Menu

One photo, one bot, zero expertise: How AI morphing is spreading across Keralam campuses

Campuses once associated with learning, friendships and youthful freedom are now confronting a darker digital threat.

Published Sep 13, 2026 | 5:00 PMUpdated Sep 13, 2026 | 5:01 PM

How AI morphing is spreading across Keralam campuses
Make Us Your Preferred Source on Google

Synopsis: As AI-powered morphing becomes an emerging threat on Keralam campuses, easy access to students’ photos and Telegram-based tools is making image abuse increasingly difficult to contain. The growing need for quick reporting, evidence preservation and stronger cyber safeguards is putting the spotlight on tools such as cybercrime.gov.in, 1930, StopNCII.org and Take It Down.

A new fear is spreading across Keralam’s campuses, particularly among girl students and women faculty: ”Has someone morphed my photo? Has someone created a deepfake of me?”

For years, phones were part of campus life—used to capture festivals, elections, classroom moments, and celebrations —with little thought about where those images could end up. But a string of disturbing morphing cases has changed that.

Recently, cases have emerged at Bharata Mata College in Thrikkakara, Kochi; IHRD College in Mavelikara, Alappuzha; and Mangalam College in Kottayam, alongside complaints from Malappuram and a separate case at Government Medical College, Thiruvananthapuram.

Police have booked the accused under provisions of the IT Act and the POCSO Act after allegedly obscene morphed images were found on seized devices.

Campuses once associated with learning, friendships and youthful freedom are now confronting a darker digital threat.

When South First spoke to cyber experts and cyber enthusiasts, they revealed just how easy it is to create, circulate and weaponise such images — and why the fear may be much bigger than the cases reported so far.

Also Read: Thrikkakara Bharath Mata College morphing case: Police probe widens to paid Telegram groups

How campus photo leaks fuel morphing attacks

Nandakishore Harikumar

Nandakishore Harikumar

Speaking to South First, Nandakishore Harikumar, a prominent cybersecurity expert from Keralam and founder of Falcon Feeds, a threat intelligence platform that tracks hackers, ransomware groups and emerging cyber threats, pointed out why campuses are particularly vulnerable to morphing and deepfake abuse.

”Every fest, election and sports day dumps thousands of high-resolution portraits into open Drive folders and Instagram pages, so a whole batch of one student’s face is a download away. Add to that the fact that the culprit is usually someone nearby with a grudge, and that a 19-year-old with a virtual number and a free VPN believes he is invisible,” he said.

Harikumar pointed out that the technology needed to create such morphed images is also easily accessible.

He said the process is trivial, with Telegram bots letting users send a photograph and receive a morphed image in return. It requires neither coding skills nor a GPU, with some bots offering a few free attempts before switching to paid credits.

Even when one bot is banned, others often emerge under new names the next day.

Law is adequate; execution remains a problem

Harikumar said colleges largely react only after such incidents become public. ”Mostly, they suspend, expel and file a complaint. Almost none have a plan for the first 48 hours, and I’ve seen staff scroll through a suspect’s phone and wreck the evidence.”

According to the cybersecurity expert, the existing legal framework is adequate, but its execution remains a problem.

”The law is fine — IT Act 66E/67/67A, BNS has provisions on voyeurism, stalking, extortion and intimidation, and POCSO if the victim is under 18. The gap is execution.”

He also pointed to the tighter timeline now applicable to platforms.

Since February 20, 2026, platforms have only two hours, instead of 24, to remove morphed intimate images following a complaint under Rule 3(2)(b), making it no longer acceptable to report the content and wait for action.

Also Read: More victims emerge in medical college morphing case; police to file additional FIRs

From Telegram bots to digital evidence- The cyber trail

Telegram scam.

Telegram scam.

Once a morphed image begins circulating, the victim can lose control of it within minutes, Harikumar said.

“Groups of 200,000, unlimited channels, and one-tap forwarding with the sender’s name hidden make Telegram particularly difficult to contain. The circulation can quickly escalate into doxxing and sextortion. Face-search links the image to a real name and handle. Then comes sextortion, often by organised gangs who never made the image and want UPI money.”

