The Deepfake Watchlist is Resemble AI's weekly surveillance of synthetic media incidents, ongoing cases, and disputed content shaping the news cycle. Each week we track confirmed incidents, emerging attack vectors, and claims under investigation, alongside the provenance, detection, and policy threads running underneath them. New to the world of deepfakes? Read the Deepfake 101 Guide to learn more about how to protect yourself and your company from threats.
1. Meta ran ads for an AI nudify app that deepfaked female politicians
WIRED's Meta ran ads for an app that only needs one photo and no consent reports that an app called Kromix, marketed as "the AI that men actually use," ran 32 advertisements on Meta's platforms promoting the creation of nonconsensual sexual deepfakes of real people, including a prominent female US politician.
- One ad featured an AI-generated image resembling the politician before cutting to explicit deepfake content using the same face.
- Meta's ad campaign targeted exclusively male users under the tagline "Unleash Next-gen AI Magic."
- Apple removed Kromix and a second app, MaskAI, from the App Store within hours of WIRED's inquiry.
- Category: CSAM / NCII
- Type: Attack
- Modality: Image, Video
- Policy / Regulatory: Neither Meta's ad review system nor Apple's App Store review caught the prohibited content before a journalist inquiry forced both companies to act.
- Trend: Nudify apps continue to evade platform moderation by introducing prohibited features after passing initial review, a pattern Meta and Apple have documented but not structurally solved.
- Attack vector: AI image-generation app distributed through a mainstream app store and promoted through paid social media advertising targeting male users.
Meta said it removed more than 340,000 nudify ads between late 2025 and early 2026, and has pursued legal action against at least one developer. Kromix still ran 32 ads, some for up to 46 hours, before a journalist flagged them. The ad account was created in early August with zero followers, exactly the profile automated systems should catch.
Apple said Kromix introduced the prohibited features after passing its initial App Store review. This is the same evasion pattern the Watchlist has tracked across multiple issues: an app presents clean functionality for review, then switches on the exploitative features once it is live. The question is whether either platform will move to continuous behavioral monitoring rather than point-in-time review.
2. Deepfake Albanese drove AUD $7.4 million in Australian investment scam losses
Tech Times's Deepfake Albanese pitching $40,000 returns led $7.4M in Australian scam losses reports that Australia's corporate regulator ASIC has documented AUD $7.4 million (roughly $5.3 million USD) in losses from investment scams impersonating the country's ten most recognizable public figures, including Prime Minister Anthony Albanese.
- The most documented scam uses audio grafting: authentic video of Albanese preserved intact, only the audio track replaced with AI-cloned speech promising guaranteed $40,000 monthly returns.
- ASIC removed a record 19,400 fraudulent websites in its most recent fiscal year, nearly three times the prior period.
- Category: Fraud / Impersonation
- Type: Attack
- Modality: Video, Audio
- Policy / Regulatory: Australia does not currently require social media platforms to verify the identity of financial advertisers before ad placement, leaving ASIC's enforcement model operating after the scam ad is already running.
- Trend: Audio grafting, where the face is real and only the voice is synthetic, defeats the standard visual detection advice consumers are given and represents the next evolution in deepfake investment fraud.
- Attack vector: AI-synthesized audio overlaid on authentic news footage of a head of state, distributed through paid social media ads and fabricated news broadcast segments.
The audio grafting technique inverts the detection problem. Standard consumer guidance says to watch for unnatural blinking or mismatched lip-sync, but those artifacts only appear when the face is artificially generated. In the Albanese scam, the face, movements, and setting are all real. Only the audio is synthetic, and modern voice cloning can produce a convincing replica from as little as three seconds of reference audio.
ASIC removed 19,400 sites in one fiscal year, averaging 32 takedowns per day at peak. Taiwan, by comparison, mandated that social media platforms verify the identity of financial advertisers before their ads run, and investment scam ads fell 96%. The gap between reactive takedowns and proactive verification is where the losses accumulate.
