
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
In the first half of 2026, cybercriminals in Italy used AI-enhanced techniques, including deepfakes and infostealer malware, to conduct sophisticated phishing and fraud. This led to the exposure of 2.5 billion personal data records on the dark web, causing widespread identity theft and privacy violations.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves AI systems in the form of deepfake audio and video used in attacks, as well as malware that collects sensitive data. These AI-enabled attacks have directly led to the exposure of massive amounts of personal data on the dark web, which is a clear harm to individuals' privacy and security, fitting the definition of an AI Incident. The article describes realized harm (data breaches and account theft) linked to AI-enabled methods, not just potential harm or general AI developments. Hence, the classification is AI Incident.[AI generated]