DIGITAL_KYC", "ACCOUNT_ONBOARDING", "MERCHANT_ONBOARDING"],
      "genai_role": "Face morphing and coherent synthetic documents, addresses, employers, and histories support repeatable identity applications.",
      "observables": [
        "Document template, font, or metadata anomaly",
        "Face morph or issuer-data mismatch",
        "Device, document, or face reused across identities",
        "Thin-file profile followed by high-risk behavior"
      ],
      "mitigations": [
        "Verify issuer-signed e-documents or DigiLocker records",
        "Use trusted capture and morph or document forensics",
        "Run cross-field and identity-graph checks",
        "Apply post-onboarding limits and monitoring"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566",
        "https://www.nist.gov/publications/considerations-implementing-morph-detection-operations"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D03",
      "title": "AePS fake-biometric transaction",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["AEPS"],
      "channels": ["BC_CSP_TOUCHPOINT", "BIOMETRIC_AUTHENTICATION"],
      "genai_role": "Generative or AI-assisted biometric artefacts, synthetic consent narratives, and scaled victim selection may strengthen a documented fake-biometric pattern.",
      "observables": [
        "Biometric mismatch or quality anomaly",
        "Repeated attempts across identities at one terminal",
        "Off-hours or distant-location withdrawal",
        "Unusual amount, velocity, or compromised agent graph"
      ],
      "mitigations": [
        "Enforce registered-device integrity and dual authentication where available",
        "Monitor BC or CSP negative registry and terminal anomalies",
        "Send instant customer alerts and support rapid disputes",
        "Promote UIDAI biometric locking"
      ],
      "primary_sources": [
        "https://www.npci.org.in/PDF/AePS/circular/2022-23/Addendum-to-AePS-Fraud-Liability-Guideline-Feb-2022.pdf",
        "https://www.uidai.gov.in/en/925-english-uk/faqs/aadhaar-online-services/biometric-lock-unlock.html"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D04",
      "title": "BC or CSP deception to capture Aadhaar, VID, or biometric and transact",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["AEPS", "EKYC"],
      "channels": ["BC_CSP_TOUCHPOINT", "BIOMETRIC_CAPTURE"],
      "genai_role": "Regional-language persuasion, synthetic receipts, automated targeting, and impersonated bank support strengthen deceptive consent.",
      "observables": [
        "Financial transaction follows a purported non-financial service",
        "Amount mismatch or repeated reversal and retry pattern",
        "Complaint spike at one agent terminal",
        "Missing or weak consent evidence"
      ],
      "mitigations": [
        "State transaction type and amount clearly on device and by voice",
        "Issue a verifiable receipt and instant alert",
        "Capture consent and monitor the agent or terminal",
        "Use negative registries, audits, dual authentication, and biometric-lock education"
      ],
      "primary_sources": [
        "https://www.npci.org.in/PDF/AePS/circular/2022-23/Addendum-to-AePS-Fraud-Liability-Guideline-Feb-2022.pdf",
        "https://www.npci.org.in/product/aeps/about-aeps"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D05",
      "title": "Wrong Aadhaar linking or seeding exploited for withdrawals or transfers",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["AEPS"],
      "channels": ["AADHAAR_SEEDING", "BANK_ACCOUNT_LINKING", "BIOMETRIC_AUTHENTICATION"],
      "genai_role": "Synthetic documents and support correspondence may conceal or induce an incorrect Aadhaar linkage.",
      "observables": [
        "Name or demographic mismatch during seeding",
        "Recent Aadhaar-link change",
        "Authentication from an unfamiliar agent or geography",
        "New AePS activity on an inactive account or linkage collision"
      ],
      "mitigations": [
        "Use strong seeding validation and maker-checker",
        "Notify the customer and apply a cooling period",
        "Check demographic and identifier consistency",
        "Maintain audit trails and a rapid unlink or dispute process"
      ],
      "primary_sources": [
        "https://www.npci.org.in/PDF/AePS/circular/2022-23/Addendum-to-AePS-Fraud-Liability-Guideline-Feb-2022.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "D06",
      "title": "Dormant or low-activity account reactivation and takeover",
      "evidence_level": "AI_EXTENSION",
      "cluster": "IDENTITY_ONBOARDING_AADHAAR_AEPS",
      "rails": ["UPI", "IMPS", "NEFT", "ATM"],
