AI fuels low-value cybercrimes, use of 'salami slicing'
The rise of low-value cybercrimes is alarming, as scammers increasingly focus on individuals rather than systems. Driven by AI and the digital economy, tactics like 'salami slicing' have become prevalent. Across India, fake utility scams and entic...

A salami slicing strategy refers to a series of incremental steps that are individually too small to trigger a strong response.
“Many times, fraudsters attempt to adopt a “salami slicing” approach. So, even though individual financial fraud is not of large value, it is carried out at scale,” said Atul Gupta, partner, KPMG, who also leads cyber security services.
Among the most widespread frauds nowadays is the fake electricity or gas supply scam, with perpetrators impersonating energy providers and threatening to shut off the power or gas supply unless they are paid immediately. “These scams are currently prevalent in the country and normally entail very insignificant amounts,” said Gupta.
Other common frauds include fake investment offers, account takeovers, spoofed calls, fraudulent payment requests and AI-generated voice or video impersonation, according to experts.
In 2025, 35% of the cases accounted for 76% of the overall money lost in cybercrimes in India, showed Union home affairs ministry data.
“This gap is telling. It suggests criminals are now investing in trust-building the same way a legitimate advisor would, which is exactly what makes it harder for victims to spot them,” said Akshay Garkel, partner and leader-cyber, Grant Thornton Bharat.
More cases with flat-to-lower total losses reflect that the average ticket size per victim is shrinking, consistent with an increase in smaller frauds, said Garkel.
Meanwhile, general cyber frauds, such as Unified Payments Interface (UPI) scams and investment schemes, are becoming a high-volume, low-value game, “while formal bank fraud is moving toward fewer but much costlier incidents”, he added.
Mfilterit, a financial cybersecurity firm, flagged 200,000-300,000 such accounts in January, a figure that spiralled to 1.5 million by August.
“Cybercriminals now have a business case for petty fraud, courtesy AI,” said Dhiraj Gupta, cofounder and chief technology officer, Mfilterit.
Earlier, it took about a week and significant investment to build a fake website, according to Gupta. “Previously, they targeted only the ‘big fish’, but now, AI agents can find vulnerabilities for free and create 1,000 fake sites in 10 minutes,” he said.
Even college students or low-income individuals with amounts under Rs 1 lakh are now vulnerable. according to him.
The widespread use of mule accounts makes petty fraud both untraceable and unrecoverable, experts said. Mule accounts are bought from poor, unemployed and illiterate people, usually against small payouts.
“Cyber fraud in India is getting democratised downward,” said Akshat Jain, chief technology officer, Cyware, an AI-powered cyber threat intelligence management services firm.
AI has made it profitable to scam a thousand people for small amounts instead of one person for a fortune, he said, adding that Cyware has seen a surge in income tax phishing and fake gift card scams.
By mining social media activity, leaked databases and online tracking data, attackers learn a target’s interests, such as football or the Cricket World Cup, and run highly personalised phishing campaigns.
“Their goal is two-fold: to target less cyber-aware individuals for petty frauds of a few thousand to a few lakhs, and to use those same compromised individuals as an entry point into the companies they work for,” Jain said.
In its ‘Cybersecurity Considerations 2026’ report, KPMG emphasised the need for autonomous defences, geopolitical resilience, protected AI systems, secure supply chains, strong identity governance, quantum-age preparation and highly resilient infrastructure.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.