Telegram poses additional challenges, he said, because regular chats are not end-to-end encrypted, cooperation can be slow, accounts can run on virtual numbers, and either side can delete a message from both phones, causing evidence to disappear.

However, tracing the creator is not impossible.

”Attribution is about joining dots, not one IP. The VPN user paid for bot credits from his own UPI. The burner Instagram follows the victim’s friends. The original download is still in his gallery.”

Telegram’s changed approach

He said Telegram has also changed its approach after its CEO, Pavel Durov, was arrested in 2024. According to a France24 report, he was arrested in Paris over allegations that his platform is being used for illicit activity such as drug trafficking and the distribution of child sexual abuse images.

”It now gives IP and phone numbers on valid court orders and did so for Indian authorities over 14,000 times in 2024. The catch is those are exactly what VPNs and virtual numbers hide, and message content isn’t shared.”

Detecting whether an image has been manipulated is becoming harder too.

“Every upload is typically recompressed, which can degrade the signals on which detection systems rely. Conversely, heavily filtered or edited genuine photographs may be incorrectly flagged as manipulated. A detector score should therefore never be treated as conclusive proof. Instead, investigators should try to identify the source image; manipulated images often retain key elements of the source, including the subject’s pose, composition, and background.”

Preserve the evidence

StopNCII.org for victims aged 18 and above

StopNCII.org for victims aged 18 and above

For students facing such abuse, Harikumar advised preserving evidence before taking action. ”Screenshot the image with its context: username, ID, channel link and timestamps. Screen-record while scrolling through it. Keep originals untouched. Don’t confront the suspect and don’t forward the image to friends ‘to check’.”

He recommended making a written police complaint, reporting the incident through cybercrime.gov.in and calling 1930 if money is involved, while simultaneously reporting the content to the platform citing Rule 3(2)(b).

He also advised victims aged 18 and above to use StopNCII.org and those under 18 to use Take It Down.

”Never pay. Change passwords, turn on two-factor everywhere and go private,” he further advised.

From a technical perspective, Harikumar said the most effective approach is to prevent easy access to original photographs in the first place. ”The cheapest fix is upstream: kill open albums, downscale, watermark, strip EXIF.”

He also recommended following the money trail, noting that morphing bots sell credits and that payment trails can therefore become a weak point for investigators.

”Third, stop asking ‘does this look AI?’ and start asking ‘where did it come from?’ C2PA provenance, an open technical standard that embeds cryptographically signed metadata into digital files to track the origin, history, and edits of media like photos, videos, and audio, which India’s new rules now mandate, is more durable than any detector.”

He cautioned that adversarial tools such as PhotoGuard and Glaze can offer some protection, but cannot make a photograph completely deepfake-proof.

”And Telegram has to own its bot platform: an open API is fine until it becomes the distribution layer for sexual abuse” he said.

Also Read: Morphed images of college students and teachers: Kerala police probe wider links

The changing face of sexual content in Keralam

Statement from the BMC

Statement from the BMC

Akhil Raghava Kurup, a Kochi-based cyber enthusiast, told South First that, ”Keralam has long had a culture of consuming sexualised content, which has now moved from magazines and films to platforms such as Instagram and Telegram.”

He said Telegram groups often circulate ordinary photos of women, including family members, with sexually coloured comments. At the same time, subscription-based platforms have enabled some women content creators to earn directly from exclusive sexualised content. However, they may have little control over where such material is later circulated.

Akhil Raghava Kurup also pointed to the difficulty of tracing offenders on Telegram, where users’ real identities and locations are not verified, and accounts can be created using temporary or anonymous numbers.

He, however, sees a shift in how women respond to such abuse.

”Unlike in the past, when the circulation of a morphed image could push victims into isolation or even suicide, more women are now willing to complain and confront the abuse,” he said.

The aftermath

In response to the recent campus cases, Bharat Mata College authorities told South First that they have strengthened campus monitoring and will fully cooperate with the police investigation.

Students from colleges in Kottayam, Devi Krishna and Pranav P, said they had generally trusted their friends and never imagined that ordinary photographs could be misused.

They said the incidents were a reminder to be more careful, but warned that restrictions on gadgets could also affect students who increasingly depend on technology for academic work.

(Edited by Sumavarsha)

journalist-ad