      "channels": ["BRANCH_SERVICING", "DIGITAL_SERVICING", "ACCOUNT_REACTIVATION"],
      "genai_role": "Synthetic update documents, cloned customer calls, personalized answers, and exposed-identity reconnaissance assist reactivation fraud.",
      "observables": [
        "Long dormancy followed by KYC, contact, SIM, or device change",
        "Immediate beneficiary addition",
        "Sudden high velocity or remote geography",
        "Recipient fan-out outside the previous customer profile"
      ],
      "mitigations": [
        "Apply enhanced due diligence to reactivation",
        "Notify through an independent channel and add a cooling period",
        "Use step-up authentication independent of the changed mobile",
        "Apply transaction caps, sequence scoring, and staff audit"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/Scripts/BS_SpeechesView.aspx?Id=826",
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12032"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E01",
      "title": "Mule-account recruitment disguised as employment, commission, or passive income",
      "evidence_level": "AI_EXTENSION",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "PPI", "BANK_TRANSFER"],
      "channels": ["SOCIAL_MEDIA", "JOB_AD", "CHAT"],
      "genai_role": "AI mass-personalizes recruiting, creates synthetic companies and agreements, and coaches candidates in multiple languages.",
      "observables": [
        "Newly active account receives many unrelated inbound credits",
        "Rapid pass-through inconsistent with KYC profile",
        "Shared recruiter, contact, or device",
        "Fixed commission retained with high recipient churn"
      ],
      "mitigations": [
        "Warn customers explicitly about mule-account liability",
        "Verify claimed employment during risk review",
        "Use graph and flow models for fan-in and fan-out",
        "Combine FRI or DIP intelligence with proportionate hold and investigation"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/scripts/AnnualReportPublications.aspx?Id=1436",
        "https://www.cybercrime.gov.in/assets/learning-corner/advisory/pdf/Fraudsters%20sending%20Fake.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E02",
      "title": "Rented or compromised WhatsApp account used as trusted scam infrastructure",
      "evidence_level": "AI_EXTENSION",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "BANK_TRANSFER"],
      "channels": ["META_AD", "FAKE_SITE", "APK", "QR", "WHATSAPP_LINKED_DEVICE"],
      "genai_role": "AI creates ad and chat variants, style-matched messages, synthetic voice notes, and persistent bot operation across a stolen trust network.",
      "observables": [
        "New linked device",
        "Burst messaging or rapid contact expansion",
        "Suspicious APK or referral-pyramid language",
        "Repeated VPAs used across downstream targets"
      ],
      "mitigations": [
        "Confirm and alert on linked-device changes",
        "Explain that the QR grants account access",
        "Revoke suspicious sessions and inspect app reputation",
        "Use messaging velocity and cross-account entity graphs"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/Webform/theme/resources/advisories/Mule%20Whatsapp%20V1.4.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E03",
      "title": "Rapid fan-in and fan-out mule layering across UPI, IMPS, NEFT, and PPI",
      "evidence_level": "AI_EXTENSION",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "IMPS", "NEFT", "PPI", "ATM"],
      "channels": ["ACCOUNT_TO_ACCOUNT", "WALLET", "ATM_CASH_OUT"],
      "genai_role": "AI may orchestrate account selection and recruiting conversations, but defensive simulations must not emit tactical routing or evasion instructions.",
      "observables": [
        "Many unrelated senders and short fund dwell time",
        "High pass-through ratio or burst after first credit",
        "Shared phone, device, IP, or beneficiary",
        "Circular or layered subgraph inconsistent with KYC profile"
      ],
      "mitigations": [
        "Use near-real-time graph and sequence models",
        "Model velocity, value, and dwell time",
        "Fuse FRI and negative-recipient intelligence across institutions",
        "Apply risk-based holds with investigator-readable graph explanations"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/scripts/AnnualReportPublications.aspx?Id=1436",
        "https://www.rbi.org.in/Scripts/PublicationVisionDocuments.aspx?Id=1202",
        "https://doi.org/10.1016/j.eswa.2024.125211"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E04",
      "title": "Digital-for-physical cash conversion using QR as ATM",
