Purported Russian-Linked Network Allegedly Used Deepfake of Maria Ressa on Facebook and Bing to Promote Cryptocurrency Scam Targeting Filipinos

A Russian-linked scam network used AI-generated deepfakes of journalist Maria Ressa to promote cryptocurrency scams and spread disinformation on Facebook and Microsoft Bing. The operation involved creating impostor websites mimicking Rappler and CNN Philippines to lend credibility to the fraud. While platforms removed the specific content, the report highlights the ongoing challenge of 'whack-a-mole' in mitigating AI-enabled disinformation and financial fraud.

A purportedly Russian-linked scam network allegedly circulated an AI-generated deepfake of journalist Maria Ressa on Facebook and Microsoft Bing. The video reportedly manipulated a 2022 interview to falsely depict Ressa endorsing cryptocurrency. Fraudulent websites allegedly impersonating Rappler and CNN Philippines reportedly amplified the scam. Investigators reportedly linked the operation to a fraudulent network targeting Filipino audiences. Meta and Microsoft removed the content, but similar scams allegedly continue to resurface.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation

The incident involved using AI-generated voice clones and deepfakes to impersonate a trusted individual for financial benefit through a cryptocurrency scam.

Additional risk subdomains

  • 3.1 False or misleading information: The campaign generated false news articles and videos to mislead the public about Maria Ressa's involvement in a cryptocurrency scam.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The incident was caused by a Russian scam network intentionally deploying AI-generated deepfakes to defraud users.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Limited Risk: The report describes the creation of AI-generated deepfakes, which are subject to transparency obligations under the EU AI Act to ensure users are aware they are interacting with synthetic content.

AI system and alleged parties

  • AI system: unspecified
  • AI purpose: Deepfake Video Generation; Voice Generation
  • Behaviour type: Tool
  • Alleged developer: Unknown deepfake technology developers, Unknown AI voice cloning developers
  • Alleged deployer: TD Globus Contract, Russian-linked scam network, M1 Shop
  • Alleged harmed parties: Rappler, Public trust in media institutions, Potential cryptocurrency scam victims, Maria Ressa, Filipino social media users, CNN Philippines

Harm severity

Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Minor, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Negligible, indirect Negligible
  • Psychological: direct Negligible, indirect Negligible
  • Epistemic: direct Minor, indirect Substantial
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

Malicious content

Reported: The report explicitly describes the creation and spread of malicious deepfake video and audio content.

Directly caused: An AI-generated deepfake video and voice clone of Maria Ressa was created and distributed on Facebook and Microsoft Bing to promote a scam.

Indirectly caused: N/A

Inferred additional harm: Similar malicious deepfakes targeting other Filipino businessmen and media anchors were also circulated using similar methods.

Epistemic

Reported: The report explicitly describes epistemic harm through the creation of fake news articles and a deepfake video that fabricated statements by Maria Ressa.

Directly caused: The scammers created cloned websites of Rappler and CNN Philippines containing fabricated articles and an AI-generated video to mislead the public.

Indirectly caused: The use of cloned news sites and deepfakes of journalists undermines public trust in legitimate news organizations and media credibility.

Inferred additional harm: The proliferation of such highly convincing deepfakes erodes the general public's trust in digital information and shared consensus reality.

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 1
  • People reportedly exposed: 22000

Potential causes

Management

  • Inadequate Ad Monitoring: Platforms failed to proactively monitor and block AI-generated scam ads.
  • Profit from Disinformation: Platforms profit from ad revenues, reducing incentive for strict pre-screening.

Technology

  • Open-Source AI Misuse: Open-source LLMs allow bad actors to modify code and strip watermarks.
  • Watermark Removal Tech: Existing tools can easily remove watermarks designed to label AI content.
  • Realistic AI Voice Generation: Generative AI voice cloning mimics authoritative voices to deceive users.

Data Inputs

  • Scraped Media Data: Scraped original video and audio utilized to train and generate deepfakes.
  • Lack of Provenance Data: Absence of secure metadata on original media allowed unauthorized manipulation.

Human Factors

  • User Inattention: Users not paying attention fail to notice lip-syncing errors in deepfakes.
  • Trust in Authority Figures: Scammers exploit trust in journalists' reputations to make scams believable.

Process and Methods

  • Weak Ad Review Processes: Bing and Facebook allowed fraudulent ads promoting deepfakes to be published.
  • Slow Platform Response: Delayed takedowns allowed deepfakes to garner tens of thousands of views.
  • Whack-a-Mole Domain Tactics: Scammers rapidly register new domains to bypass platform domain bans.

Regulatory Environment

  • Lack of Platform Accountability: No strong legal frameworks to hold platforms liable for hosting fake ads.
  • Anonymity in Domain Registration: Scammers exploit loose domain registration rules to remain anonymous.

Information quality

  • Classification confidence: High
  • Reason for confidence: The report is highly detailed, coming directly from Rappler (the targeted organization) and supported by a digital forensic investigation by Qurium, providing clear evidence of the scam's mechanics and impact.
  • Ambiguities identified: The specific AI models used to generate the voice clone and deepfake video are not identified.

A Russian-linked scam network utilized AI-generated deepfakes and voice clones of Nobel laureate Maria Ressa to run cryptocurrency fraud campaigns targeting Philippine audiences. While demonstrating evolved capabilities in synthetic media generation and ad-network evasion, the incident's impact remains confined to localized financial fraud and reputational damage, posing minor national security concerns.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Multiple nations
  • Primary target: Philippines
  • Alleged perpetrator: Russian scam network

Threat characteristics

  • Imminence: Long-term. Represents an ongoing strategic concern regarding the proliferation of deepfake technology for fraud rather than an immediate national security crisis.
  • Autonomy: Human-controlled. The AI systems were utilized strictly as tools by human operators to generate specific media assets.
  • Novelty: Evolved capability. While deepfake scams are established, the integration of voice cloning with multi-layered ad-evasion networks targeting specific national figures represents an evolved threat.

Impact by dimension

  • Physical security: Negligible. No threats to physical systems, critical infrastructure, or human safety were reported in this incident.
  • Information security: Minor. Foreign-linked network deployed AI-generated deepfakes of a prominent journalist to spread disinformation, but it was primarily a financially motivated scam rather than state-directed information warfare.
  • Sovereignty: Negligible. No impact on state authority, government operations, or constitutional processes.
  • Economic security: Minor. Involves localized financial fraud and cryptocurrency scams, but does not threaten national economic stability or strategic industries.
  • Societal stability: Minor. Targeted reputational damage against a prominent journalist and potential erosion of public trust in media, but no mass-scale societal disruption.
Explore in the interactive Incident Tracker