Capillary subsidiary hit by €3M deepfake-enabled banking fraud

Retail customer-engagement SaaS firm Capillary Technologies has initiated a KPMG forensic audit after a recently acquired subsidiary lost €3 million in an alleged deepfake-enabled banking fraud. The company says €450,000 has been recovered and customer data and infrastructure were unaffected.

— Source publishedFri, 31 Jul, 2026, 15:44 IST·First seen Fri, 31 Jul, 2026, 16:29 IST·Source Inc42

What happened

Retail customer-engagement SaaS provider Capillary Technologies launched a KPMG forensic audit after a recently acquired subsidiary suffered a €3 million

Key facts

  • €3 million (₹32.7 crore) fraudulent transfer
  • €450,000 recovered
  • Q4 FY26 net profit: ₹43.4 crore
  • Q4 FY26 operating revenue: ₹191.3 crore
  • FY26 revenue: ₹734.6 crore
  • FY26 net profit: ₹52.4 crore

Why this matters

For acquirers, the incident underscores the importance of forensic financial-control diligence, bank mandate reviews and deepfake-resistant authorization processes when integrating acquired subsidiaries.

What to watch

  • KPMG findings on whether fraud arose from a human-authorisation lapse, compromised credentials, bank-account manipulation or broader control failures.
  • Any revision to the gross loss, recovered amount, insurance coverage or expected net financial impact.
  • Confirmation of whether other subsidiaries, vendors, bank accounts or payment workflows were targeted.
  • Customer renewal, deal-cycle or procurement-security commentary following the incident.
  • Regulatory, law-enforcement, litigation or insurer developments.
  • Management changes, delayed acquisition integration or new treasury-control investment.
  • Complete the KPMG forensic audit and disclose whether the incident was isolated, including the control failure and remediation timeline.
  • Implement out-of-band callback verification, dual approvals, payment hold periods and bank-account change controls for all subsidiaries.
  • Centralize treasury visibility and fraud monitoring across acquired entities; run deepfake and business-email-compromise simulations for finance leadership.
  • Pursue additional fund recovery through banks, law enforcement, insurers and relevant payment intermediaries.
  • Provide enterprise customers and prospective buyers with a clear assurance package confirming the scope of impact, data-security status and strengthened controls.

Also reported by