Capillary cyber fraud: EUR 3m deepfake hit overseas 2026
Capillary Technologies India Ltd
CAPILLARY
Ask AI
What Capillary Technologies disclosed to exchanges
Capillary Technologies, a Bengaluru-based customer loyalty and engagement SaaS company, reported a cyber-enabled banking fraud at one of its recently acquired overseas step-down subsidiaries. In a stock exchange filing on Monday, the company said funds of approximately EUR 3.0 million (around Rs 32.7 crore) were fraudulently transferred to unauthorised third-party bank account(s). The company described the incident as a sophisticated attack executed through advanced deepfake techniques.
Capillary said it has initiated legal and operational measures to recover the transferred money. It also stated that it has no evidence, based on currently available information, of any compromise of customer data, employee data, or its technology infrastructure. The company added that business operations are continuing without any material disruption, and the incident does not require changes to annual or long-term goals at this stage.
How the fraud was executed: voice cloning and impersonation
According to the filing, the fraud used “very advanced deep-fake methodologies” including voice cloning, signature forging, and social engineering. The attackers allegedly impersonated the company’s key managerial personnel (KMPs) and used that impersonation to authorise the transfers.
While Capillary did not disclose the precise sequence of communications or which bank(s) were involved, it framed the event as a cyber-enabled banking fraud rather than a breach of its product systems. That distinction matters for investors tracking operational risk at SaaS companies, where incidents can range from account-level fraud to technology infrastructure compromise.
Recovery actions: EUR 0.45 million recovered, more funds traced
Capillary said it took immediate action after discovering the incident and recovered EUR 0.45 million (around Rs 4.9 crore). It also said that additional funds have been traced and the related accounts have been placed on hold by respective banks, reducing the amount at risk.
However, the company noted that the exact amount currently on hold is yet to be determined. The matter remains under investigation, and the company said it will provide updates on any material developments in line with SEBI Listing Regulations.
Coordination with banks, cybercrime authorities, and law enforcement
The company said recovery efforts are being pursued in coordination with relevant law enforcement and cybercrime authorities, concerned banks, and other stakeholders. These steps typically include urgent recall requests, account freezing, and formal complaints to enable banks and authorities to move quickly across jurisdictions.
Capillary’s filing also highlights that the subsidiary is overseas and is a “step-down” entity, implying additional complexity in coordinating across legal systems and banking networks. The company did not provide the subsidiary’s name or location in the disclosure.
Why the disclosure came after the incident
Capillary said the incident occurred just prior to the weekend. It stated that its immediate priority was to safeguard the funds by coordinating with banks and investigating authorities to maximise the possibility of recovery. This operational response, the company said, delayed its disclosure to the stock exchanges.
The company’s communication is consistent with a typical incident-response pattern where immediate containment and recovery actions run in parallel with internal escalation and regulatory disclosure steps.
Insurance: cyber and crime policy notified, coverage being assessed
Capillary said the affected subsidiary is covered under a cyber and crime insurance policy, and the insurer has been notified. The company is currently assessing the extent of insurance coverage and the eventual financial impact.
At this stage, Capillary has not quantified any net loss after recoveries and possible insurance proceeds. The filing also does not specify deductibles, exclusions, or timelines for claims resolution.
No evidence of customer data compromise, operations continue
A key point in the filing is the company’s statement that there is no evidence of compromise of customer data, employee data, or its technology infrastructure. Capillary also said its business operations continue without any material disruption.
This framing suggests the incident was centred on payment authorisation and banking processes rather than a breach of Capillary’s SaaS platform. Still, investors typically watch for follow-up disclosures on process changes, additional controls, and any confirmation from investigators.
Key facts at a glance
Stock snapshot and valuation context from the shared data
The provided market snapshot lists Capillary Technologies India Ltd with a market cap of Rs 5,463 crore and a current price near Rs 689 (CMP also shown as Rs 688.75 in the table). It also shows High/Low of Rs 799 / Rs 560, Stock P/E of about 386, and dividend yield of 0.00%.
The same snapshot lists quarterly profit and return metrics, including NP (quarter) Rs 1.03 crore, quarterly profit variation 359.22%, and ROCE 2.88%. These figures provide context on how the market is valuing the company, though the disclosure itself does not quantify the net financial impact of the incident.
Market impact: what investors can and cannot infer right now
The company has not disclosed any immediate change to guidance or long-term targets and explicitly said it does not see the incident requiring modification of annual or long-term goals at this point. It has also not disclosed whether any additional internal controls, payment approval workflows, or banking mandates are being changed, beyond describing recovery and investigation actions.
Given the amounts involved and the partial recovery already stated, the key market question becomes the eventual outcome on the unrecovered portion, the amount frozen, and the extent to which insurance offsets the impact. Until those numbers are disclosed, any estimate of net loss would be incomplete.
Why the incident matters: deepfake fraud risk in corporate finance
The case underscores a growing operational risk for companies that rely on remote approvals and cross-border treasury movements. Deepfake-driven impersonation, as described by Capillary, can target human authorisation steps rather than technology systems, making traditional cybersecurity controls only part of the solution.
It also raises the importance of strong verification protocols for fund transfers, especially where KMP approvals are involved. Capillary’s note that there is no evidence of technology infrastructure compromise suggests the attack exploited trust and process vulnerabilities rather than software vulnerabilities.
What to watch next
Capillary said the matter remains under investigation and that it will provide updates on material developments. Investors will watch for future disclosures on the amount ultimately recovered, the amount frozen and released, and the final position after insurance.
Another point to monitor is whether the company introduces enhanced verification steps for authorisations at subsidiaries, particularly for overseas entities and newly acquired units.
Conclusion
Capillary Technologies has disclosed a deepfake-led banking fraud at an overseas step-down subsidiary involving about EUR 3 million, with EUR 0.45 million already recovered and additional funds traced and frozen. The company says operations continue without material disruption and that it sees no evidence of data compromise. The next concrete updates are expected around recoveries, the amount on hold, and the outcome of the insurance assessment as the investigation progresses.
Frequently Asked Questions
Did your stocks survive the war?
See what broke. See what stood.
Live Q1 Earnings Tracker