In partnership with

Summary

Between April 2024 and April 2026, Bombay Stock Exchange (BSE Ltd), India's oldest stock exchange, issued repeated public advisories warning investors about deepfake videos that falsely showed its Managing Director & CEO, Sundararaman Ramamurthy, handing out stock tips and pushing viewers into private WhatsApp and Telegram "investment" groups. The exchange described the April 2026 wave as the "fourth such incident in the past four months," on top of the original 2024 wave, a sustained impersonation campaign, not a one-off attack.

This is a different species of deepfake fraud from the classic CFO-on-a-Zoom-call fraud. There was no single wire transfer and no confirmed corporate victim inside BSE. The attackers stole something harder to price: the institutional credibility of a national exchange and its chief executive, using it as bait for a mass-market investment scam aimed at retail investors.

Key Takeaway: Your organisation can be the instrument of a fraud without ever being its victim. When an attacker clones your CEO to endorse a scam, the losses land on your customers, investors, and brand and you inherit the cleanup, the regulatory inspection, and the trust deficit, with no recoverable wire transfer to freeze.

Incident Overview

The target of the impersonation: BSE Ltd is India's oldest stock exchange and among the world's largest by number of listed companies. Its endorsement, real or fake carries enormous weight with India's fast-expanding base of retail investors, many of them first-timers. That authority is exactly what the attackers monetised.

The man in the video: Sundararaman Ramamurthy is a market veteran with nearly two decades at the National Stock Exchange (NSE), where he was among the early architects from 1995 to 2014, holding senior roles including SVP. Before joining BSE, he served as Chief Operating Officer–India at Bank of America, overseeing technology implementation, compliance, and stakeholder management.
As a well-known, authoritative figure with extensive public footage, including interviews, conference appearances, and market commentary, Ramamurthy represents an ideal deepfake target, because that publicly available material can be used as training data for synthetic-media attacks.

What the fake claimed: The videos showed "Ramamurthy" recommending specific stocks for 2026 and promising extraordinary returns, with claims that viewers would become multi-millionaires, one version explicitly stated "you will have ₹8 million by 2027." Every clip drove to the same destination: a WhatsApp or Telegram channel for "exclusive" tips. That group is the scam engine, where victims are groomed, shown fake profits, and eventually asked to deposit money they never recover.

A pattern, not an incident: BSE was neither first nor alone. In April 2024, both BSE and the National Stock Exchange warned about deepfakes of their chiefs, NSE's MD & CEO Ashishkumar Chauhan was targeted in April and again in June 2024. The BSE campaign then re-erupted through 2026, with the same footage resurfacing repeatedly despite takedown efforts, the defining feature of the case, and its central lesson.

Fact

Details

Impersonated organisation

BSE Ltd (formerly Bombay Stock Exchange)

Impersonated individual

Sundararaman Ramamurthy, MD & CEO, BSE

Attack type

Deepfake video impersonation → mass investment-scam funnel

Primary lure

"Guaranteed"/super-normal returns, join WhatsApp/Telegram groups

Documented advisories

Apr 2024, 12 Jan 2026, 8 Mar 2026, 24 Apr 2026

Confirmed direct loss to BSE

Not publicly disclosed

Verified victim count

Not publicly disclosed

Reported by

BSE advisories, Reuters, Hindustantimes

How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads

For its first CTV campaign, Jennifer Aniston’s DTC haircare brand LolaVie had a few non-negotiables. The campaign had to be simple. It had to demonstrate measurable impact. And it had to be full-funnel.

LolaVie used Roku Ads Manager to test and optimize creatives — reaching millions of potential customers at all stages of their purchase journeys. Roku Ads Manager helped the brand convey LolaVie’s playful voice while helping drive omnichannel sales across both ecommerce and retail touchpoints.

The campaign included an Action Ad overlay that let viewers shop directly from their TVs by clicking OK on their Roku remote. This guided them to the website to buy LolaVie products.

Discover how Roku Ads Manager helped LolaVie drive big sales and customer growth with self-serve TV ads.

The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.

Attack Timeline and Methodology

Reconstructed from BSE's public advisories and corroborated by Reuters, Business Standard, and ANI. Private-side mechanics (who built the videos, how groups were run) remain under investigation, the public timeline is well documented.

