A Ukrainian national was arrested in Malta for orchestrating a cryptocurrency fraud scheme that targeted local residents. The perpetrator used AI-generated deepfake videos of high-profile figures, including the Prime Minister, to lure victims into a fake investment platform. One victim lost over €53,000 in life savings after being manipulated through AI-generated messages and fraudulent financial advice.
A 24-year-old Ukrainian woman, Kateryna Izotkina, was reportedly arrested in Malta after allegedly using an AI-generated deepfake video of Prime Minister Robert Abela to promote a fraudulent cryptocurrency scheme. According to investigators, victims were misled into transferring tens of thousands of euros, including one who reportedly lost €53,250. Police conducted a controlled delivery and detained the suspect, who has been charged with fraud, money laundering, and related offenses.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The scammers used AI-generated deepfakes of public figures and ChatGPT-generated text to execute a targeted financial scam against a specific victim.
Additional risk subdomains
- 3.1 False or misleading information: Deepfake videos of political figures were used to spread false information about investment schemes to lure victims.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by human scammers who intentionally used deployed AI tools (deepfake generators and ChatGPT) to defraud the victim.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The incident involved AI-generated content such as deepfakes of political figures and ChatGPT-generated text, which fall under the transparency obligations of Limited Risk systems.
AI system and alleged parties
- AI system: ChatGPT, unspecified (OpenAI)
- AI purpose: Deepfake Video Generation; Writing Assistant
- Behaviour type: Tool
- Alleged developer: Unknown voice cloning technology developers, Unknown deepfake technology developers
- Alleged deployer: Maria Lipinski, Kateryna Izotkina
- Alleged harmed parties: Robert Abela, Investors in Malta, Investors, General public of Malta, General public, Epistemic integrity
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Minor, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Minor
- Epistemic: direct Minor, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Financial
Reported: The report describes 1 occurrence causing a total financial loss of 53,250 euros, with an average loss of 53,250 euros per occurrence.
Directly caused: The victim directly lost 53,250 euros of her life savings through multiple transactions and cash handovers to the scammers.
Indirectly caused: N/A
Inferred additional harm: Other individuals in Malta were reportedly defrauded by the same scam, suggesting the total financial loss across all victims is likely higher.
Malicious content
Reported: The report describes the creation and distribution of deepfake videos of political figures and ChatGPT-generated scam messages.
Directly caused: The scammers created and distributed deepfake videos of Prime Minister Robert Abela and other public figures on Facebook, as well as ChatGPT-generated text messages to manipulate the victim.
Indirectly caused: N/A
Inferred additional harm: The deepfake videos were circulated on social media, exposing an unknown number of Facebook users to the malicious scam content.
Privacy
Reported: The report describes privacy violations where the scammers obtained the victim's personal details and remote access to her laptop.
Directly caused: The scammers obtained the victim's mobile number, bank card details, bank account numbers, and remote access to her laptop via AnyDesk.
Indirectly caused: N/A
Inferred additional harm: The scammers likely accessed and compromised personal and financial data stored on the victim's laptop through the AnyDesk remote access.
Psychological
Reported: The report describes threats made to the victim, including legal threats of being sued for money laundering and a threatening phone call after the arrest.
Directly caused: N/A
Indirectly caused: The victim experienced distress and anxiety due to threats of legal action and retaliatory warnings from the scammers.
Inferred additional harm: It is highly likely the victim suffered significant emotional distress, anxiety, and trauma from losing her entire life savings of over 53,000 euros and receiving threats.
Epistemic
Reported: The report describes epistemic harm through the creation of deepfake videos of political figures endorsing a fake investment scheme.
Directly caused: Deepfake videos falsely depicted Prime Minister Robert Abela, Simon Busuttil, Joseph Muscat, and Ursula von der Leyen endorsing a fraudulent cryptocurrency scheme.
Indirectly caused: N/A
Inferred additional harm: The fabrication of endorsements by high-profile political figures misleads the public and erodes trust in official communications.
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Technology
- Realistic Deepfake Generation: AI-generated videos of prominent politicians made the fake investment look real.
- ChatGPT Text Generation: Scammers used ChatGPT to write convincing and threatening messages.
Human Factors
- Inability to Spot Deepfakes: The victim could not distinguish the AI-generated videos from real footage.
- Inability to Spot ChatGPT Text: The victim did not recognize AI-generated text until her daughter noticed it.
Process and Methods
- Inadequate Content Filtering: Facebook failed to detect and block deepfake scam ads from being published.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide detailed, consistent testimonies from the court proceedings regarding how the scam was executed, the specific AI technologies used (deepfakes and ChatGPT), and the exact financial losses incurred.
A Ukrainian national in Malta used AI-generated deepfakes of Maltese and EU political leaders alongside ChatGPT-generated messages to execute a successful cryptocurrency scam. While representing an evolved cyber-fraud capability that exploits the likeness of state officials, the incident was a localized criminal act with minor national security implications, successfully resolved by local law enforcement.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: Malta
- Alleged perpetrator: Kateryna Izotkina
Threat characteristics
- Imminence: Long-term. The immediate threat has been mitigated by the arrest of the perpetrator, though the strategic risk of AI-enabled fraud remains ongoing.
- Autonomy: Human-controlled. AI systems were used strictly as tools by the human perpetrator to generate text and video content, with no autonomous decision-making by the AI.
- Novelty: Evolved capability. While deepfakes and LLM-generated phishing are established, combining them to impersonate multiple high-level national and international leaders represents an evolved capability.
Impact by dimension
- Physical security: Negligible. The incident was a financial scam with no physical components, kinetic threats, or critical infrastructure targeting.
- Information security: Minor. Deepfakes of the Maltese Prime Minister and EU Commission President were used, but the operation was a localized financial fraud rather than a state-sponsored disinformation campaign.
- Sovereignty: Minor. Impersonation of top government and EU officials occurred, but it did not disrupt actual government decision-making, elections, or state authority.
- Economic security: Minor. The scam resulted in a direct financial loss of over 53,000 euros for a single victim, representing local criminal fraud rather than a systemic threat to economic security.
- Societal stability: Minor. The use of political deepfakes erodes epistemic trust in public figures, but the societal impact remains localized and limited to the fraud victims.