A Pune woman was allegedly persuaded to send ₹4.09 lakh to multiple bank accounts after encountering an Instagram video that purported to show Ratan Tata promoting high-return share trading, according to a report published Sunday by The News Mill. The case is another reminder that the most consequential part of an AI-enabled investment scam is often not the synthetic video itself: it is the chain of ordinary-looking services that follows — an ad link, an app download, a familiar collaboration platform, and UPI transfers to accounts outside any regulated brokerage relationship.

The News Mill identified the complainant as 38-year-old Vaishali Swapnil Jagdale and reported that she encountered the alleged video between October 9, 2024, and June 13, 2025. After clicking an advertising link and downloading an application, she was reportedly contacted on Microsoft Teams by a person calling himself Manu Mohan, who promised substantial returns from share trading and directed payments to different bank accounts associated with separate UPI IDs.

Pune police have registered a case against the operators of the link and the bank-account beneficiaries under the Bharatiya Nyaya Sanhita and Section 66(d) of India’s Information Technology Act, the outlet reported. Section 66(d) specifically covers cheating by personation through a computer resource or communication device — a close fit for a fraud that allegedly relied on a false identity, social-media promotion, an application, and Teams-based contact.

There is an important reporting limitation: no other outlet located by WindowsForum independently reported the specific complaint, its FIR number, the police station handling it, the precise BNS provisions invoked, or the date the case was registered. Those details matter. An FIR is the point at which investigators can seek preservation of account records, payment trails, app-hosting data, advertising records, and platform information; without it, the public account identifies the alleged method but not how quickly authorities were able to move on the money.

Illustration warning of an AI investment scam using fake returns, social media persuasion, and anonymous UPI payments.The Ratan Tata video was the lure, not the whole fraud​

The alleged timeline begins on October 9, 2024 — the day Ratan Tata died. Tata Group and Tata Trusts confirmed his death that day at age 86. That does not establish when the video was created, when it was first circulated, or whether the scammers reacted to the news cycle, but it underscores a harder fact: an impersonation scam can continue to exploit the image of a trusted public figure long after that person can issue a direct denial.

Ratan Tata’s likeness had already been used in bogus investment and betting promotions before his death. In late 2023, fact-checkers at India Today documented an AI-manipulated video falsely presenting Tata as an endorser of an online betting scheme. Tata himself also publicly warned in December 2023 about a fake video using his image to promise unusually high investment returns.

That history changes how this Pune case should be read. The material fact is not merely that criminals could generate or recycle a convincing video. It is that a known false-endorsement pattern remained useful enough to serve as the initial trust signal in a later alleged fraud. The scammer does not need a perfect deepfake if the victim sees a familiar face, a plausible investment claim, and a path that appears frictionless from Instagram to messaging to payment.

The video also did not need to impersonate a licensed broker. Its function was simply to lower the victim’s skepticism enough to induce the click. Once a target downloads the app and starts communicating with a purported adviser, the fraud moves from media manipulation to a social-engineering operation designed to extract payments.

Microsoft Teams was used as a contact channel, not evidence of a Microsoft breach​

The report says the alleged operator contacted Jagdale through Microsoft Teams. There is no indication that Microsoft Teams itself was compromised, that Microsoft endorsed the trading scheme, or that the alleged fake application was distributed through Microsoft’s software channels. Treating the Teams reference as evidence of a platform breach would overstate what is known.

But the choice of Teams is still operationally significant. Business collaboration software benefits from inherited trust: many people associate it with office accounts, meetings, vendors, and legitimate work communication. A fraudster appearing on Teams can seem more credible than an unknown caller or a newly created Telegram account, particularly after an Instagram advertisement has already established the fiction of an investment opportunity.

Pune has seen that credibility effect in other cases. In July, The Indian Express reported that a finance executive at a Pune-based company transferred ₹56 lakh after messages arrived from a Teams profile using the name and photograph of her Italy-based chief executive. The case was described as a “boss scam,” a targeted impersonation fraud in which a familiar corporate tool becomes part of the deception.

For IT teams, this is a practical security lesson rather than an indictment of Teams. A familiar communications product does not verify the commercial legitimacy of every person who uses it. Organizations should treat unsolicited financial or investment conversations on collaboration platforms in the same way they treat an unexpected invoice, password-reset prompt, or remote-support request: independently validate the individual and the organization through a pre-existing, trusted channel.

