AI Incident Database - Incident 1117
Source evidence cited by public records. This page shows where the source is used, its trust tier, and when it was last checked in the seed.
Records using this source
- deepfake-technology-developers
entity | 4 July 2026 | 70%
deepfake-technology-developers - organisation named in the AI Incident Database harm index.
- synthetic-audio-generation-technology-developers
entity | 4 July 2026 | 70%
synthetic-audio-generation-technology-developers - organisation named in the AI Incident Database harm index.
- epistemic-integrity
entity | 30 June 2026 | 70%
epistemic-integrity - organisation named in the AI Incident Database harm index.
- national-security-and-intelligence-stakeholders
entity | 4 June 2026 | 70%
national-security-and-intelligence-stakeholders - organisation named in the AI Incident Database harm index.
- government-of-north-korea
entity | 18 Mar 2026 | 70%
government-of-north-korea - organisation named in the AI Incident Database harm index.
- lazarus-group
entity | 24 Nov 2025 | 70%
lazarus-group - organisation named in the AI Incident Database harm index.
- macos-users
entity | 24 Nov 2025 | 70%
macos-users - organisation named in the AI Incident Database harm index.
- web3
entity | 24 Nov 2025 | 70%
web3 - organisation named in the AI Incident Database harm index.
- bluenoroff
entity | 23 June 2025 | 70%
bluenoroff - organisation named in the AI Incident Database harm index.
- cryptocurrency-infrastructure
entity | 23 June 2025 | 70%
cryptocurrency-infrastructure - organisation named in the AI Incident Database harm index.
- north-korea
entity | 23 June 2025 | 70%
north-korea - organisation named in the AI Incident Database harm index.
- unnamed-web3-employee
entity | 23 June 2025 | 70%
unnamed-web3-employee - organisation named in the AI Incident Database harm index.
- North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee
event | 23 June 2025 | 78%
An alleged phishing scheme involving actors linked to North Korea used purported AI-generated deepfake videos of company executives to deceive a Web3 employee during a fake Zoom call. The target was reportedly tricked into installing macOS malware disguised as a "Zoom extension," leading to the deployment of spyware, a keylogger, and a crypto wallet stealer. The attackers reportedly used Telegram and spoofed Zoom domains to orchestrate the breach.