The Deepfake Watchlist is Resemble AI's weekly surveillance of synthetic media incidents, ongoing cases, and disputed content shaping the news cycle. Each week we track confirmed incidents, emerging attack vectors, and claims under investigation, alongside the provenance, detection, and policy threads running underneath them. New to the world of deepfakes? Read the Deepfake 101 Guide to learn more about how to protect yourself and your company from threats.
★ Featured: AI-generated BRICS summit selfie shared by Russian and Iranian embassy accounts as real
France 24's Viral Putin, Modi and Xi selfie at BRICS summit is AI-generated, published September 15, confirms that images purporting to show world leaders at the 18th BRICS Summit in New Delhi are AI-generated, with a SynthID watermark identifying OpenAI tools as the source; the Russian Embassy in South Africa shared the image as real under the caption "BRICS is a superpower," and Iranian embassy accounts in India and Armenia amplified it, reaching millions of viewers before fact-checkers arrived.
- Category: Political / Electoral
- Type: Attack
- Modality: Image
- Policy / Regulatory: No jurisdiction currently requires AI disclosure on images shared through official diplomatic social media accounts, leaving state-amplified fabrications outside any mandatory labeling or takedown obligation.
- Trend: State-linked actors distributing AI-fabricated imagery through official diplomatic accounts, which carries institutional credibility that anonymous posts cannot replicate.
- Attack vector: AI-generated group image timed to a genuine geopolitical summit and seeded through official embassy accounts to exploit the news cycle's demand for visual documentation.
- What we saw in the content: France 24, AAP FactCheck, BOOM, and Lead Stories each ran independent verification and documented the following signals:
- SynthID invisible watermark pointing to OpenAI generation tools, establishing a clear provenance chain at the generation layer
- Former Iranian President Ebrahim Raisi visible in the image despite having died in a helicopter crash in May 2024, two years before this summit
- Brazilian President Lula da Silva depicted despite not attending, with Brazil represented by Foreign Minister Mauro Vieira
- Turkish President Erdoğan present despite Turkey not being a BRICS member and having no delegation at the event
When state institutions are the primary distribution vector for a fabrication, the implicit credibility of official diplomatic social media does the work that a convincingly generated image alone cannot. The Russian Embassy's post reached millions before any correction landed, and Iranian embassy accounts in two countries amplified it further, none of which triggered a labeling requirement or a platform takedown.
SynthID caught this image, as it caught the Merz-Epstein image the week before, but only because a fact-checker ran the check. The asymmetry between who has access to detection tools and who encounters the content in a feed is the operating gap every deepfake political campaign exploits.
The forensic tells here were not subtle: a dead president, three leaders confirmed absent from the official guest list, a non-member country's head of state in the frame. None of those signals prevented distribution through official diplomatic channels. Provenance embedded at the generation layer is the only intervention that changes the sequence, surfacing synthetic origin at the moment of first exposure rather than days later when the correction arrives.
1. West Michigan homebuyers lose $66,000 to AI voice-clone real estate fraud
CNN's How two homebuyers in Michigan lost $66,000 in a suspected voice-cloning scam, published September 15, reports that Brian and Wendy VanDoeselaar lost their entire closing fund to scammers who combined AI voice cloning, spoofed email, and spoofed caller ID to impersonate the mortgage professional they had worked with for weeks, with fraud prevention company CertifID identifying it as a voice-cloning attack.
- Category: Fraud / Impersonation
- Type: Attack
- Modality: Audio
- Policy / Regulatory: The FBI classifies homebuyer wire fraud as a variant of business email compromise; no federal statute specifically addresses AI voice synthesis as an element of real estate wire fraud.
- Trend: AI voice cloning combined with email and caller ID spoofing as a layered real estate closing fraud, targeting buyers during the narrow window when large sums must move quickly.
- Attack vector: Scammers impersonated a known mortgage professional across three channels simultaneously, using the voice clone as trust confirmation for wiring instructions delivered by spoofed email.
Brian VanDoeselaar heard a familiar voice on a number that matched his lender's contact, calling to confirm wiring instructions that arrived in an email that looked right, and three spoofing layers reinforcing each other cleared the bar before any single one raised a flag.
