SEO Title: Capillary Technologies Q1 Loss: How A ₹32.7 Crore Deepfake Fraud Erased A Profitable Quarter
Meta Description: Capillary Technologies swung to a ₹9.5 crore consolidated loss in Q1 FY27 after a deepfake-enabled cyber fraud at a subsidiary, despite 42% YoY revenue growth.
---
For a growing number of Indian companies, the most dangerous adversary in the room is no longer a rival competitor or a slowing market — it is a synthetically generated voice or video convincing enough to fool a finance team into wiring millions of dollars to a stranger. Capillary Technologies, the Bengaluru-founded, Singapore-headquartered SaaS company that builds loyalty and customer-engagement platforms for roughly 400 global brands, became the latest and most vivid Indian illustration of that threat this quarter, when a sophisticated deepfake-enabled cyber fraud at a recently acquired subsidiary wiped out what would otherwise have been a genuinely strong quarter of underlying business growth.
Capillary Technologies reported a consolidated net loss of approximately ₹9.55 crore for the first quarter of FY27, a sharp reversal after the company had posted a consolidated net profit of ₹43.36 crore in the immediately preceding quarter. The swing to loss came despite the company's core business continuing to grow at a healthy clip — underlying revenue rose 42% year-on-year — underscoring just how significant the financial impact of the cyber incident was relative to the company's overall quarterly earnings base.

What Actually Happened
According to disclosures made by the company to the Bombay Stock Exchange and National Stock Exchange, one of Capillary's "recently acquired step-down subsidiaries" was targeted by a financial services-related cyber fraud amounting to approximately €3 million — roughly ₹32.7 crore at prevailing exchange rates. The mechanism of the fraud, according to the company's own account, involved advanced deepfake techniques, including voice cloning, forged signatures, and social engineering designed to impersonate senior members of the company's management team — precisely the kind of synthetic-media-enabled fraud that cybersecurity experts globally have been warning would become increasingly common as generative AI tools have made convincing audio and video impersonation dramatically cheaper and more accessible to criminal actors.
The funds were fraudulently transferred to an unauthorised third-party bank account. Upon identifying the attack, Capillary said it moved quickly, working with law enforcement, cybercrime authorities and the banks involved to trace and freeze accounts suspected of being connected to the fraud. That rapid response yielded partial recovery: the company was able to recover approximately €450,000 of the diverted funds relatively quickly, and subsequently traced additional bank accounts suspected to be linked to the fraud, with those accounts placed on hold by the relevant banks — reducing, though not eliminating, the ultimate financial exposure.
Capillary has stated that the affected step-down subsidiary carried a cyber and crime insurance policy, and that the company is evaluating the extent of insurance coverage and the recoverability of the remaining diverted funds. The company has also initiated an independent forensic audit conducted by KPMG to investigate the incident thoroughly and to help rebuild governance safeguards against similar attacks in the future.
Connecting The Dots: A Recent Acquisition Under Scrutiny
While Capillary has not explicitly named the affected subsidiary in its public disclosures, the timing and description — a "recently acquired step-down subsidiary" — point toward the company's most recent notable acquisition: global card network Mastercard's customer engagement and loyalty platform SessionM, which Capillary acquired for approximately $20 million earlier this year. Newly acquired subsidiaries are, almost by definition, at heightened cybersecurity risk during the integration period — their financial controls, banking relationships, and internal authorisation processes may not yet be fully harmonised with the acquiring company's own security infrastructure, creating exactly the kind of procedural gaps that sophisticated fraud schemes are designed to exploit.
This dynamic — M&A integration as a cybersecurity vulnerability window — is a well-documented risk in corporate security literature globally, but it remains a comparatively underappreciated consideration in how Indian companies evaluate and price acquisitions. Capillary's experience offers a concrete, costly illustration of why cybersecurity due diligence and rapid security-infrastructure integration should arguably rank alongside financial and legal due diligence as a priority workstream in any acquisition, particularly one involving cross-border entities with potentially less mature internal controls than the acquiring parent.
The Underlying Business: Genuinely Strong Growth
It would be a mistake to let the fraud-driven loss obscure what was, by the company's own operational metrics, a genuinely solid underlying quarter. Capillary's revenue growth of 42% year-on-year reflects continued momentum in what the company describes as its core commercial engine: a loyalty system-of-record and rewards platform, increasingly supplemented by artificial intelligence, marketing automation and data-insights products that management has positioned as incremental monetisation layers on top of the core loyalty business.
According to company disclosures, Capillary's platform now supports approximately 400 brands and around 115 large enterprise accounts, managing roughly 1.9 billion consumer profiles with what the company describes as "five-nines" uptime reliability — a standard implying 99.999% system availability, an operationally demanding benchmark for any SaaS platform operating at that scale. Management has also highlighted strong net revenue retention (NRR) economics, with incremental gross margins on account upsells reported in the 85-90% range, alongside growing customer adoption of the company's AI product stack — with roughly a quarter of customers reportedly piloting AI capabilities under a usage-based pricing model.
That said, management's own commentary also flagged a genuine tension emerging from Capillary's acquisition-driven growth strategy: inorganic net revenue retention, at approximately 94%, trails the company's organic NRR of around 114%, a gap management attributed to first-year migration discounts typically offered to customers acquired through M&A, alongside the operational complexity of migrating those customers onto Capillary's core platform. In other words, acquisitions like the SessionM deal add revenue and customer scale, but they also import both integration complexity and — as this quarter's fraud incident starkly demonstrated — genuine operational risk that can materially affect near-term financial performance in ways a purely organic growth strategy would not.
Full-Year Context: FY26 Was A Genuinely Strong Year
Capillary's FY26 results, reported before this quarter's fraud-driven setback, had shown consolidated net profit surging 295% year-on-year to ₹52.39 crore, with consolidated revenue rising 23% to ₹734.60 crore and adjusted EBITDA increasing 43% year-on-year to ₹106.92 crore. The company had also appointed Sumit Kumar as President for the Middle East, Africa and India in April 2026 to lead regional sales strategy — part of a broader push to deepen the company's presence across markets beyond its traditional strongholds.




