AI incident #1163 ·
Purported Face‑Swap Technology Reportedly Used to Circumvent Financial Platform's Facial Recognition Security in Nanjing, China
What happened
In Nanjing, Jiangsu Province, a defendant (Fu Mou) was convicted in October 2024 for allegedly using AI‑powered face‑swap software to bypass an unnamed financial platform's facial recognition system. Authorities reported that he obtained over 1.95 million pieces of personal data, accessed 23 victims' payment accounts, changed passwords for several, and used one linked bank card to make purchases. Prosecutors said only one platform was successfully breached.
Editor's notes (AI Incident Database)
Timeline note: The reporting indicates that the suspect in the case was sentenced in October 2024. The incident ID date of 10/15/2024 is an approximation. Public reporting on this incident appears to have emerged on 07/18/2025. Suspect name note: Chinese legal reporting often partially anonymizes defendants' names by publishing only the surname followed by the character 某 (Mou), meaning "a certain" or "someone." In this case, the reported perpetrator is identified as 符某 (Fu Mou), indicating that the surname is Fu but the given name has not been disclosed.
Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.
News reports (2)
Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.
Who was involved
- Alleged deployer
- Synthetic media creators Fu Mou Deepfake creators Cybercriminals
- Alleged developer
- Synthetic video generation technology developers Synthetic media generation technology developers Face-swap technology developers Deepfake technology developers
- Alleged harmed party
- Unnamed financial payment platform Individuals affected by compromise of 1.95 million+ personal records 23 unnamed victims whose payment accounts were accessed
AI systems implicated
Synthetic video generation technologySynthetic media generation technologyFinancial payment platformsFace-swap technologyDeepfake technologyAI-enabled decision support systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- Malicious Actors & Misuse
- Risk subdomain
- 4.3 Fraud, scams, and targeted manipulation
- Causal entity
- Human
- Intent
- Intentional
- Timing
- Post-deployment
- Harm level
- —
- Sectors
- —
- Countries
- —
Risk entries describing this failure mode
Entries from the MIT AI Risk Repository coded to subdomain 4.3.
- Impersonation/identity theft
"Impersonation/identity theft - Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them."
- IP/copyright loss
"IP/copyright loss - Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents."
- Dehumanisation/objectification
"Dehumanisation/objectification - Use or misuse of a technology system to depict and/or treat people as not human, less than human, or as objects."
- Defamation/libel/slander
"Defamation/libel/slander - Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group, or organisation."
- Financial and business
"Financial and Business - Use or misuse of a technology system in a manner that damages the financial interests of an individual or group, or which causes strategic, operational, legal or financial harm to a business or...
- Cheating/plagiarism
"Cheating/plagiarism - Use of another person’s or group’s words or ideas without consent and/or acknowledgement."
- Cybersecurity
"LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or...
- Domain-Specific Misuses
"Improvements in LLMs may exert greater pressure to apply LLMs to various domains, such as health and education (Eloundou et al., 2023). Crude efforts to use LLMs in such domains, however, may incur harm and should be di...
Related incidents on the AI Incident Database
Linked by AIID editors or by its text-similarity model.
Incidents in the same risk subdomain
- Italian Mediaset Journalist Safiria Leccese's Image Was Reportedly Used in a Purportedly AI-Generated Fake Loan Scam
- Scammers Reportedly Used AI-Cloned Daughter's Voice to Defraud Bay Area Mother in Fake Kidnapping Call
- Texas Man Arturo Hernandez Allegedly Published AI-Generated Deepfake Pornography Depicting Women in TAKE IT DOWN Act Case
- Guelph, Ontario, Woman Reportedly Lost $14,000 in Purported Deepfake MrBeast Cryptocurrency Scam
- Purportedly AI-Recreated Clips from Beastie Boys' 'Sabotage' Video Reportedly Appeared in FBI Promotional Video Posted by Kash Patel
- Ahmedabad Aadhaar Fraud Racket Reportedly Used Purportedly AI-Generated Deepfakes to Change Businessman's Linked Mobile Number
Other incidents involving Synthetic media creators
- Delhi Man Allegedly Used AI to Create and Circulate Obscene Images of College Acquaintance
- Wyoming Woman's Childhood Photograph Reportedly Used to Generate Thousands of Explicit Images with Grok
- Man in Egypt Reportedly Convicted of Using AI-Fabricated Sexual Content to Blackmail Relative
- Two Men Allegedly Created and Distributed Purportedly AI-Generated Sexual Images of 22 Women in Silleda, Galicia
- Texas Man Arturo Hernandez Allegedly Published AI-Generated Deepfake Pornography Depicting Women in TAKE IT DOWN Act Case
- Lyft Driver in Boca Raton, Florida, Allegedly Used Purported Google Gemini-Generated Image to Support False $75 Damage Fee