Surge in Phishing Scams Exploiting DeepSeek AI Tool

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Within two months, scammers misused the popular free AI tool DeepSeek to create 3000 highly realistic phishing websites. These counterfeit sites tricked users into downloading fake apps and making unwarranted payments, resulting in financial losses and data breach risks for numerous victims.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the AI system DeepSeek and the proliferation of fake websites impersonating it to scam users. The harm includes financial fraud and personal data theft, which are direct harms to individuals. Although the AI system is not malfunctioning, the misuse of its brand and identity by malicious actors is causing harm. This fits the definition of an AI Incident because the development and use of the AI system is directly linked to the harm through its impersonation and exploitation by scammers.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRobustness & digital securitySafetyTransparency & explainabilityRespect of human rights

Industries
Digital securityFinancial and insurance servicesConsumer services

Affected stakeholders
Consumers

Harm types
Economic/PropertyHuman or fundamental rights

Severity
AI incident

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

獲習近平認可後 中國官僚追捧DeepSeek

2025-03-18
Rti 中央廣播電臺
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (DeepSeek) actively used by government officials in sensitive areas, which implies AI system involvement. The article mentions expert warnings about the dangers of overreliance and misinformation generation, indicating plausible future harm. However, no direct or indirect harm has been reported as having occurred. Therefore, this situation fits the definition of an AI Hazard, as the development and use of the AI system could plausibly lead to harm, especially given the concerns about misinformation and uncritical use by officials.
Thumbnail Image

美商務部禁用DeepSeek 創聯邦政府部會首例 - 自由財經

2025-03-18
ec.ltn.com.tw
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (DeepSeek chatbot) and concerns about its use leading to potential harm, specifically violations of data privacy and risks to sensitive government information. However, the article does not report any actual harm or incident caused by the AI system; rather, it reports a ban to prevent such harm. Therefore, this is an AI Hazard, as the use of the AI system could plausibly lead to an AI Incident involving data privacy breaches or national security threats if not controlled. The event is not Complementary Information because it is not an update or response to a past incident but a preventive policy action. It is not unrelated because it clearly involves an AI system and potential harm.
Thumbnail Image

為保障資訊安全 美國商務部禁用DeepSeek | 美國官員 | 電子設備

2025-03-19
NTDChinese
Why's our monitor labelling this an incident or hazard?
The article does not report any realized harm caused by DeepSeek but highlights concerns and preventive measures taken by governments to avoid potential data privacy violations and sensitive information leaks. The involvement of the AI system DeepSeek is explicit, and the measures taken indicate a credible risk of future harm if the system were used on government devices. Therefore, this event fits the definition of an AI Hazard, as it plausibly could lead to an AI Incident involving violations of data privacy and national security.
Thumbnail Image

198人民幣買永久會員? DeepSeek仿冒網站急增

2025-03-16
Yahoo News
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the AI system DeepSeek and the proliferation of fake websites impersonating it to scam users. The harm includes financial fraud and personal data theft, which are direct harms to individuals. Although the AI system is not malfunctioning, the misuse of its brand and identity by malicious actors is causing harm. This fits the definition of an AI Incident because the development and use of the AI system is directly linked to the harm through its impersonation and exploitation by scammers.
Thumbnail Image

DeepSeek問世兩個月 冒牌釣魚網站激增

2025-03-15
Yahoo News (Taiwan)
Why's our monitor labelling this an incident or hazard?
The article details realized harm caused by malicious actors exploiting the AI system DeepSeek's brand to create phishing websites and fake apps that deceive users into paying for non-existent or malicious services. This has directly led to economic harm to individuals and potential privacy breaches, which fall under harms to persons and property. The AI system's presence is explicit, and the harm is directly linked to its use and misuse. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

DeepSeek問世兩個月 冒牌釣魚網站激增 | 兩岸 | 中央社 CNA

2025-03-15
Central News Agency
Why's our monitor labelling this an incident or hazard?
The event involves the use and misuse of an AI system (DeepSeek) and its brand. The harm is direct: users have been financially scammed and exposed to malware, which threatens their privacy and economic interests. The phishing websites and fake apps impersonate the AI system, leading to realized harm. This fits the definition of an AI Incident because the development and use of the AI system (DeepSeek) has directly led to harm to people (economic loss and privacy risks). The article does not merely warn of potential harm but reports actual harm occurring due to the AI system's misuse.
Thumbnail Image

198人民幣買永久會員? DeepSeek仿冒網站急增

2025-03-16
on.cc東網
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the AI system DeepSeek and details how malicious actors have created fake websites and apps mimicking it to scam users. This misuse of the AI system's identity has caused direct harm to users through financial loss and data theft. Therefore, this qualifies as an AI Incident because the development and use of the AI system (DeepSeek) is central to the harm caused by the fraudulent activities exploiting its name and interface.