The app-and-UPI sequence matches the regulator’s scam model​

The Securities and Exchange Board of India has repeatedly warned investors about fraudulent social-media ads, fake trading platforms, unregistered advisers, fabricated profits, and payments made to third-party accounts. Its published guidance describes the common progression: a social-media hook promises abnormal returns; a supposed expert or group builds confidence; the victim is directed to a fake app; the app displays profits; further payments are requested; and an attempted withdrawal exposes the fraud.

The Pune allegation follows that pattern closely. According to The News Mill, Jagdale clicked an advertisement link, downloaded an application, received personal reassurance from the alleged adviser, and then sent funds to several accounts. A dashboard, app, or intermediary can make a scheme feel like an investment account, but none of those things makes it a regulated trading service.

The separate UPI destinations are the more actionable red flag than the deepfake video. A legitimate broker or registered intermediary should be verifiable before funds leave a bank account. Payments routed to multiple unrelated accounts, particularly after an unsolicited online pitch, are a reason to stop the transaction and verify the entity through SEBI’s registration and trading-app resources rather than through contact details supplied by the person making the pitch.

SEBI has moved toward more visible verification measures. In March, SEBI chairman Tuhin Kanta Pandey said the regulator had escalated more than 130,000 items of misleading investment content to platforms for takedown and had pushed 66 fake trading-app cases to app stores, which removed them. SEBI also said verified labels for registered stock-broker apps had begun appearing in Google Play.

That initiative is useful, but it does not close the route alleged in the Pune complaint. The regulator itself has identified side-loading — installing applications from links sent by fraudsters rather than from official app stores — as a continuing risk. A badge in an app store cannot protect someone who is sent elsewhere before they ever reach the store.

What investigators need to establish​

Police said they are working to identify the holders of the receiving accounts and those behind the link and trading application. That distinction is important because the account holder, the person who obtained the account, the mule-account handler, the operator of the fake platform, the advertiser, and the person communicating on Teams may all be different people.

The 2025 arrest of five suspects in a similar Pimpri-Chinchwad case shows why following the money is more important than merely removing an advertisement. The Indian Express reported that a businessman allegedly lost ₹54.6 lakh after a deepfake video of trading educator Rachana Ranade led to a WhatsApp group and fraudulent app. Investigators reportedly traced funds through accounts connected to an Indore entity and alleged that handlers converted money into Tether cryptocurrency for onward transfer to overseas operators.

That case does not prove the same structure was used against Jagdale. It does demonstrate the investigative problem: the visible account receiving a victim’s UPI payment may be one link in a chain rather than the control point of the operation. Prompt bank notifications and preservation requests can be decisive before balances are transferred again, withdrawn, or converted.

The reported BNS and IT Act charges cover the alleged deception, but the public report does not state whether police have sought account freezes, identified the fake app’s developer or hosting provider, preserved the Instagram advertisement, or requested Teams account information. Those are the milestones that will show whether this is progressing beyond a registration into a traceable financial investigation.

The fastest response is still the financial-fraud helpline​

Anyone who has just sent money after an online investment pitch should contact their bank immediately and call India’s national cyber financial-fraud helpline, 1930. The National Cyber Crime Reporting Portal says the helpline operates around the clock for immediate reporting of financial cyber fraud; a portal complaint should follow with transaction IDs, UPI handles, beneficiary account details, screenshots, app package information, advertisements, chat logs, and any phone numbers or email addresses used.

Do not keep paying “tax,” “processing,” “unlock,” or “withdrawal” charges to recover a displayed balance. In fake-trading scams, the balance shown inside the app is often part of the deception, not evidence that funds exist or are recoverable.

For Windows users, the immediate device step is to preserve evidence before removing anything: capture the app name, icon, permissions, installation source, file name, and conversations; then revoke unnecessary permissions and run a security scan. If the app was installed from an APK or an unverified link, assume it may have collected more than investment details — including contacts, SMS access, notification content, or device identifiers — and change financial-account passwords from a known-clean device.

The alleged ₹4.09 lakh loss began with a famous face in a video, but it advanced because a supposed adviser persuaded the victim to bypass the ordinary proof required for a real investment: a verifiable intermediary, an authentic trading application, and a payment route belonging to that intermediary. The decisive check comes before the first transfer, when there is still money to protect.