logologo
Search stocks, ETFs, IPOs & more
Quest
arrow
WhatsApp Icon

Capillary cyber fraud: EUR 3m deepfake hit overseas 2026

CAPILLARY

Capillary Technologies India Ltd

CAPILLARY

Ask AI

Ask AI

What Capillary Technologies disclosed to exchanges

Capillary Technologies, a Bengaluru-based customer loyalty and engagement SaaS company, reported a cyber-enabled banking fraud at one of its recently acquired overseas step-down subsidiaries. In a stock exchange filing on Monday, the company said funds of approximately EUR 3.0 million (around Rs 32.7 crore) were fraudulently transferred to unauthorised third-party bank account(s). The company described the incident as a sophisticated attack executed through advanced deepfake techniques.

Capillary said it has initiated legal and operational measures to recover the transferred money. It also stated that it has no evidence, based on currently available information, of any compromise of customer data, employee data, or its technology infrastructure. The company added that business operations are continuing without any material disruption, and the incident does not require changes to annual or long-term goals at this stage.

How the fraud was executed: voice cloning and impersonation

According to the filing, the fraud used “very advanced deep-fake methodologies” including voice cloning, signature forging, and social engineering. The attackers allegedly impersonated the company’s key managerial personnel (KMPs) and used that impersonation to authorise the transfers.

While Capillary did not disclose the precise sequence of communications or which bank(s) were involved, it framed the event as a cyber-enabled banking fraud rather than a breach of its product systems. That distinction matters for investors tracking operational risk at SaaS companies, where incidents can range from account-level fraud to technology infrastructure compromise.

Recovery actions: EUR 0.45 million recovered, more funds traced

Capillary said it took immediate action after discovering the incident and recovered EUR 0.45 million (around Rs 4.9 crore). It also said that additional funds have been traced and the related accounts have been placed on hold by respective banks, reducing the amount at risk.

However, the company noted that the exact amount currently on hold is yet to be determined. The matter remains under investigation, and the company said it will provide updates on any material developments in line with SEBI Listing Regulations.

Coordination with banks, cybercrime authorities, and law enforcement

The company said recovery efforts are being pursued in coordination with relevant law enforcement and cybercrime authorities, concerned banks, and other stakeholders. These steps typically include urgent recall requests, account freezing, and formal complaints to enable banks and authorities to move quickly across jurisdictions.

Capillary’s filing also highlights that the subsidiary is overseas and is a “step-down” entity, implying additional complexity in coordinating across legal systems and banking networks. The company did not provide the subsidiary’s name or location in the disclosure.

Why the disclosure came after the incident

Capillary said the incident occurred just prior to the weekend. It stated that its immediate priority was to safeguard the funds by coordinating with banks and investigating authorities to maximise the possibility of recovery. This operational response, the company said, delayed its disclosure to the stock exchanges.

The company’s communication is consistent with a typical incident-response pattern where immediate containment and recovery actions run in parallel with internal escalation and regulatory disclosure steps.

Insurance: cyber and crime policy notified, coverage being assessed

Capillary said the affected subsidiary is covered under a cyber and crime insurance policy, and the insurer has been notified. The company is currently assessing the extent of insurance coverage and the eventual financial impact.

At this stage, Capillary has not quantified any net loss after recoveries and possible insurance proceeds. The filing also does not specify deductibles, exclusions, or timelines for claims resolution.

No evidence of customer data compromise, operations continue

A key point in the filing is the company’s statement that there is no evidence of compromise of customer data, employee data, or its technology infrastructure. Capillary also said its business operations continue without any material disruption.

This framing suggests the incident was centred on payment authorisation and banking processes rather than a breach of Capillary’s SaaS platform. Still, investors typically watch for follow-up disclosures on process changes, additional controls, and any confirmation from investigators.

Key facts at a glance

ItemDetail (as disclosed)
Nature of incidentCyber-enabled banking fraud using deepfake techniques
Methods citedVoice cloning, forged signatures, social engineering
Entity impactedRecently acquired overseas step-down subsidiary
Amount transferredApprox. EUR 3.0 million (around Rs 32.7 crore)
Amount recoveredEUR 0.45 million (around Rs 4.9 crore)
Additional fundsTraced and bank accounts placed on hold (amount not yet determined)
Data impactNo evidence of customer/employee data compromise
Operations impactNo material disruption reported
InsuranceCyber and crime insurance policy notified
Timing notedIncident occurred just before the weekend; disclosure made after action to secure funds

Stock snapshot and valuation context from the shared data

The provided market snapshot lists Capillary Technologies India Ltd with a market cap of Rs 5,463 crore and a current price near Rs 689 (CMP also shown as Rs 688.75 in the table). It also shows High/Low of Rs 799 / Rs 560, Stock P/E of about 386, and dividend yield of 0.00%.

The same snapshot lists quarterly profit and return metrics, including NP (quarter) Rs 1.03 crore, quarterly profit variation 359.22%, and ROCE 2.88%. These figures provide context on how the market is valuing the company, though the disclosure itself does not quantify the net financial impact of the incident.

Market impact: what investors can and cannot infer right now

The company has not disclosed any immediate change to guidance or long-term targets and explicitly said it does not see the incident requiring modification of annual or long-term goals at this point. It has also not disclosed whether any additional internal controls, payment approval workflows, or banking mandates are being changed, beyond describing recovery and investigation actions.

Given the amounts involved and the partial recovery already stated, the key market question becomes the eventual outcome on the unrecovered portion, the amount frozen, and the extent to which insurance offsets the impact. Until those numbers are disclosed, any estimate of net loss would be incomplete.

Why the incident matters: deepfake fraud risk in corporate finance

The case underscores a growing operational risk for companies that rely on remote approvals and cross-border treasury movements. Deepfake-driven impersonation, as described by Capillary, can target human authorisation steps rather than technology systems, making traditional cybersecurity controls only part of the solution.

It also raises the importance of strong verification protocols for fund transfers, especially where KMP approvals are involved. Capillary’s note that there is no evidence of technology infrastructure compromise suggests the attack exploited trust and process vulnerabilities rather than software vulnerabilities.

What to watch next

Capillary said the matter remains under investigation and that it will provide updates on material developments. Investors will watch for future disclosures on the amount ultimately recovered, the amount frozen and released, and the final position after insurance.

Another point to monitor is whether the company introduces enhanced verification steps for authorisations at subsidiaries, particularly for overseas entities and newly acquired units.

Conclusion

Capillary Technologies has disclosed a deepfake-led banking fraud at an overseas step-down subsidiary involving about EUR 3 million, with EUR 0.45 million already recovered and additional funds traced and frozen. The company says operations continue without material disruption and that it sees no evidence of data compromise. The next concrete updates are expected around recoveries, the amount on hold, and the outcome of the insurance assessment as the investigation progresses.

Frequently Asked Questions

Capillary reported that an overseas step-down subsidiary suffered a cyber-enabled banking fraud, leading to a fraudulent transfer of about EUR 3 million to unauthorised third-party accounts.
The company said attackers used deepfake techniques including voice cloning, forged signatures, and social engineering to impersonate key managerial personnel and authorise transfers.
Capillary said it recovered EUR 0.45 million after taking immediate action upon discovering the incident.
No. The company stated there is no evidence, based on currently available information, of any compromise of customer data, employee data, or its technology infrastructure.
Yes. Capillary said the subsidiary is covered under a cyber and crime insurance policy, the insurer has been notified, and coverage and financial impact are being assessed.

Did your stocks survive the war?

See what broke. See what stood.

Live Q1 Earnings Tracker