How to Protect Your Phone and Social Media From Deepfakes

AI deepfakes can now create convincing fake videos, images and cloned voices that appear to show real people saying or doing things they never did. Strong passwords, two-factor authentication, privacy controls and careful verification can reduce the risk of becoming a victim.

Why AI deepfakes are becoming a bigger online risk

Deepfakes are synthetic videos, images or audio created or manipulated using artificial intelligence. They can be used for entertainment and legitimate creative work, but criminals can also use the technology for impersonation, fraud, misinformation and harassment.

CERT-In has classified deepfakes as a high-risk threat because increasingly realistic synthetic media can contribute to fraud, social engineering, reputational damage and financial loss. Its advisory specifically recommends that individuals and organisations learn to identify and respond to deepfake threats.

The risk is not limited to celebrities or politicians. A person’s publicly available photographs, videos and voice recordings can potentially be misused to create misleading content. A fake video may show someone promoting an investment scheme, endorsing a product or making a statement that they never actually made.

For ordinary social media users, the safest approach is not to assume that a video is genuine simply because the face, voice or account looks familiar.

How to spot a possible AI deepfake

There is no single visual clue that can reliably identify every deepfake. AI-generated content is improving quickly, and obvious errors such as distorted faces or unnatural blinking are not always present.

Instead, look for several warning signs together.

Check whether the person’s mouth movements match the words naturally. Pay attention to unusual facial expressions, inconsistent lighting, strange shadows or sudden changes in image quality. In an audio clip, listen for unnatural pauses, unusual pronunciation or a voice that sounds slightly different from the person’s normal speech.

Context is equally important.

If a video claims that a famous person is recommending an investment, lottery, cryptocurrency scheme or financial product, do not treat the video itself as proof. Search for the same announcement through the person’s verified account or an established news organisation.

MeitY has specifically identified examples such as fake celebrity endorsements, cloned voices of family members or officials demanding urgent payments, and fabricated videos of public figures as forms of potentially deceptive synthetic content.

Do not trust a familiar face or cloned voice

One of the biggest mistakes people make with deepfake scams is assuming that familiar appearance or voice equals authenticity.

A scammer can use publicly available photographs to create a fake profile and combine them with AI-generated images or video. Voice cloning can create another layer of deception, particularly when the scammer contacts someone by phone or messaging app.

Imagine receiving a video call that appears to come from a relative asking for money urgently. The face and voice may appear genuine, but that does not automatically prove that the person is actually on the call.

If the request involves money, passwords, OTPs, bank details or urgent action, verify it through a separate communication channel. Call the person using a number you already have rather than replying to the suspicious message or calling a number provided by the sender.

This simple second-check process can prevent many impersonation scams.

Protect your phone with a strong screen lock

Your phone contains much more than photographs and messages. It may provide access to email, banking applications, social media accounts, cloud storage and authentication services.

Start with a strong device password or PIN. Use biometric authentication where available, but keep a secure passcode as the primary backup.

Avoid using predictable PINs such as birthdays, 1234 or repeated numbers. Do not share your device passcode casually, even with people who claim they need temporary access.

The Indian Cyber Crime Coordination Centre’s online safety guidance recommends protecting communication devices with passwords, PINs, patterns or biometric authentication and installing applications only from trusted sources.

Also keep your phone’s operating system and applications updated. Security updates can address vulnerabilities that attackers may otherwise exploit.

Turn on two-factor authentication everywhere possible

A password alone should not be the only barrier protecting an important social media account.

Enable two-factor authentication, commonly called 2FA, for Instagram, Facebook, WhatsApp, email and other accounts that support it. Depending on the service, this may involve an authenticator app, security key or another verification method.

Two-factor authentication is particularly important for email because an attacker who gains access to your email account may be able to reset passwords for other services.

Use a different password for important accounts. A password manager can help generate and store unique passwords instead of forcing you to remember the same password everywhere.

If a social media account is compromised, an attacker may use the account’s existing trust to distribute fake videos, request money from contacts or send malicious links.

Review Instagram, Facebook and WhatsApp privacy settings

Your public social media profile can reveal more information than you realise.

Review who can see your photographs, stories, contact information, friend list and other personal details. Consider limiting sensitive information to people you actually know.

The National Cyber Crime Reporting Portal advises users to select appropriate privacy settings and content-sharing filters, be selective when accepting friend requests and remain cautious about fake social media accounts.

Also review old public posts. Photographs and videos posted years ago can remain accessible even after your interests or circumstances have changed.

You do not need to delete every photograph or video. The goal is to reduce unnecessary public exposure of information that could be used for impersonation.

Be careful during video calls and voice messages

Video calls can feel more trustworthy than text messages, but they are not automatically safe.

The Indian Cyber Crime Reporting Portal warns that video chats can be recorded by the person on the other side and later shared on social media or websites. It also advises users to be cautious when accepting chat requests from strangers.

Avoid sharing sensitive personal information, documents, passwords or financial details during unexpected calls.

If someone suddenly asks for money or confidential information, end the call and contact them separately. If the request supposedly comes from a company, bank or government department, use the organisation’s official website or published contact number rather than the number supplied by the caller.

