ImpactTechnology13 MIN READ

Capillary Technologies Swings To ₹9.5 Crore Loss After Deepfake Cyber Fraud, Even As Revenue Grows 42%

Capillary Technologies swung to a ₹9.5 crore consolidated loss in Q1 FY27 after a deepfake-enabled cyber fraud at a subsidiary, despite 42% YoY revenue growth.

By Aravind Kumar · Author5 August 2026
Capillary Technologies Swings To ₹9.5 Crore Loss After Deepfake Cyber Fraud, Even As Revenue Grows 42%

SEO Title: Capillary Technologies Q1 Loss: How A ₹32.7 Crore Deepfake Fraud Erased A Profitable Quarter

Meta Description: Capillary Technologies swung to a ₹9.5 crore consolidated loss in Q1 FY27 after a deepfake-enabled cyber fraud at a subsidiary, despite 42% YoY revenue growth.

---

For a growing number of Indian companies, the most dangerous adversary in the room is no longer a rival competitor or a slowing market — it is a synthetically generated voice or video convincing enough to fool a finance team into wiring millions of dollars to a stranger. Capillary Technologies, the Bengaluru-founded, Singapore-headquartered SaaS company that builds loyalty and customer-engagement platforms for roughly 400 global brands, became the latest and most vivid Indian illustration of that threat this quarter, when a sophisticated deepfake-enabled cyber fraud at a recently acquired subsidiary wiped out what would otherwise have been a genuinely strong quarter of underlying business growth.

Capillary Technologies reported a consolidated net loss of approximately ₹9.55 crore for the first quarter of FY27, a sharp reversal after the company had posted a consolidated net profit of ₹43.36 crore in the immediately preceding quarter. The swing to loss came despite the company's core business continuing to grow at a healthy clip — underlying revenue rose 42% year-on-year — underscoring just how significant the financial impact of the cyber incident was relative to the company's overall quarterly earnings base.

ChatGPT Image Aug 5, 2026, 02_03_19 PM.png



What Actually Happened

According to disclosures made by the company to the Bombay Stock Exchange and National Stock Exchange, one of Capillary's "recently acquired step-down subsidiaries" was targeted by a financial services-related cyber fraud amounting to approximately €3 million — roughly ₹32.7 crore at prevailing exchange rates. The mechanism of the fraud, according to the company's own account, involved advanced deepfake techniques, including voice cloning, forged signatures, and social engineering designed to impersonate senior members of the company's management team — precisely the kind of synthetic-media-enabled fraud that cybersecurity experts globally have been warning would become increasingly common as generative AI tools have made convincing audio and video impersonation dramatically cheaper and more accessible to criminal actors.

The funds were fraudulently transferred to an unauthorised third-party bank account. Upon identifying the attack, Capillary said it moved quickly, working with law enforcement, cybercrime authorities and the banks involved to trace and freeze accounts suspected of being connected to the fraud. That rapid response yielded partial recovery: the company was able to recover approximately €450,000 of the diverted funds relatively quickly, and subsequently traced additional bank accounts suspected to be linked to the fraud, with those accounts placed on hold by the relevant banks — reducing, though not eliminating, the ultimate financial exposure.

Capillary has stated that the affected step-down subsidiary carried a cyber and crime insurance policy, and that the company is evaluating the extent of insurance coverage and the recoverability of the remaining diverted funds. The company has also initiated an independent forensic audit conducted by KPMG to investigate the incident thoroughly and to help rebuild governance safeguards against similar attacks in the future.

Connecting The Dots: A Recent Acquisition Under Scrutiny

While Capillary has not explicitly named the affected subsidiary in its public disclosures, the timing and description — a "recently acquired step-down subsidiary" — point toward the company's most recent notable acquisition: global card network Mastercard's customer engagement and loyalty platform SessionM, which Capillary acquired for approximately $20 million earlier this year. Newly acquired subsidiaries are, almost by definition, at heightened cybersecurity risk during the integration period — their financial controls, banking relationships, and internal authorisation processes may not yet be fully harmonised with the acquiring company's own security infrastructure, creating exactly the kind of procedural gaps that sophisticated fraud schemes are designed to exploit.

