AI-Driven Phishing Scam Targets Gmail Users

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Sam Mitrovic, a Microsoft solutions consultant, reported a phishing scam using AI to impersonate Google support. The scam involved fake account recovery notifications and phone calls claiming to be from Google Sydney. The AI-generated calls aimed to deceive users into revealing their Gmail credentials, posing significant privacy and security risks.[AI generated]

Why's our monitor labelling this an incident or hazard?

This event describes a realized fraud scheme in which generative AI–produced voices are directly used by attackers to deceive victims and cause financial loss. The misuse of an AI system (voice cloning) has led to actual harm (drained savings), meeting the criteria for an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securitySafetyAccountabilityTransparency & explainabilityRespect of human rights

Industries
Digital securityConsumer servicesIT infrastructure and hosting

Affected stakeholders
Consumers

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Business function:
Citizen/customer service

AI system task:
Content generationInteraction support/chatbots

In other databases

Articles about this incident or hazard