The Deepfake Incident Tracker: Verified Cases, Updated Through 2026
This is a running, sourced log of confirmed deepfake fraud and abuse cases — not a list padded with rumors or unverified social posts. Every entry links to a named organization, a court record, or independently confirmed reporting.
UncovAI is an AI content detection platform that checks text, images, video, and audio for signs of AI generation — the same category of synthetic media behind every case below.
2024
Arup — Hong Kong, February 2024. A finance employee joined a video call with people who looked and sounded exactly like the company's CFO and several colleagues, and authorized 15 transfers totaling roughly $25.6 million. Every other person on the call was an AI-generated clone; the funds were never recovered. It remains the largest confirmed deepfake-enabled wire fraud case to date, and the reference point most fraud teams now build verification policy around. (Source: CFO Dive, 2024)
2025–2026
Bombay Stock Exchange CEO impersonation, early 2026. Scammers took an existing interview of the BSE's CEO and used AI voice and video cloning to fabricate a new video in which he appeared to give stock tips and promise guaranteed returns to retail investors. The exchange issued a public warning after the clip began circulating — one of a growing pattern of fabricated "insider tip" videos using cloned executives to run investment scams. (Source: BSE public advisory, early 2026)
Grok non-consensual imagery incident, early 2026. Users exploited permissive content guardrails on xAI's Grok to mass-generate sexualized, non-consensual images of real people, including public figures, at a volume that overwhelmed platform moderation. The incident triggered litigation and renewed regulatory pressure for stricter safety constraints on generative image tools. (Source: reporting, early 2026)
The pattern across confirmed cases
The mechanism is almost never a technical exploit. In Arup, the BSE case, and most contact-center fraud, the victim followed a normal process — joined a scheduled call, recognized a familiar voice, acted on a video they had no reason to doubt. The fraud works because it targets trust in a channel, not a system vulnerability.
Voice cloning needs almost no source material — publicly available tools can produce a usable clone from about three seconds of audio (McAfee, 2023), so any executive who's given a public interview or earnings call already has enough audio in the wild to be cloned. That's the exact gap audio deepfake detection and real-time meeting protection are built to close.
How we verify a case before adding it
An incident is added only once it traces to at least one of: a named organization's own statement or advisory, court filings or law-enforcement reporting, or reporting from an outlet that independently confirmed the case rather than aggregating another blog's list. If a widely-shared "deepfake incident" doesn't meet that bar, we leave it out rather than pad the count.
Frequently asked questions
What was the largest confirmed deepfake fraud case?
The Arup case in Hong Kong (February 2024): $25.6 million transferred across 15 payments after a video call where every participant except the victim was an AI-generated clone.
What criteria are used to verify an incident before it's added here?
A named organization's own statement, court or law-enforcement records, or independent reporting that confirmed the case directly — not another list repeating unverified claims.
Is most deepfake harm financial?
No. Over 80% of Resemble AI's verified 2025 incidents had no disclosed financial figure — much of the harm is non-financial, including harassment, reputational damage, and non-consensual imagery.
Have a verified case we're missing?
Send us a source and we'll review it for the next update.
Submit a case →
