A Deepfake of Canada's Prime Minister Drained a Retiree's Life Savings in a Crypto Scam
What happened
A Facebook ad showed Canadian Prime Minister Mark Carney endorsing a cryptocurrency investment platform. The video looked like him. It sounded like him. It was not him. The ad was, according to reports, an AI-generated deepfake, and it was the first step in a scam that ultimately cost an Ontario retiree nearly one million dollars.
Judy Skene saw the ad and believed it. By the time she understood what had happened, she had liquidated her retirement savings, taken out a mortgage on her condominium, and drawn a cash advance on her credit card. Reports placed her total losses at close to $1 million. The scammers did not break into her accounts. They convinced her, step by step, to hand the money over herself, starting with a video that looked like an endorsement from the head of government.
That sequence, a fabricated video of a trusted public figure placed inside a legitimate advertising channel, is not an accident of technology. It is a deliberate choice to use AI image synthesis to manufacture credibility that scammers could not build on their own. Carney's face and voice are familiar, authoritative, and closely associated in the public mind with economic policy. Attaching that face to a financial product bypasses the skepticism a stranger's pitch would trigger. Deepfakes do not need to fool an expert review under lab conditions. They need to be convincing enough, at normal viewing speed, on a phone screen, by someone with no reason to doubt what a platform's ad system has placed in their feed.
The distribution channel is part of the problem. Social media advertising systems serve billions of impressions daily and have limited capacity to verify whether the person depicted in an ad has consented to appear in it. A video of a public figure promoting an investment product looks, to an automated system, like any other ad creative. There is no check at upload time asking whether the likeness was generated with permission, and no mechanism that flags fabricated identity before an ad reaches scale.
What is missing is a provable record of what a system did: who created the video, which account submitted it as an ad, when it was approved, and how many people saw it before the first complaint. That record, attached to the content at the moment it entered the platform, would make fabricated-identity fraud traceable rather than disposable. Right now, scammers create the video, run the ad, withdraw the money, and leave behind almost nothing that law enforcement can reliably act on.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.