      "evidence_level": "AI_EXTENSION",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI"],
      "channels": ["MERCHANT_QR", "P2M", "PHYSICAL_CASH"],
      "genai_role": "Synthetic identity and receipt evidence, merchant discovery, and personalized urgency make a cash-for-UPI request persuasive.",
      "observables": [
        "Payment has no corresponding goods or service",
        "Repeated round-amount credits followed by cash release",
        "Many unrelated payers to one merchant",
        "Source accounts later become disputed"
      ],
      "mitigations": [
        "Prohibit or review cash-for-UPI behavior",
        "Educate merchants about disputed-fund risk",
        "Use MCC and behavior anomaly monitoring",
        "Apply high-risk receipt delays and payer-merchant graph checks"
      ],
      "primary_sources": [
        "https://www.phonepe.com/trust-and-safety/"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E05",
      "title": "Fake investment or trading app deposits routed to Indian mule accounts",
      "evidence_level": "AI_EXPLICIT",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "IMPS", "NEFT"],
      "channels": ["SOCIAL_AD", "SOCIAL_GROUP", "FAKE_APP", "FAKE_WEBSITE"],
      "genai_role": "Deepfake endorsements, synthetic market commentary and testimonials, automated portfolio chat, and fabricated dashboards sustain the funnel.",
      "observables": [
        "Sideloaded or unregistered app",
        "Guaranteed return and beneficiary mismatch",
        "Small inbound credit followed by larger outbound deposits",
        "Many unrelated investors and rapid onward movement"
      ],
      "mitigations": [
        "Verify SEBI registration and app or domain authenticity",
        "Check beneficiary name",
        "Model staged payments and mule graphs",
        "Step up or cool off escalating payments to a risky recipient"
      ],
      "primary_sources": [
        "https://cybercrime.gov.in/pdf/Advisories/ADVISORY%20TAU-ADV-001%20%2822.04.2024%29.pdf"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E06",
      "title": "Unregistered fake lending app with data harvesting and synthetic-image extortion",
      "evidence_level": "AI_EXPLICIT_MORPHED_IMAGERY",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "BANK_TRANSFER", "DIGITAL_LOAN"],
      "channels": ["APP_STORE", "AD", "SMS", "CHAT", "LOAN_APP"],
      "genai_role": "AI targets borrowers, runs support chat, morphs images, personalizes threats, and creates fake lender branding and policies.",
      "observables": [
        "App or lender has no verified regulated relationship",
        "Excessive contacts, storage, or location permissions",
        "Payment goes to a personal or mismatched account",
        "Shared developer, device, or payment graph with harassment bursts"
      ],
      "mitigations": [
        "Verify the lender and regulated entity",
        "Minimize permissions and vet app-store listings",
        "Require direct disbursal and repayment with the regulated entity",
        "Report abuse and graph-link developers and beneficiaries for takedown"
      ],
      "primary_sources": [
        "https://www.cybercrime.gov.in/assets/learning-corner/advisory/pdf/Monthly%20Underground%20Banking%20Report.pdf",
        "https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12382"
      ],
      "implementation_status": "RESEARCHED"
    },
    {
      "id": "E07",
      "title": "Synthetic merchant or collusive merchant onboarding and payment laundering",
      "evidence_level": "AI_EXTENSION",
      "cluster": "MULE_LAUNDERING_FRAUD_INFRASTRUCTURE",
      "rails": ["UPI", "CARDS", "PAYMENT_GATEWAY", "POS"],
      "channels": ["MERCHANT_ONBOARDING", "FAKE_STOREFRONT", "PAYMENT_GATEWAY", "POS", "QR"],
      "genai_role": "AI creates coherent storefronts, catalogs, invoices, reviews, KYC material, and a customer-support facade that can be cloned across applications.",
      "observables": [
        "Young merchant with high early velocity",
        "MCC mismatch or no credible fulfilment",
        "Shared device, document, or bank account across merchants",
        "High disputes with rapid settlement cash-out or circular self-payments"
      ],
      "mitigations": [
        "Strengthen merchant KYC and beneficial-owner checks",
        "Verify issuer-signed documents, website, and fulfilment",
        "Use reserve or settlement controls for high-risk newcomers",
        "Apply cross-merchant graph and chargeback monitoring"
      ],
      "primary_sources": [
        "https://www.rbi.org.in/scripts/PublicationReportDetails.aspx?ID=610",
        "https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=11566"
      ],
      "implementation_status": "RESEARCHED"
    }
  ]
}
