An investment scam in Cyprus is using sophisticated AI-generated deepfake videos of government officials to trick citizens into investing in fraudulent financial platforms. Victims are initially lured with small investments that appear to grow rapidly, leading to significant financial losses when they attempt to withdraw funds. The Cyprus Consumers Association has identified multiple platforms and is warning of the potential for the scam to spread across Europe.
Citizens in Cyprus reported being targeted by an alleged investment scam involving purported AI-manipulated videos that appeared to depict government officials endorsing financial platforms. The Cyprus Consumers Association stated that several individuals suffered significant financial losses after being misled by the videos, which circulated via social media and messaging apps. Authorities are investigating, and the association has warned of potential cross-border spread of the scheme.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The incident involves malicious actors using AI-generated deepfakes of public figures to conduct targeted financial fraud against individual citizens.
Additional risk subdomains
- 3.1 False or misleading information: The deepfake videos generate highly realistic false statements attributed to government officials to mislead the public.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by human scammers who intentionally deployed deepfake AI models to defraud victims.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The AI system is used to generate deepfakes, which are subject to transparency obligations under the EU AI Act.
AI system and alleged parties
- AI system: None named
- AI purpose: Deepfake Video Generation; Voice Generation
- Behaviour type: Tool
- Alleged developer: Unknown deepfake technology developers
- Alleged deployer: Unknown scammers
- Alleged harmed parties: Haris Georgiades, General public of Cyprus, Averof Neofytou
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Minor
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Minor
- Epistemic: direct Minor, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Financial
Reported: The report describes financial losses, including one case exceeding 40,000 euros, and initial investments of 150 to 250 euros requested from victims.
Directly caused: N/A
Indirectly caused: The use of AI deepfakes facilitated the scam, leading to financial losses including one case exceeding 40,000 euros and others losing initial 150-250 euro deposits. Average loss per occurrence is estimated at 3,000 euros.
Inferred additional harm: Total financial losses across all victims likely exceed 100,000 euros, given the scale of the scam and the high losses reported by some individuals.
Malicious content
Reported: The report explicitly describes manipulated videos of politicians encouraging fraudulent investments.
Directly caused: The AI was used to directly generate deepfake videos with lip movements matching fraudulent statements.
Indirectly caused: N/A
Inferred additional harm: It is likely that numerous variations of these deepfake videos were created and distributed across social media platforms, exposing thousands of users to malicious content.
Psychological
Reported: The report explicitly describes psychological harm in the form of threats received by victims when they discovered the deception.
Directly caused: N/A
Indirectly caused: Victims experienced distress and fear due to receiving threats from the scammers after discovering the fraud.
Inferred additional harm: Significant financial loss and receiving threats likely caused severe anxiety, stress, and psychological distress to the 14 reported victims.
Epistemic
Reported: The report explicitly describes epistemic harm in the form of deepfake videos where the lip movements of politicians matched fraudulent statements they did not make.
Directly caused: The AI generated highly realistic but completely fabricated videos of politicians recommending fraudulent investments.
Indirectly caused: N/A
Inferred additional harm: The widespread dissemination of realistic deepfakes of state officials undermines the public's ability to distinguish real official communications from fabricated ones, eroding shared truth.
People affected
- Occurrences reported: 1
- People reportedly harmed: 14
- People reportedly exposed: 14
Potential causes
Technology
- Sophisticated Deepfake Generation: AI-generated videos with matching lip movements made fraud highly convincing.
- Social Media Algorithm Distribution: Algorithms distributed fraudulent videos of politicians to target victims.
Data Inputs
- Unauthorized Use of Public Media: Publicly available video and audio of politicians were used to train deepfakes.
Human Factors
- Trust in Public Figures: Victims trusted the politicians' fake recommendations, lowering their guard.
- Cognitive Bias and Greed: Victims were lured by rapidly increasing profits shown on fake accounts.
- Lack of Deepfake Awareness: Victims could not distinguish sophisticated deepfakes from real footage.
Process and Methods
- Inadequate Platform Moderation: Social media platforms failed to detect and remove deepfake scam ads quickly.
- Ineffective Law Enforcement Tracing: Economic Crime Unit struggled to trace perpetrators operating across platforms.
Regulatory Environment
- Lack of Deepfake Regulations: Absence of strict regulations on AI-generated deepfakes allowed easy misuse.
Information quality
- Classification confidence: High
- Reason for confidence: The report is clear about the scam, the victims, the technology used (deepfakes), and the financial impact. The lack of specific model name is common and does not prevent classification of the risk.
- Ambiguities identified: The specific AI model or software used to generate the deepfakes is not identified.
An ongoing investment scam in Cyprus utilizes highly realistic AI-generated deepfakes of the President and other government officials to defraud citizens. While the incident represents a sophisticated use of synthetic media targeting state leadership, its primary impact is localized financial fraud rather than a systemic threat to national security, critical infrastructure, or sovereignty.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: Cyprus
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Near-term. The scam is active and has the potential to spread across Europe, requiring ongoing law enforcement monitoring and public warnings.
- Autonomy: Human-controlled. AI tools were utilized by human operators to generate the deepfake content, with no autonomous decision-making by the AI system.
- Novelty: Evolved capability. Represents an advancement in the deployment of highly realistic lip-synced deepfakes of state leaders for criminal financial fraud.
Impact by dimension
- Physical security: Negligible. No physical security threat or critical infrastructure compromise was reported in this incident.
- Information security: Minor. Sophisticated deepfakes of state leaders were deployed, but the motivation was localized financial fraud rather than state-sponsored information operations.
- Sovereignty: Minor. Impersonation of the President and ministers mimics official authority to perpetrate fraud, posing minor risks to public trust in official communications.
- Economic security: Minor. The incident caused direct financial losses to individuals but does not threaten national financial systems or strategic economic infrastructure.
- Societal stability: Minor. Direct financial harm and threats to multiple citizens occurred, along with potential erosion of public trust, but without large-scale social instability.