YouTube Phishing Scam Uses AI-Generated Deepfake of Its CEO

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

YouTube has warned creators about a phishing scam using an AI-generated deepfake video of CEO Neal Mohan, falsely announcing changes to monetization policies. The fake video is shared privately to trick users into clicking malicious links that may steal credentials or install malware.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system generating a fake video of a CEO used in a phishing campaign that has already caused harm by stealing credentials and causing monetary losses. The AI-generated content is central to the scam's effectiveness, directly leading to harm to individuals (creators) and communities (YouTube creators). Therefore, this qualifies as an AI Incident due to realized harm caused by the AI system's use in malicious activity.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRespect of human rightsRobustness & digital securitySafetyTransparency & explainability

Industries
Media, social platforms, and marketingDigital security

Affected stakeholders
Consumers

Harm types
Economic/PropertyReputationalHuman or fundamental rightsPsychological

Severity
AI incident

AI system task:
Content generation

In other databases

Articles about this incident or hazard

Thumbnail Image

YouTube scam warning: How hackers using AI video of CEO Neal Mohan to target people - The Times of India

2025-03-06
The Times of India
Why's our monitor labelling this an incident or hazard?
The event involves an AI system generating a fake video of a CEO used in a phishing campaign that has already caused harm by stealing credentials and causing monetary losses. The AI-generated content is central to the scam's effectiveness, directly leading to harm to individuals (creators) and communities (YouTube creators). Therefore, this qualifies as an AI Incident due to realized harm caused by the AI system's use in malicious activity.
Thumbnail Image

YouTube Warns Creators of AI-Generated Phishing Scams Impersonating CEO

2025-03-06
Analytics Insight
Why's our monitor labelling this an incident or hazard?
The phishing scam involves AI-generated content impersonating a high-profile individual to deceive users, directly leading to harm by tricking users into giving away sensitive information and risking malware infection. The AI system's use in generating realistic fake videos is central to the harm caused. Therefore, this qualifies as an AI Incident due to realized harm caused by the AI system's malicious use.
Thumbnail Image

YouTubers are being scammed with AI-generated deepfake videos

2025-03-06
PCWorld
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems to generate deepfake videos that directly lead to phishing scams targeting YouTubers. This results in realized harm through the theft of login credentials and potential account compromise, which constitutes a violation of rights and harm to individuals. Therefore, this qualifies as an AI Incident because the AI system's use directly leads to harm through malicious impersonation and fraud.
Thumbnail Image

YouTube Alerts Creators About Phishing Emails Targeting Login Credentials - IT Security News

2025-03-07
IT Security News
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI-generated deepfakes in a phishing campaign that directly leads to harm by tricking users into compromising their login credentials. This constitutes a violation of user security and privacy, which falls under harm to persons or communities. Since the AI system's use directly facilitates the phishing attack and resulting harm, this qualifies as an AI Incident.
Thumbnail Image

AI-Generated Video of YouTube's CEO Used In Phishing Attack

2025-03-05
PCMAG
Why's our monitor labelling this an incident or hazard?
The phishing attack involves the use of an AI system to generate a realistic video of YouTube's CEO, which is then exploited to trick users into harmful actions like downloading malware or giving up login credentials. The AI-generated content is central to the scam's effectiveness, directly leading to harm including loss of access to accounts and misleading customers. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to harm to individuals and communities through fraud and security breaches.
Thumbnail Image

YouTube warns creators an AI-generated video of its CEO is being used for phishing scams

2025-03-04
The Verge
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (deepfake video generation) used in phishing scams that have directly led to harm by attempting to steal user credentials, which is a violation of user security and privacy. The harm is realized or ongoing as phishing scams are actively targeting users. Therefore, this qualifies as an AI Incident due to the direct involvement of AI-generated content causing harm through deception and fraud.
Thumbnail Image

Scammers use deepfake of YouTube's CEO in new phishing attack

2025-03-04
Android Police
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (deepfake video generation) used in a phishing scam that has directly led to harm—malware installation and theft of credentials and financial data. The harm to individuals' security and privacy qualifies as harm to persons. The AI system's use is central to the incident, as the deepfake video is the key tool enabling the scam. Hence, this is an AI Incident, not merely a hazard or complementary information.
Thumbnail Image

YouTube CEO Neal Mohan used for AI video scam

2025-03-05
The Hindu
Why's our monitor labelling this an incident or hazard?
The AI system is explicitly involved in generating deepfake videos used maliciously in phishing scams. This use of AI directly leads to harm by enabling fraud and potential malware infection, which fits the definition of an AI Incident due to realized harm to individuals' security and privacy. The event involves the use and misuse of AI-generated content causing actual harm, not just potential harm or general information, thus qualifying as an AI Incident.
Thumbnail Image

