
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Nguyễn Tiến Đạt and accomplices used AI-enabled facial spoofing software to bypass banks' biometric authentication, illegally accessing and trading over 1,000 bank accounts. The group manipulated victims' phone cameras to defeat security systems, resulting in significant financial theft and criminal activity across multiple Vietnamese provinces.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves the use of an AI-enabled software tool that manipulates biometric authentication processes, which is an AI system by definition. The criminal use of this AI system directly caused harm by enabling unauthorized access to bank accounts and facilitating illegal financial transactions, fulfilling the criteria for an AI Incident. The harm is materialized and significant, involving violations of property rights and financial theft. The involvement of AI in the development and use of the biometric spoofing software is central to the incident, not merely incidental or potential. Hence, the classification as AI Incident is appropriate.[AI generated]