AI-Powered Biometric Spoofing Used to Steal Over 1,000 Bank Accounts in Vietnam

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Nguyễn Tiến Đạt and accomplices used AI-enabled facial spoofing software to bypass banks' biometric authentication, illegally accessing and trading over 1,000 bank accounts. The group manipulated victims' phone cameras to defeat security systems, resulting in significant financial theft and criminal activity across multiple Vietnamese provinces.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of an AI-enabled software tool that manipulates biometric authentication processes, which is an AI system by definition. The criminal use of this AI system directly caused harm by enabling unauthorized access to bank accounts and facilitating illegal financial transactions, fulfilling the criteria for an AI Incident. The harm is materialized and significant, involving violations of property rights and financial theft. The involvement of AI in the development and use of the biometric spoofing software is central to the incident, not merely incidental or potential. Hence, the classification as AI Incident is appropriate.[AI generated]
AI principles
SafetyRobustness & digital security

Industries
Financial and insurance services

Affected stakeholders
Consumers

Harm types
Economic/Property

Severity
AI incident

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

Bắt đối tượng Nguyễn Tiến Đạt (SN 2004) liên quan đến hơn 1.000 tài khoản ngân hàng, thu lợi bất chính hàng tỷ đồng

2026-06-27
cafef.vn
Why's our monitor labelling this an incident or hazard?
The event involves the use of an AI-enabled software tool that manipulates biometric authentication processes, which is an AI system by definition. The criminal use of this AI system directly caused harm by enabling unauthorized access to bank accounts and facilitating illegal financial transactions, fulfilling the criteria for an AI Incident. The harm is materialized and significant, involving violations of property rights and financial theft. The involvement of AI in the development and use of the biometric spoofing software is central to the incident, not merely incidental or potential. Hence, the classification as AI Incident is appropriate.
Thumbnail Image

Thủ đoạn 'qua mặt' sinh trắc học, chiếm đoạt hơn 1.000 tài khoản ngân hàng

2026-06-26
Báo điện tử Tiền Phong
Why's our monitor labelling this an incident or hazard?
The event involves the use of software that manipulates biometric authentication, which is an AI system component (facial recognition AI). The software's use directly caused harm by enabling unauthorized access to bank accounts, leading to financial theft and associated criminal harms. Therefore, this qualifies as an AI Incident because the AI system's use directly led to violations of property rights and facilitated criminal harm.
Thumbnail Image

Thủ đoạn "qua mặt" sinh trắc học, chiếm đoạt hơn 1.000 tài khoản ngân hàng

2026-06-27
xaluannews.com
Why's our monitor labelling this an incident or hazard?
The event explicitly describes the use of software that manipulates biometric authentication, which is an AI system or closely related technology, to commit fraud and illegally access bank accounts. The harm is realized and significant, involving theft and misuse of financial accounts, which constitutes harm to property and breaches of legal rights. Therefore, this is an AI Incident due to the direct and malicious use of AI-enabled biometric spoofing software causing harm.