A deepfake video impersonating the former Mongolian Deputy Prime Minister Amarsaikhan Sainbuyan was circulated on Facebook to promote a fraudulent investment scheme. The video, which used manipulated audio and lip movements, directed users to a website designed to harvest personal information. Fact-checkers confirmed the manipulation using Hive Moderation tools and identified the original footage as a 2024 interview.
A Facebook post reportedly used a deepfake-altered clip of then-Mongolian Deputy Prime Minister Amarsaikhan Sainbuyan to promote investment in the "Power of Siberia-2" pipeline and direct viewers to a registration website. The video allegedly modified a 2024 MONGOL TV interview with altered lip movement and added Russian audio, while the linked site sought personal information.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The deepfake video was created to impersonate a trusted public official to deceive individuals into registering for a fraudulent investment scheme.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by human malicious actors who intentionally deployed deepfake technology to create a deceptive video for a financial scam.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The incident involves AI-generated content, specifically a deepfake video, which falls under Limited Risk and is subject to transparency obligations under the EU AI Act.
AI system and alleged parties
- AI system: Hive Moderation, unspecified (Hive)
- AI purpose: Deepfake Video Generation; Voice Generation
- Behaviour type: Tool
- Alleged developer: Video generation technology developers, Synthetic media technology developers, Deepfake creators, Audio generation technology developers
- Alleged deployer: Today Information (Facebook account), Scammers in Mongolia, Scammers
- Alleged harmed parties: Social media users in Mongolia, Social media users, Mongolian investors, Investors, Financial scam victims, Facebook users in Mongolia, Facebook users, Epistemic integrity, Amarsaikhan Sainbuyan
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Minor
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Minor
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Minor, indirect Minor
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Malicious content
Reported: The report explicitly describes malicious content created and spread directly by the incident.
Directly caused: A deepfake video of the Mongolian Deputy Prime Minister was created using AI to alter his lip movements and add a Russian voiceover.
Indirectly caused: The video was shared on Facebook by the page 'Today Information', receiving at least 595 reactions.
Inferred additional harm: It is likely the video reached a larger audience on Facebook beyond those who reacted, exposing more users to the malicious content.
Privacy
Reported: The report explicitly describes privacy concerns related to the harvesting of personal data via the scam website.
Directly caused: N/A
Indirectly caused: The deepfake video directed users to a fraudulent website that harvested personal data including names, emails, and phone numbers.
Inferred additional harm: It is likely that multiple users entered their private information on the registration site, leading to unauthorized data collection and potential identity theft or targeted phishing.
Epistemic
Reported: The report explicitly describes epistemic harm caused directly by the incident through the creation of a deepfake video.
Directly caused: The AI-generated deepfake falsely depicted Deputy Prime Minister S. Amarsaikhan promoting a 'Power of Siberia-2' investment scheme.
Indirectly caused: The false video was spread on Facebook, misleading viewers into believing the official endorsed the scheme.
Inferred additional harm: The incident contributes to the broader erosion of trust in digital media and official statements due to the availability of convincing deepfakes.
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 595
Potential causes
Technology
- Deepfake Generation Tools: AI tools allowed realistic alteration of lip movements and voice dubbing.
- Lack of Real-time AI Filters: Social media platforms failed to block the deepfake at the upload stage.
Data Inputs
- Unsecured Public Video Data: An official TV interview was harvested to train and generate the deepfake.
Human Factors
- Exploitation of Public Trust: Using a high-profile official made the fraudulent investment scheme credible.
- Limited User Awareness: Viewers struggled to identify synthetic media and fell for the scam.
Process and Methods
- Delayed Moderation Action: Fact-checking occurred only after the post gained hundreds of reactions.
Regulatory Environment
- Inadequate Deepfake Controls: Lack of strict regulatory standards for labeling synthetic media online.
Information quality
- Classification confidence: High
- Reason for confidence: The report from the Mongolian Fact Checking Center is clear, provides the source of the original video, and uses a verified tool (Hive Moderation) to confirm the deepfake with 99.9% confidence. The details of the scam and the data harvested are explicitly described.
- Ambiguities identified: The exact number of users who fell victim to the scam and the total financial loss incurred are not specified.
- Alternative interpretations: None. The evidence clearly points to a deepfake-enabled phishing and financial scam.
An AI-generated deepfake video of the Mongolian Deputy Prime Minister was used on Facebook to promote a fraudulent investment pipeline scheme and harvest personal data. The incident represents a minor national security concern, demonstrating how consumer-grade deepfake tools can be used to impersonate state officials for cybercrime and financial fraud.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: Mongolia
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. The specific video has been flagged and mitigated, leaving only the long-term strategic threat of deepfake technology.
- Autonomy: Human-controlled. The AI system acted purely as a generation tool controlled and deployed by human actors.
- Novelty: Established threat. Using deepfakes of politicians for financial scams is an established threat vector seen globally.
Impact by dimension
- Physical security: Negligible. No physical security threats, kinetic attacks, or critical infrastructure impacts were reported in this incident.
- Information security: Minor. The incident used an AI deepfake to impersonate a government official, but it was aimed at financial fraud rather than state-sponsored information warfare.
- Sovereignty: Minor. Impersonation of the Deputy Prime Minister could marginally affect public trust in official communications, but did not disrupt government operations.
- Economic security: Negligible. The incident was a localized consumer scam and did not pose a systemic threat to national financial systems or strategic industries.
- Societal stability: Minor. The fraudulent website harvested personal data from users who registered, representing a minor localized threat to individual privacy.