Date

Event

Detail

~Apr 2024

First BSE CEO deepfake surfaces

A morphed clip appears showing Ramamurthy giving investment advice, NSE had warned of similar fakes of its CEO days earlier.

Apr 2024

BSE escalates to authorities

Ramamurthy tells Reuters BSE has approached SEBI and is filing a police complaint against unknown persons behind the videos.

Apr–Jun 2024

Sector-wide wave

NSE's CEO is impersonated again in June 2024, confirming exchange chiefs as a repeat target class.

Jan 2026

Advisory #1 (2026 wave)

BSE warns of a fake pushing 2026 tips and a WhatsApp channel, including the "₹8 million by 2027" claim, pursues takedowns and legal action.

Mar 2026

Advisory #2 — "resurfaced"

A high-priority advisory notes the same fake has "resurfaced multiple times" despite scrubbing.

Apr 2026

Advisory #3 — "4th incident"

BSE calls it the fourth such incident in four months, citing its finfluencer-awareness campaign under SEBI.

How the Funnel Works?

Simpler and cheaper than a live multi-person Zoom deepfake, which is exactly why it scales.

  • Harvest public footage: Ramamurthy's interviews and events are scraped as training data. No insider access needed.

  • Generate the impersonation: Face and voice are synthesised into a short, shareable clip, optimised for feeds and forwarding, not a live call.

  • Wrap it in authority: The BSE name and CEO title borrow the exchange's credibility wholesale.

  • Drive to a closed channel: Every clip funnels viewers to a WhatsApp/Telegram group, the actual scam engine.

  • Exploit resurfacing: Because the payload is a file, not a live event, it re-uploads endlessly. Takedowns treat symptoms, copies persist.

Why this format is so hard to Kill?

A live deepfake call ends when the call ends. A deepfake video is infinitely reproducible, re-uploaded across accounts and platforms faster than any legal or takedown process can remove it. That is precisely what BSE reported through 2026.

Financial Impact Analysis

Honesty matters more than a dramatic number here. BSE has not disclosed a direct financial loss, and there is no publicly verified figure for what retail investors lost specifically to these videos. Inventing one would be worse than useless. What we can responsibly frame is the cost structure and the scale of the category.

Cost Category

Assessment

Direct loss to BSE

None publicly confirmed, BSE is the impersonated party, not the payer

Retail investor losses (this campaign)

Not publicly quantified

Brand & trust cost to BSE

Material but unpriced, repeated advisories, active legal effort, awareness spend

Remediation cost

Legal action, SEBI coordination, repeated takedowns, nationwide awareness campaign

Category context

GenAI-enabled fraud losses (US): $12.3B (2023) → $40B (2027), ~32% CAGR (Deloitte)

Where does the money actually leak?
In impersonation-funnel scams the loss doesn't sit on the impersonated institution's balance sheet, it is distributed across thousands of retail victims who join the group, are shown doctored gains, and deposit funds into mule accounts. The exchange absorbs the reputational liability, the public absorbs the financial one.

The asymmetry that draws attackers:
A short deepfake clip costs almost nothing, high-quality generation tools now sit below the price of a streaming subscription while the credibility it borrows (a national exchange, a named CEO) would take a legitimate business years to build. That cost asymmetry, not any single technical breakthrough, is the engine of this fraud class.

Control Failure Analysis

The uncomfortable point: BSE did most things right, and the attack still recurred for two years. The failures are systemic in the ecosystem not simply one organisation's negligence.

1. Takedown ≠ removal: BSE reported the same fake "resurfacing multiple times" despite scrubbing. Removal is reactive and per-copy, a reproducible file defeats it structurally. This is the single most important failure in the case.

2. No pre-emptive provenance signal: There was no widely deployed way (content authentication, verified-source watermarking, platform provenance) for an ordinary investor to instantly confirm whether a "BSE CEO" video was genuine. Without that, viewers fall back on "it looks real" the exact judgment deepfakes defeat.

3. Platform incentives lag: The videos spread on platforms whose detection-and-removal speed didn't match re-upload speed. Legal templates exist in India, but enforcement runs on a slower clock than virality.