This dynamic — M&A integration as a cybersecurity vulnerability window — is a well-documented risk in corporate security literature globally, but it remains a comparatively underappreciated consideration in how Indian companies evaluate and price acquisitions. Capillary's experience offers a concrete, costly illustration of why cybersecurity due diligence and rapid security-infrastructure integration should arguably rank alongside financial and legal due diligence as a priority workstream in any acquisition, particularly one involving cross-border entities with potentially less mature internal controls than the acquiring parent.

The Underlying Business: Genuinely Strong Growth

It would be a mistake to let the fraud-driven loss obscure what was, by the company's own operational metrics, a genuinely solid underlying quarter. Capillary's revenue growth of 42% year-on-year reflects continued momentum in what the company describes as its core commercial engine: a loyalty system-of-record and rewards platform, increasingly supplemented by artificial intelligence, marketing automation and data-insights products that management has positioned as incremental monetisation layers on top of the core loyalty business.

According to company disclosures, Capillary's platform now supports approximately 400 brands and around 115 large enterprise accounts, managing roughly 1.9 billion consumer profiles with what the company describes as "five-nines" uptime reliability — a standard implying 99.999% system availability, an operationally demanding benchmark for any SaaS platform operating at that scale. Management has also highlighted strong net revenue retention (NRR) economics, with incremental gross margins on account upsells reported in the 85-90% range, alongside growing customer adoption of the company's AI product stack — with roughly a quarter of customers reportedly piloting AI capabilities under a usage-based pricing model.

That said, management's own commentary also flagged a genuine tension emerging from Capillary's acquisition-driven growth strategy: inorganic net revenue retention, at approximately 94%, trails the company's organic NRR of around 114%, a gap management attributed to first-year migration discounts typically offered to customers acquired through M&A, alongside the operational complexity of migrating those customers onto Capillary's core platform. In other words, acquisitions like the SessionM deal add revenue and customer scale, but they also import both integration complexity and — as this quarter's fraud incident starkly demonstrated — genuine operational risk that can materially affect near-term financial performance in ways a purely organic growth strategy would not.

Full-Year Context: FY26 Was A Genuinely Strong Year

Capillary's FY26 results, reported before this quarter's fraud-driven setback, had shown consolidated net profit surging 295% year-on-year to ₹52.39 crore, with consolidated revenue rising 23% to ₹734.60 crore and adjusted EBITDA increasing 43% year-on-year to ₹106.92 crore. The company had also appointed Sumit Kumar as President for the Middle East, Africa and India in April 2026 to lead regional sales strategy — part of a broader push to deepen the company's presence across markets beyond its traditional strongholds.

The funds were fraudulently transferred to an unauthorised third-party bank account using advanced deepfake methods, including cloning, signature forging, and social engineering to impersonate the company's senior management, Capillary said in its exchange filing.

Set against that backdrop, the ₹32.70 crore fraud loss represents a manageable, if painful, fraction of Capillary's overall annual revenue base — the company's own framing, echoed by outside analysts, has emphasised that while the incident is financially significant at the quarterly level, it does not appear to threaten Capillary's underlying business model or growth trajectory in a structural sense. The more consequential question, several analysts have suggested, is reputational and governance-related: rebuilding digital trust with customers, partners and investors is described as paramount to sustaining the company's global SaaS expansion ambitions and maintaining what has been, until this incident, a premium market valuation relative to peers.

What This Means For India's Broader Corporate Cybersecurity Conversation

Capillary's experience arrives at a moment when Indian businesses more broadly are grappling with a rapidly evolving cyber threat landscape shaped significantly by the mainstreaming of generative AI tools. A separate industry study released this year found that the average cost of a data breach in India rose to ₹25.5 crore in 2026, even as AI-powered security tools were found to meaningfully reduce both breach costs and incident response times when deployed effectively — a somewhat paradoxical dynamic in which the same underlying AI technology is simultaneously enabling more sophisticated attacks (as in Capillary's deepfake-driven fraud) and more effective defensive capabilities, depending on which side of the arms race a given organisation has invested in more aggressively.

