Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Capillary Technologies, a customer-loyalty software company based in Bengaluru and listed on India's stock exchanges, disclosed in a regulatory filing that one of its recently acquired overseas subsidiaries was tricked into wiring roughly 3 million euros to accounts controlled by criminals. The instruction that moved the money did not come from a stranger. It came, to all appearances, from the company's own senior executives, whose voices had been cloned and whose signatures had been forged.
The company says it has clawed back about 450,000 euros so far and that no customer or employee data was touched. What is worth understanding here is not the accounting. It is how a few seconds of an executive's recorded voice can now be enough to override a finance team's caution.
In a filing made just after the start of July 2026, Capillary described a cyber-enabled banking fraud at a step-down subsidiary, a company it controls through another subsidiary rather than directly. Attackers used what the company called advanced techniques, including voice cloning, forged signatures, and social engineering, to impersonate its key managerial personnel (the senior executives who can authorize spending) and approve transfers to third-party bank accounts. Roughly 3 million euros, about 32.7 crore rupees, left the business before anyone caught it.
The mechanism is the ordinary machinery of corporate payments turned against itself. Voice cloning is the trick of feeding a short sample of someone's speech into an AI model that can then say anything in their voice, convincingly enough to pass on a phone call. Pair that cloned voice with a forged signature on a payment document and a plausible story about an urgent transfer, and you have an instruction that looks and sounds authorized at every step a busy finance officer would check. Capillary has not made public the exact channel the attackers used, so the fine detail of the approach remains unconfirmed. What the company did disclose points to the softest spot in its defenses: the fraud struck a subsidiary it had only recently bought.
The concrete loss is a listed company down several million euros, most of it not yet recovered, reported to regulators and handed to insurers. The part that should travel to your own organization is where the attack landed. A newly acquired subsidiary is a near-perfect target: its finance staff may never have heard the parent's executives speak, the approval workflows are often only half-integrated, and everyone is under pressure to prove they can move quickly for their new owners. If your company grows by acquisition, the weeks after a deal closes are exactly when a cloned-voice instruction is hardest to challenge, because the people receiving it have no baseline for what the real executive sounds like. The wider shift is that this fraud does not exploit a software flaw, so there is no patch to apply. It exploits trust and the payment-approval process, and AI has made the raw material cheap. A few seconds of an executive speaking on a webinar, an earnings call, or a conference panel is enough to build the voice. What once needed a skilled human impersonator now takes a public clip and a model anyone can rent.
Capillary's loss is a clean illustration of a fraud that needs no malware, no stolen password, and no software vulnerability. It needs a recording of a voice, a forged signature, and a finance team with no reason to doubt either. Bring one question to your next security meeting: if an executive called our accounts-payable team tomorrow with an urgent wire request, in a voice everyone recognized, what in our process would stop the money before it left, and would that same safeguard also hold at the subsidiary we bought last quarter?