4. The trust vector itself: The attack weaponised the very thing exchanges depend on public trust in their leadership's word. There is no patch for institutional credibility, it can only be defended with pre-registered, verifiable channels the public is trained to check.

Red Flags and Warning Signs

Because the victims here are the investing public, these are red flags to teach customers, employees, and family, not just a treasury team. Every one appeared in the BSE fakes.

Red Flag

Why It Matters

A named executive giving stock tips at all

Exchange officials are prohibited from recommending stocks. The premise itself is the tell.

Guaranteed or "super-normal" returns

No legitimate participant promises fixed extraordinary profits. Certainty is the signature of a scam.

A specific rupee promise

"₹8 million by 2027" is engineered greed-bait, precise, aspirational, impossible to guarantee.

"Join this WhatsApp/Telegram group"

Regulated institutions don't run private tip groups. The closed channel is the scam engine.

Urgency to act on 2026 picks now

Time pressure short-circuits the pause where a victim would verify.

Video as the "proof"

Seeing the CEO say it is the false comfort deepfakes exploit. Video is no longer evidence of authenticity.

Resurfacing / multiple versions

The same "official" clip across random accounts is itself a fraud signal.

The one-line defence to teach everyone: If a video routes you to a private group and promises guaranteed returns, it is fake, regardless of whose face is on it. Verify only through the institution's official website and SEBI-registered intermediaries.

Lessons Learned & Root Cause

Root Cause

The case sits at the intersection of two forces: (1) the commoditisation of convincing video/voice synthesis, letting anyone borrow a trusted figure's likeness from public footage at near-zero cost and (2) the absence of a provenance layer in our information ecosystem, so authenticity can't be checked at the speed content spreads. The first makes the attack cheap, the second makes it durable. Takedown-based defence addresses neither.

Key Lessons

  • Impersonation risk is now core executive protection: Any leader with public footage is a target, reputation defence belongs in the security programme, not just PR.

  • Pre-register and publicise your real channels, loudly and repeatedly: BSE's correct move was to state plainly that no official ever gives tips or runs groups. Say it before an incident, and keep saying it.

  • Assume resurfacing: One advisory isn't closure. Build a standing rapid-response playbook: monitoring, a template advisory, platform-escalation contacts, legal on standby.

  • Push for provenance, not just takedown: Content-authentication and verified-source signals scale where per-copy removal cannot.

  • Educate the audience that gets defrauded: The victims are retail investors, so awareness campaigns (like BSE's finfluencer effort under SEBI) are frontline controls, not marketing.

  • Preparedness is still the exception: In Deloitte's executive survey, only about a third of organisations had established anti-deepfake protocols, and roughly six in ten had none, meaning most institutions would meet a BSE-style attack with no playbook at all.

Conclusion

The BSE deepfake is a quieter story than a $499K wire heist, and in some ways more unsettling. There was no dramatic recovery, no frozen account, no single victim to interview, just a fabricated video of a CEO who never gave a stock tip, resurfacing again and again for two years, quietly steering trusting investors toward scam channels while the institution issued advisory after advisory.

It marks the maturation of a distinct threat: deepfakes as a mass-market trust-laundering tool. The attacker's product isn't a forged transaction, it's borrowed credibility, sold at scale. And the defence can't be a one-time takedown, it has to be durable provenance, relentless public communication, and the assumption that every trusted face will eventually appear in a fake.

The finance leaders who internalise this case won't ask "could someone drain our account with a deepfake?" They'll ask the harder question: "What happens to everyone who trusts us when our CEO's face is used to defraud them and are we ready for that video to come back a fourth time?"

About Deepfake Finance

It is a free weekly briefing you can read in under 10 minutes - covering how deepfakes are actually built, real deepfake fraud cases studies, honest detection tool reviews, and prevention protocols that work. Written independently. 1,000+ cybersecurity professionals, founders, and IT managers across SMBs already read it. Feel free to forward it to your friends who might benefit from this newsletter.

Have you seen something that didn't feel right? or Got questions you don't know who to ask? Whether you've encountered a suspected deepfake, want to understand your exposure, or just want to talk through what's happening in this space, I'm setting aside time for free 30-minute calls.