For finance and treasury teams across corporate India, Capillary's disclosure functions as a genuinely instructive cautionary tale: traditional fraud-prevention protocols built around recognising suspicious written communications or unfamiliar phone numbers are increasingly inadequate against attackers capable of convincingly cloning a CFO's voice or forging video calls with a senior executive's likeness. The defensive playbook required to counter deepfake-enabled fraud — multi-channel verification protocols, mandatory callback procedures using pre-verified contact numbers rather than numbers provided in the suspicious communication itself, and genuine organisational scepticism toward urgent, high-value payment requests regardless of how convincingly they are communicated — represents a meaningfully different and more demanding security posture than most Indian corporate finance functions have historically maintained.

The Insurance Question That Will Shape The Final Financial Picture

One of the more consequential open questions hanging over Capillary's fraud disclosure is the extent to which its cyber and crime insurance policy will ultimately offset the financial damage. The company has stated it is still evaluating the extent of insurance coverage and recoverability, language that suggests the final net financial impact of the incident — after accounting for both the recovered €450,000 and any eventual insurance payout — remains genuinely uncertain at the time of this quarter's results. Cyber insurance policies frequently contain specific carve-outs, sub-limits, or procedural requirements (such as demonstrating adequate security controls were in place prior to the incident) that can materially affect the actual payout relative to the headline coverage amount a policy nominally provides, meaning investors should treat this quarter's reported loss figure as a snapshot subject to potential future revision, rather than a fully and finally settled number.

A Pattern Indian Companies Are Increasingly Confronting

Capillary's disclosure joins a small but growing list of Indian companies that have publicly acknowledged significant deepfake or AI-enabled fraud losses in 2026, a trend that mirrors warnings cybersecurity researchers have issued for several years about the maturing capability of generative AI tools to enable convincing financial fraud at a fraction of the cost and technical sophistication such attacks previously required. For corporate boards and audit committees across Indian industry, Capillary's experience — a costly, publicly disclosed incident at a well-governed, publicly listed technology company with presumably above-average security awareness — offers a sobering reminder that sophistication of target is no longer a meaningful defence against sophistication of attack, given how accessible advanced deepfake tools have become to criminal actors operating well outside the resource constraints that once limited such attacks to state-sponsored or highly organised criminal groups.

Market Reaction As A Reputational Barometer

How Capillary's stock and broader market perception respond in the weeks following this disclosure will offer a useful, real-time indicator of how Indian investors currently price cybersecurity governance risk relative to underlying operational performance. A muted or quickly recovering market reaction would suggest investors are treating the incident as a genuinely one-off, addressable event consistent with the company's own framing; a more prolonged or severe reaction would suggest deeper investor concern about governance and integration discipline at a company that has grown substantially through acquisitions, potentially complicating Capillary's ability to raise capital or pursue further M&A on favourable terms until that concern is credibly addressed through demonstrated remediation.

ChatGPT Image Aug 5, 2026, 02_04_51 PM.png



What Comes Next

With the KPMG forensic audit underway and insurance recovery evaluations ongoing, Capillary's near-term priority is clearly containment and governance remediation rather than aggressive new growth initiatives. For investors and analysts tracking the stock, the coming quarters will offer a clearer picture of whether this quarter's loss proves to be an isolated, one-time setback attributable to a specific, addressable integration failure — or whether it exposes broader governance gaps that could recur as the company continues pursuing the acquisition-driven growth strategy that has, until now, been a core pillar of its expansion into new markets and customer segments. For India's wider technology and corporate governance ecosystem, Capillary's costly quarter offers a concrete, quantified reminder that in an era of increasingly capable generative AI tools, cybersecurity due diligence during M&A integration deserves the same rigour traditionally reserved for financial and legal review — a lesson that arrived, in this instance, at a price of roughly ₹32.7 crore.

TagsCapillaryTechnologiesDeepfakeFraudCyberSecurityIndiaSaaSIndiaQ1ResultsCorporateGovernanceFraudPreventionEnterpriseTechIndianTechStocksKPMGAudit

Reader reviews

Sign in to rate and review this article.
Loading reviews…