An 86-year-old Ontario retiree lost nearly $1 million after being targeted by a cryptocurrency investment scam. The scam began with a Facebook advertisement featuring an AI-generated deepfake video of the Canadian Prime Minister. The victim was subsequently manipulated into liquidating her retirement funds and mortgaging her home, resulting in severe financial hardship.
An Ontario retiree, Judy Skene, reportedly lost nearly $1 million after a Facebook ad featuring an alleged AI-generated deepfake video of Prime Minister Mark Carney drew her into a cryptocurrency investment scam. Reports said scammers later persuaded her to liquidate retirement funds, mortgage her condo, and take a credit-card cash advance.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The incident involved scammers using an AI-generated deepfake of a political leader to execute a targeted cryptocurrency investment scam, resulting in massive financial fraud.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by human scammers who intentionally deployed an AI-generated deepfake video post-deployment to defraud the victim.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The incident involves 'AI-generated content such as deepfakes', specifically an 'AI-generated deepfake video of Prime Minister' Justin Trudeau used in an advertisement.
AI system and alleged parties
- AI system: None named
- AI purpose: Deepfake Video Generation; Voice Generation
- Behaviour type: Tool
- Alleged developer: Video generation technology developers, Synthetic media generation technology developers, Synthetic audio generation technology developers, Deepfake technology developers
- Alleged deployer: Scammers impersonating Mark Carney, Scammers, Cryptocurrency scammers
- Alleged harmed parties: Targets of scams, Targets of scammers in Canada, Mark Carney, Judy Skene, Investors, Epistemic integrity, Elderly investors, Elderly individuals in Canada, Elderly individuals, Cryptocurrency investors
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Minor, indirect Minor
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Minor
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Financial
Reported: The report explicitly describes a financial loss of nearly $1 million for the single occurrence.
Directly caused: Judy Skene lost approximately $985,000, which included cashing in her $650,000 RRIF, taking a $300,000 mortgage, and a $35,000 credit card cash advance.
Indirectly caused: She lost her entitlement to Old Age Security payments and access to the Canadian Dental Care Plan due to cashing in her RRIF, and had her mortgage, condo fees, and credit card payments bounce.
Inferred additional harm: N/A
Malicious content
Reported: The report explicitly describes malicious content created and spread directly by the incident in the form of a deepfake video.
Directly caused: An AI-generated deepfake video of Prime Minister Justin Trudeau was created and spread via a Facebook advertisement to promote a fraudulent cryptocurrency scheme.
Indirectly caused: N/A
Inferred additional harm: It is likely that the deepfake video reached a wider audience on Facebook beyond the single reported victim, exposing numerous other users to the malicious content.
Psychological
Reported: The report explicitly describes psychological harm to the victim, noting she was devastated and felt like the world ended.
Directly caused: N/A
Indirectly caused: Judy Skene suffered severe emotional distress and trauma, describing herself as 'devastated' and feeling like 'the world ended' after losing her life savings.
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Management
- Prioritizing Ad Revenue: Social media management prioritized profits over user safety.
- Insufficient Risk Assessment: Management failed to assess risks of AI deepfakes in active scams.
Technology
- AI Deepfake Generation: Scammers used advanced AI to create a convincing deepfake of the PM.
- Lack of Deepfake Detection: Social platforms lacked tools to automatically detect and block deepfakes.
- Insecure Platform Algorithms: Algorithms recommended the fraudulent ad to vulnerable users.
Data Inputs
- Targeted Social Media Data: Scammers used platform data to target vulnerable demographics.
- Unverified Ad Content Data: Ad networks accepted unverified video data containing deepfakes.
Human Factors
- Trust in AI-Impersonated Figures: The victim trusted the realistic AI video of the Prime Minister.
- Vulnerability of Elderly Users: Elderly victim was susceptible to high-pressure social engineering.
- Overconfidence in Online Ads: Victim assumed advertisements on Facebook were vetted.
Process and Methods
- Inadequate Ad Vetting Process: Facebook failed to vet the legitimacy of the deepfake video.
- Incomplete Fraud Reporting Loop: Reporting mechanisms did not trigger rapid removal of the ad.
Regulatory Environment
- Lack of Deepfake Regulation: Absence of strict laws governing the creation and spread of AI.
- No Platform Liability Laws: Social media platforms face minimal liability for hosting scams.
- Weak Crypto Scam Oversight: Regulatory gaps in crypto exchanges allow easy laundering of funds.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide clear, consistent, and detailed accounts of the scam, the specific financial losses, the victim's identity, and the role of the AI-generated deepfake video. There is no conflicting information regarding the primary events.
- Ambiguities identified: The specific AI tool or platform used to generate the deepfake video is not identified.
- Alternative interpretations: None. The evidence clearly points to a targeted financial scam initiated by an AI deepfake.
An 86-year-old Canadian citizen was defrauded of nearly $1 million in a cryptocurrency scam initiated by an AI-generated deepfake video of Prime Minister Justin Trudeau. While the incident represents a devastating personal financial loss and highlights the rising threat of high-fidelity public figure impersonation, it has minor direct implications for national security.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: Canada
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. The specific incident is resolved, but the underlying threat of deepfake-enabled fraud represents an ongoing strategic concern for consumer protection and public trust.
- Autonomy: Human-controlled. The AI was used purely as a content-generation tool by human scammers who directed the fraudulent campaign and interactions.
- Novelty: Evolved capability. While deepfakes and financial scams are established, the high-fidelity impersonation of a sitting Prime Minister for targeted financial fraud represents an evolved and increasingly sophisticated threat.
Impact by dimension
- Physical security: Negligible. No threat to physical systems, critical infrastructure, or human safety was reported in this incident.
- Information security: Minor. Use of an AI deepfake of the Canadian Prime Minister to deceive citizens represents an evolved capability in public figure impersonation, though deployed for financial fraud rather than geopolitical influence.
- Sovereignty: Minor. Unauthorized deepfake impersonation of the head of government on public platforms slightly erodes trust in official communications, but did not disrupt core government functions.
- Economic security: Minor. High-value individual financial fraud of nearly $1 million occurred, but it lacks systemic impact on national financial systems or strategic industries.
- Societal stability: Minor. Highlights the vulnerability of elderly citizens to sophisticated AI-enabled fraud, but does not threaten broader social cohesion or human rights at scale.