YouTube Warns Creators About AI-Generated Video of Its CEO

2025-03-05
PetaPixel
Why's our monitor labelling this an incident or hazard?
The event involves an AI system generating a deepfake video of a CEO, which is then used maliciously in phishing scams. The harm is realized as creators are targeted for credential theft and malware installation, directly linked to the AI-generated content. This meets the criteria for an AI Incident because the AI system's use has directly led to harm (credential theft, malware risk) to individuals. The event is not merely a potential risk or a general update but describes an active harm caused by AI misuse.
Thumbnail Image

YouTube has a serious phishing problem, and AI is to blame

2025-03-05
Android Headlines
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems to create deepfake videos that are used maliciously in phishing attacks. These attacks have directly led to harm by tricking users into compromising their credentials or devices, which constitutes harm to individuals (a). The AI system's use in generating realistic fake videos is pivotal to the scam's effectiveness. Therefore, this qualifies as an AI Incident due to realized harm caused by the AI-enabled phishing scam.
Thumbnail Image

YouTube Warns of Phishing Attempts Via Fake AI Video of Its CEO

2025-03-06
MEDIANAMA
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI-generated deepfake video used in phishing attempts, which is a direct misuse of an AI system leading to potential harm to users' security and privacy. The phishing attempts could cause harm such as credential theft and malware infection, fulfilling the criteria for harm to persons or communities. The AI system's role is pivotal as it enables the creation of convincing fake content used in the scam. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

YouTube warns of phishing video using its CEO as bait

2025-03-06
TechRadar
Why's our monitor labelling this an incident or hazard?
The event involves an AI system explicitly: AI-generated deepfake video of the CEO used as bait in a phishing scam. The AI system's use directly leads to harm (phishing, credential theft, account hijacking, and crypto scams), which constitutes harm to people and communities. Therefore, this qualifies as an AI Incident under the definition of harm caused by AI system use.
Thumbnail Image

Deepfake Videos of YouTube CEO Phish Creators

2025-03-06
darkreading.com
Why's our monitor labelling this an incident or hazard?
The event involves AI systems explicitly through the creation of deepfake videos, which are used maliciously to deceive victims into providing credentials, resulting in harm such as theft and malware infection. This constitutes a direct AI Incident because the AI-generated content is pivotal in enabling the phishing scam and consequent harm to users. The harm is realized, not just potential, as victims are targeted and credentials stolen, fulfilling the criteria for an AI Incident under violations of rights and harm to individuals.
Thumbnail Image

Un video fake del Ceo di YouTube viene usato per una campagna di phishing

2025-03-05
Wired Italia
Why's our monitor labelling this an incident or hazard?
The use of AI-generated deepfake videos to conduct phishing attacks constitutes an AI Incident because the AI system's outputs are directly used to cause harm (credential theft, fraud). The article details an ongoing campaign with actual harm to users, not just a potential risk. Therefore, this is an AI Incident involving harm to individuals (harm to persons through fraud and potential financial loss).
Thumbnail Image

YouTube: video deepfake del CEO Neal Mohan usato per le truffe

2025-03-05
Punto Informatico
Why's our monitor labelling this an incident or hazard?
The event involves the use of an AI system (deepfake technology) to create a realistic fake video of a public figure, which is then used maliciously to trick users into giving away sensitive information. This constitutes a direct harm to individuals (harm to persons through fraud and potential identity theft). Therefore, it meets the criteria of an AI Incident because the AI system's use has directly led to harm.
Thumbnail Image

YouTube video AI fake del CEO dell'azienda usato per phishing

2025-03-06
HTML.it
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (deepfake video generation) used in phishing attacks that have already caused harm by tricking users into giving up credentials and losing control of their accounts. This is a direct AI Incident because the AI-generated content is pivotal in enabling the phishing scam and resulting harm. The harm includes violation of user rights and property harm (account hijacking).
Thumbnail Image

Truffa ai danni dei creator su YouTube a causa dell'AI: cosa sta succedendo

2025-03-06
PC Professionale
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI-generated deepfake video technology to impersonate the YouTube CEO, which is used maliciously to deceive users into providing sensitive data and installing malware. This has directly led to harm through phishing and potential financial theft. The AI system's use is central to the incident, as the realistic deepfake video is the key tool enabling the scam. Hence, it meets the criteria for an AI Incident because the AI system's use has directly led to harm to persons and property.