Verify videos before sharing them

A fake video becomes more dangerous when it is repeatedly forwarded.

Before sharing a shocking clip, check where it originally came from. Look for the earliest available upload, the account that posted it and whether credible news organisations have independently reported the claim.

Reverse image search can sometimes help identify older photographs or videos that have been reused in a new context. Searching a distinctive sentence from the video or checking the person’s verified social media account can also reveal whether the claim has been denied or debunked.

Do not assume that a high number of views means that a video is genuine. Viral content can spread before anyone has properly checked it.

The same rule applies to AI-generated audio. A voice note that sounds like a friend, relative, manager or public official should still be verified when it contains an unusual request.

Watch for celebrity and investment deepfake scams

Deepfake scams often exploit trust in well-known people.

A fake video may show a celebrity apparently recommending a trading platform, investment opportunity, health product or financial service. Meta has described this as celeb-bait, where scammers misuse public figures’ images or identities to encourage people to interact with fraudulent offers.

Meta said in March 2026 that it had removed more than 159 million scam advertisements globally during 2025 and more than 12.1 million scam-related ad pieces in India. It also said it had disabled 10.9 million Facebook and Instagram accounts associated with criminal scam centres.

These numbers do not mean that every celebrity advertisement is fraudulent. They show why users should independently verify financial or commercial claims before providing money or personal information.

If a video promises guaranteed returns, asks for an urgent payment or directs you to an unfamiliar website, stop before entering any information.

What to do if someone creates a fake account using your identity

If you discover an account pretending to be you, save evidence before reporting it.

Take screenshots showing the account name, profile URL, photographs, messages and any fraudulent posts. Record the date and time if possible.

Then report the impersonating account through the platform’s reporting system.

The National Cyber Crime Reporting Portal also provides links for reporting illegal activity directly to major social media intermediaries, including Facebook, Instagram, X, Telegram, WhatsApp and YouTube.

If the impersonation involves fraud, threats, harassment, financial loss or another cybercrime, consider filing a complaint through the National Cyber Crime Reporting Portal.

The portal accepts complaints involving online and social media crimes, mobile crimes, hacking, financial fraud and other categories of cybercrime.

What to do if you lose money to a deepfake scam

Act quickly if money has already been transferred.

For cyber financial fraud in India, the National Cyber Crime Reporting Portal advises immediate reporting through the 1930 helpline. The helpline is available for immediate reporting of financial cyber fraud.

Also contact your bank or payment provider immediately and ask about available measures to secure the transaction or account.

Keep screenshots, transaction details, phone numbers, social media URLs, emails, messages and other evidence. Do not delete conversations that could help investigators understand what happened.

If your social media account has also been compromised, change the password from a trusted device, revoke unfamiliar sessions and enable two-factor authentication.

A simple deepfake safety checklist

You do not need advanced technical knowledge to improve your protection.

Start by securing the device itself, then protect the accounts connected to it. Review privacy settings, reduce unnecessary public information and become more cautious about unexpected requests.

Before trusting a suspicious video, ask three questions: Who originally posted it? Can the claim be independently verified? What does the sender want me to do?

If the answer involves sending money, revealing an OTP, installing an unknown application or clicking an unfamiliar link, stop and verify first.

Platforms are also introducing additional protections. Meta announced new anti-scam tools in 2026, including WhatsApp warnings for suspicious device-linking requests, Facebook warnings for some suspicious friend requests and expanded scam detection in Messenger.

These tools can help, but they should complement rather than replace basic digital safety habits.

Key Takeaways

  • Do not assume that a familiar face, voice or verified-looking profile proves that a video is genuine.
  • Use strong device security, unique passwords, two-factor authentication and restrictive social media privacy settings.
  • Verify unexpected requests for money or sensitive information through a separate trusted communication channel.
  • In India, report cybercrime through the National Cyber Crime Reporting Portal, and report financial cyber fraud immediately through 1930.

FAQs

Can AI deepfakes be detected just by looking at a video?

Not reliably. Some deepfakes contain visible or audio inconsistencies, but increasingly sophisticated synthetic media may look convincing. Check the source, context and claim rather than relying on one visual clue.

Can someone create a deepfake using my social media photos?

Public photographs and videos can potentially be misused to create misleading or impersonating content. Limiting unnecessary public information and reviewing privacy settings can reduce exposure.

What should I do if someone creates a fake Instagram or Facebook account using my name?

Save screenshots and the account URL, report the account through the platform’s impersonation or abuse reporting system and consider filing a complaint through the National Cyber Crime Reporting Portal if the activity involves fraud, threats, harassment or another cybercrime.

What is the cybercrime helpline number in India?

For immediate reporting of cyber financial fraud, call 1930. Cybercrime complaints can also be filed through the National Cyber Crime Reporting Portal at cybercrime.gov.in.

(AI deepfake safety, how to detect deepfake videos, deepfake scams in India, social media safety tips, protect phone from scams, Instagram security tips, Facebook security tips, WhatsApp safety tips, AI voice cloning scams, cybercrime reporting India)

popup