Submit incident
Documented

A Scammer Deepfaked a BBC Presenter's Voice and Walked Away with GBP 20,000

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1475View source ↗
LinkedInX

What happened

In March 2024, Incognito CEO Howard Carter believed he had secured a celebrity endorsement deal with BBC science presenter Liz Bonnin. The negotiation took place over WhatsApp voice messages and email, which was unremarkable. What Carter did not know was that the voice in those messages was not Bonnin's. It was a clone, generated using AI, and the person conducting the negotiation was a scammer who had never spoken to Bonnin and had no authority to represent her.

The deception was built in two layers. A fake Facebook profile presenting as Bonnin gave the initial outreach a surface of credibility, and the voice messages supplied the feeling of personal contact that text alone cannot. Carter paid GBP 20,000 for what he believed was a legitimate licensing agreement. The real Bonnin knew nothing about any of it until her image appeared in Incognito's advertising materials, without her consent or any payment to her.

Bonnin reported the incident publicly. AI voice experts who analyzed the WhatsApp recordings identified the fake through acoustic inconsistencies: irregular accent patterns, unnatural cadence, and a flatness in delivery that human speech does not typically carry. The analysis confirmed what Bonnin already knew, that she had played no part in any deal, but it could not recover Incognito's money or undo the reputational exposure that her unauthorized likeness had already caused the company.

Both parties ended up as victims of the same fraud. Incognito lost GBP 20,000 and had to manage the fallout of having used a celebrity's image in marketing without a legitimate agreement in place. Bonnin had her voice and likeness used for commercial purposes she had never approved. The scammer's identity was not established in the public record, and the AI tool used to clone the voice was never publicly identified.

What this case exposed is the absence of any verification layer between a voice and the identity it claims. An audio message carries no credential. A negotiation conducted over recorded audio and email can be run by anyone capable of producing a convincing imitation, and the technology to produce that imitation now requires no specialist access. A provable record of what a system generated, when, and from whose source material, would not have stopped this fraud on its own, but it would have created a trail for investigation and narrowed the window for plausible denial. Without that record, voice is no longer a reliable signal of who is actually speaking.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
A Scammer Deepfaked a BBC Presenter's Voice and Walked Away with GBP 20,000
2024