3. Wisconsin congressman posts deepfake videos of his opponent with no AI disclaimer
Spectrum News 1's Republican congressman posting deepfake videos of his Democratic opponent online reports that Rep. Derrick Van Orden (R-WI) has been posting AI-generated deepfake videos of Democrat Rebecca Cooke that manipulate her image to make it seem like she said things she did not.
- Category: Political / Electoral
- Type: Attack
- Modality: Video
- Policy / Regulatory: Wisconsin law requires AI-generated political content to carry the disclaimer "This video content generated by AI," but Van Orden's videos contain no such disclaimer, only the words "Made with Grok Imagine" elsewhere in the posts.
- Trend: Incumbents are now using AI-generated content offensively in competitive congressional races, moving deepfake campaign material from the fringes to the official accounts of sitting members of Congress.
- Attack vector: AI image-generation platform used by a sitting congressman to create manipulated video of a political opponent, distributed through the candidate's own social media channels.
Cooke responded directly: "This sort of slop is what frustrates people on both sides of the aisle. It's nasty mudslinging and character defamation. Deception like this should be illegal. But unfortunately Congress hasn't passed any laws to help that stand up in court." Her point lands because several bipartisan federal bills to regulate deepfakes in elections have been introduced, and none have come close to passage. The state-level patchwork, which the Watchlist mapped last week across 29 states, is the only protection voters currently have.
Wisconsin's law is one of the stronger ones, requiring explicit AI disclosure on political audio and video. Whether the "Made with Grok Imagine" tag satisfies the disclosure requirement is an open question. The race itself is rated a toss-up for control of the House, which means this is not a fringe case in a safe district. It is AI-generated campaign material in one of the most watched congressional races in the country.
4. AI-generated bomb threats force Georgia and California school closures
WSB-TV's Bomb threats toward north Georgia schools 'possibly generated' by AI reports that multiple school districts across Georgia canceled classes on August 14 after receiving bomb threats that investigators described as "computer generated" and "possibly generated by AI."
- Jackson County Schools received threats overnight targeting multiple buildings and canceled the full school day; deputies searched all buildings and gave the all-clear around 10:30 a.m.
- Hall County's Cherokee Bluff High School received a similar threat and resumed classes after a search around 10:45 a.m.
- In California, Wheatland Union High School was forced to close on August 18 after an AI-generated voice delivered a bomb threat with a ransom demand.
- Category: Harassment / Public Safety
- Type: Attack
- Modality: Audio
- Policy / Regulatory: The FBI is investigating the Georgia incidents, and both state and county law enforcement are working to identify the origin of the threats.
- Trend: AI-generated voice is being used to deliver anonymous threats at scale, extending the swatting playbook from individual targets to institutions serving thousands of people.
- Attack vector: AI-generated voice used to deliver bomb threats to schools, forcing emergency closures and law enforcement response across multiple districts simultaneously.
AI-generated threats delivered simultaneously to multiple schools in multiple states are harder to attribute, easier to replicate, and they force the same emergency response regardless of whether the threat is real. The cost is measured in lost school days, diverted law enforcement resources, and the erosion of trust in systems that are supposed to keep children safe.
The Wheatland Union case added a ransom demand, which suggests the caller was testing whether AI voice could be used not just for disruption but for extortion. Whether these incidents are connected or independent copycats, the infrastructure for AI-generated institutional threats is accessible enough that either explanation is plausible.
5. WSJ investigation reveals North Korean operatives using AI face-swapping to infiltrate US companies
The Wall Street Journal's yearlong investigation The North Korean Operatives Hiding Inside U.S. Companies, published August 13 with reporting and analysis continuing through the week, traces a North Korean IT worker cell that applied to more than 1,000 US companies in three months using AI at nearly every step of the process.
- The operatives used AI to generate resumes, AI-assisted responses during live interviews, and real-time face-swapping to appear as stolen American identities on video calls.
- The FBI has identified thousands of such applicants, with the Treasury Department estimating the operation earns $800 million annually for the regime.
- Category: Fraud / Impersonation
- Type: Attack
- Modality: Video, Image, Audio
- Policy / Regulatory: The FBI has warned employers that a driver's license, resume, and video interview are no longer sufficient proof that a remote applicant is who they claim to be.
