Malta's Prime Minister Robert Abela Reportedly Deepfaked by a Ukrainian National in Cryptocurrency Fraud Targeting Local Residents

A Ukrainian national was arrested in Malta for orchestrating a cryptocurrency fraud scheme that targeted local residents. The perpetrator used AI-generated deepfake videos of high-profile figures, including the Prime Minister, to lure victims into a fake investment platform. One victim lost over €53,000 in life savings after being manipulated through AI-generated messages and fraudulent financial advice.

A 24-year-old Ukrainian woman, Kateryna Izotkina, was reportedly arrested in Malta after allegedly using an AI-generated deepfake video of Prime Minister Robert Abela to promote a fraudulent cryptocurrency scheme. According to investigators, victims were misled into transferring tens of thousands of euros, including one who reportedly lost €53,250. Police conducted a controlled delivery and detained the suspect, who has been charged with fraud, money laundering, and related offenses.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation

The scammers used AI-generated deepfakes of public figures and ChatGPT-generated text to execute a targeted financial scam against a specific victim.

Additional risk subdomains

  • 3.1 False or misleading information: Deepfake videos of political figures were used to spread false information about investment schemes to lure victims.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The incident was caused by human scammers who intentionally used deployed AI tools (deepfake generators and ChatGPT) to defraud the victim.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Risk Level 3: Limited Risk. The incident involved AI-generated content such as deepfakes of political figures and ChatGPT-generated text, which fall under the transparency obligations of Limited Risk systems.

AI system and alleged parties

  • AI system: ChatGPT, unspecified (OpenAI)
  • AI purpose: Deepfake Video Generation; Writing Assistant
  • Behaviour type: Tool
  • Alleged developer: Unknown voice cloning technology developers, Unknown deepfake technology developers
  • Alleged deployer: Maria Lipinski, Kateryna Izotkina
  • Alleged harmed parties: Robert Abela, Investors in Malta, Investors, General public of Malta, General public, Epistemic integrity

Harm severity

Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Minor, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Minor, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Minor, indirect Negligible
  • Psychological: direct Negligible, indirect Minor
  • Epistemic: direct Minor, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

Financial

Reported: The report describes 1 occurrence causing a total financial loss of 53,250 euros, with an average loss of 53,250 euros per occurrence.

Directly caused: The victim directly lost 53,250 euros of her life savings through multiple transactions and cash handovers to the scammers.

Indirectly caused: N/A

Inferred additional harm: Other individuals in Malta were reportedly defrauded by the same scam, suggesting the total financial loss across all victims is likely higher.

Malicious content

Reported: The report describes the creation and distribution of deepfake videos of political figures and ChatGPT-generated scam messages.

Directly caused: The scammers created and distributed deepfake videos of Prime Minister Robert Abela and other public figures on Facebook, as well as ChatGPT-generated text messages to manipulate the victim.

Indirectly caused: N/A

Inferred additional harm: The deepfake videos were circulated on social media, exposing an unknown number of Facebook users to the malicious scam content.

Privacy

Reported: The report describes privacy violations where the scammers obtained the victim's personal details and remote access to her laptop.

Directly caused: The scammers obtained the victim's mobile number, bank card details, bank account numbers, and remote access to her laptop via AnyDesk.

Indirectly caused: N/A

Inferred additional harm: The scammers likely accessed and compromised personal and financial data stored on the victim's laptop through the AnyDesk remote access.

Psychological

Reported: The report describes threats made to the victim, including legal threats of being sued for money laundering and a threatening phone call after the arrest.

Directly caused: N/A

Indirectly caused: The victim experienced distress and anxiety due to threats of legal action and retaliatory warnings from the scammers.

Inferred additional harm: It is highly likely the victim suffered significant emotional distress, anxiety, and trauma from losing her entire life savings of over 53,000 euros and receiving threats.

Epistemic

Reported: The report describes epistemic harm through the creation of deepfake videos of political figures endorsing a fake investment scheme.

Directly caused: Deepfake videos falsely depicted Prime Minister Robert Abela, Simon Busuttil, Joseph Muscat, and Ursula von der Leyen endorsing a fraudulent cryptocurrency scheme.

Indirectly caused: N/A

Inferred additional harm: The fabrication of endorsements by high-profile political figures misleads the public and erodes trust in official communications.

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 1
  • People reportedly exposed: 1

Potential causes

Technology

  • Realistic Deepfake Generation: AI-generated videos of prominent politicians made the fake investment look real.
  • ChatGPT Text Generation: Scammers used ChatGPT to write convincing and threatening messages.

Human Factors

  • Inability to Spot Deepfakes: The victim could not distinguish the AI-generated videos from real footage.
  • Inability to Spot ChatGPT Text: The victim did not recognize AI-generated text until her daughter noticed it.

Process and Methods

  • Inadequate Content Filtering: Facebook failed to detect and block deepfake scam ads from being published.

Information quality

  • Classification confidence: High
  • Reason for confidence: The reports provide detailed, consistent testimonies from the court proceedings regarding how the scam was executed, the specific AI technologies used (deepfakes and ChatGPT), and the exact financial losses incurred.

A Ukrainian national in Malta used AI-generated deepfakes of Maltese and EU political leaders alongside ChatGPT-generated messages to execute a successful cryptocurrency scam. While representing an evolved cyber-fraud capability that exploits the likeness of state officials, the incident was a localized criminal act with minor national security implications, successfully resolved by local law enforcement.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Single nation
  • Primary target: Malta
  • Alleged perpetrator: Kateryna Izotkina

Threat characteristics

  • Imminence: Long-term. The immediate threat has been mitigated by the arrest of the perpetrator, though the strategic risk of AI-enabled fraud remains ongoing.
  • Autonomy: Human-controlled. AI systems were used strictly as tools by the human perpetrator to generate text and video content, with no autonomous decision-making by the AI.
  • Novelty: Evolved capability. While deepfakes and LLM-generated phishing are established, combining them to impersonate multiple high-level national and international leaders represents an evolved capability.

Impact by dimension

  • Physical security: Negligible. The incident was a financial scam with no physical components, kinetic threats, or critical infrastructure targeting.
  • Information security: Minor. Deepfakes of the Maltese Prime Minister and EU Commission President were used, but the operation was a localized financial fraud rather than a state-sponsored disinformation campaign.
  • Sovereignty: Minor. Impersonation of top government and EU officials occurred, but it did not disrupt actual government decision-making, elections, or state authority.
  • Economic security: Minor. The scam resulted in a direct financial loss of over 53,000 euros for a single victim, representing local criminal fraud rather than a systemic threat to economic security.
  • Societal stability: Minor. The use of political deepfakes erodes epistemic trust in public figures, but the societal impact remains localized and limited to the fraud victims.
Explore in the interactive Incident Tracker