Foreseeable misuse analysis
Reasonably foreseeable misuse and abuse scenarios are identified.
Hong Kong authorities described a fraud in which attackers used deepfake technology to fabricate a video conference impersonating senior personnel, leading to transfers and a loss of about HK$200 million.
Material financial loss and a high-profile demonstration of synthetic-media identity risk in corporate payment processes.
Impersonation of trusted executives combined with social engineering and insufficient out-of-band transaction verification.
Police investigation; the case supports stronger payment authorisation, identity verification and deepfake-awareness controls.
This record should inform control design, testing and monitoring for comparable AI systems. The incident database does not infer that every system using the same provider or model shares the same failure.
These are CRG methodology mappings from the documented incident to controls worth testing in comparable systems. They do not assert that any single control would have prevented the incident.
Reasonably foreseeable misuse and abuse scenarios are identified.
Agent tools and external APIs are allowlisted, authenticated and scoped.
Users receive appropriate disclosure when interacting with AI or AI-generated content.
The organisation maintains a consistent AI incident and hazard taxonomy.
Hong Kong Legislative Council / Hong Kong Police information · confidence 99% · last verified 23 Aug 2026
Open underlying source