- Trend: Generative AI has transformed employment fraud from an individual crime into an industrialized, state-sponsored operation, collapsing the cost of identity fabrication while scaling the attack surface to thousands of companies simultaneously.
- Attack vector: Real-time AI face-swapping during live video interviews combined with AI-generated application materials, using stolen American identities to pass background checks for remote positions.
The WSJ investigation drew from leaked data taken directly from the operatives' own machines, including browser histories, emails, calendars, and screen recordings. One cell infiltrated at least eight companies within months. The American victims of the identity theft face devastating consequences: a Georgia man whose identity was stolen said he can no longer open a bank account, qualify for loans, or rent a home.
Real-time face-swapping during live video calls is the capability that makes this structurally different from traditional identity fraud. A stolen Social Security number and a fabricated resume have been available for decades, but passing a live video interview as someone else required an accomplice or a physical disguise. AI face-swapping removes that bottleneck entirely. The FBI's recommendation, to independently verify previous employment and cross-check photographs against additional records, is effectively an admission that the visual channel can no longer be trusted for identity confirmation.
Honorable mentions
Jewish Insider, Randy Fine's primary opponent pushes openly antisemitic, pro-Hitler messaging, August 17. Florida congressional candidate Dan Bilzerian posted a 2.5-minute AI-generated campaign video deploying antisemitic tropes against Rep. Randy Fine (R-FL), drawing bipartisan condemnation from House leadership and more than 15 members of Congress.
Engadget, Another woman joins lawsuit accusing Grok of generating CSAM, August 17. A Wyoming woman whose stepfather used Grok to generate more than 7,000 CSAM deepfakes from her childhood photos became the fourth plaintiff in the Lieff Cabraser class action against xAI.
Multiple outlets, Robin Williams's children reactivate his Instagram, August 18. The family reactivated his official account to preserve his authentic legacy and combat AI-generated content using his likeness.
The pattern

- Platform moderation is failing at every checkpoint, and the failures are structural. Meta's ad review did not catch Kromix. Apple's App Store review did not catch Kromix. ASIC is removing 32 fraudulent sites per day, and the scams keep regenerating. Every layer of defense is designed for point-in-time review, and the attackers have learned to operate in the gaps between reviews.
- AI-generated content is now being used openly by officials, not just by anonymous bad actors. A sitting congressman is posting deepfake videos of his opponent from his own account. North Korean operatives are sitting in job interviews with AI-swapped faces. School bomb threats use AI-generated voice to trigger emergency closures. The shift from covert to overt, from fringe to institutional, is the defining trend of this month.
- The gap between state-level regulation and federal inaction is widening. Wisconsin has an AI disclosure law that may or may not cover Van Orden's videos. Minnesota has a nudification ban being challenged in court. Tennessee's deepfake ad law found its first gap within a month. Congress has passed nothing on AI in elections. The result is a patchwork where the protections available to voters and victims depend entirely on which state they live in.
Watching next week
- Kromix and Meta enforcement follow-up. Whether Meta implements proactive ad screening for nudify apps or continues to rely on journalist inquiries and reactive takedowns.
- Van Orden AI disclosure. Whether Wisconsin's election oversight body addresses the absence of required AI disclaimers on the congressman's deepfake videos, and whether the "Made with Grok Imagine" tag is treated as sufficient disclosure.
- xAI/Grok class action developments. The Lieff Cabraser class action now has four plaintiffs and growing media attention. Discovery proceedings and any motion to dismiss will signal how the litigation shapes up.
- Georgia school threat investigation. FBI investigation into the coordinated AI-generated bomb threats across Jackson and Hall counties. Whether additional threats emerge and whether attribution is established.
The Deepfake Watchlist publishes every Friday. Subscribe to receive it in your inbox, or follow Zohaib Ahmed on LinkedIn for the weekly social companion. Track every documented incident in the Resemble Deepfake Incident Database, and read the full methodology in our 2026 Midyear Deepfake Threat Report.