CertifID describes buyer cash-to-close as its most common recovery category, accounting for 30 percent of accepted cases with a median loss of $239,850. The FBI recorded more than $275 million in real estate wire fraud losses last year, a 58.5 percent increase over 2024, and homebuyers are particularly exposed because, as CertifID's Tyler Adams noted, most people do this transaction so rarely they have no verification routine to fall back on.
2. Russia's Matryoshka network opens its US midterm campaign with AI-cloned celebrity deepfakes
AFP's reporting, published September 14–15 and carried by Free Malaysia Today and MS.NOW, documents that the Kremlin-linked Matryoshka network has deployed at least 16 videos using authentic celebrity footage with AI-cloned audio and unauthorized CNN branding to attack named Democratic candidates in specific congressional races ahead of November.
- Category: Political / Electoral
- Type: Attack
- Modality: Video, Audio
- Policy / Regulatory: No US statute specifically criminalizes AI-manipulated audio in electoral influence operations; Bluesky suspended seven accounts while X took no action.
- Trend: Hybrid AI attacks combining authentic celebrity footage with voice-cloned audio and fake news branding, designed to evade detection tools trained on face swaps and image generation.
- Attack vector: Authentic video clips of American celebrities, including Cameo recordings, overlaid with AI-synthesized audio attacking named Democratic candidates, then wrapped in CNN's logo and amplified through bot networks.
The footage of Sarah Jessica Parker, Julia Roberts, Alyson Hannigan, Christopher Lloyd, and Emma Caulfield is real; the audio is not. That combination specifically evades face-swap detection, and the CNN logo frames the content with the visual authority of journalism. Darren Linvill at Clemson called this "the first salvo" in Russia's 2026 midterm operation, with specific targeting of congressional races in New Hampshire, Texas, Georgia, Alaska, North Carolina, and Ohio.
The campaign's current reach is small, but the targeting reveals which races Russia considers competitive enough to invest in early. As of Friday the bot network remained intact, X had taken no action, and the infrastructure for subsequent salvos was already built.
3. Offshore casino deepfakes Alphonso Davies's father in fake gambling arrest ad
The Edmonton Journal's Offshore casino targets Alphonso Davies's family with deepfake ad, reported by Steven Sandor and published September 11, documents that an Instagram advertiser called "Prime Spin Zone" ran a video using AI-generated footage of Bayern Munich star Alphonso Davies's father being arrested by Edmonton police and then endorsing Oxibet, a Comoros-based offshore gambling site not licensed in Alberta.
- Category: Brand / Likeness
- Type: Attack
- Modality: Video
- Policy / Regulatory: Alberta law prohibits licensed celebrity athletes from endorsing gambling sites, but that regulation does not reach offshore operators like Oxibet, which sits outside the province's 31-site iGaming registry.
- Trend: AI-generated family member deepfakes used as celebrity endorsement fraud vectors, escalating from the prior pattern of using static athlete images without consent.
- Attack vector: AI-generated video fabricating a false arrest narrative involving the athlete's father to manufacture a story of legitimate gambling wealth, then directing viewers to an unregulated offshore platform.
Davies's agent Nedal Huoseh confirmed the family has no connection to gambling. An AI-generated version of Canadian rapper Drake appears in the same ad, confirming this is a template deployed against multiple celebrities rather than a targeted attack on Davies specifically. InsiderSport reports that more than 10,000 such ads appeared online in a recent twelve-month period.
Alberta Service Alberta Minister Dale Nally called the offshore sites "predatory" and encouraged residents to check for the iGaming Corporation logo, which is the extent of what provincial regulation can accomplish against a Comoros-based operator. In 2023, an unauthorized static photo of Davies was used without consent; the 2026 version is an AI-generated video of his father in a fabricated criminal proceeding.
The pattern

- Two of this week's four stories are state-linked operations working through opposite mechanics. The BRICS selfie traveled through official diplomatic accounts, exploiting the institutional credibility of state social media. Matryoshka worked through bot networks and fake news branding, exploiting the visual authority of journalism. Both are state-linked, both target political perception, and neither needed forensic sophistication to move at scale.
- Voice cloning and AI-generated video are now operating at the retail level as readily as the geopolitical one. A Michigan couple losing their closing funds and an Edmonton family targeted by an offshore casino face the same underlying technology as a Kremlin influence operation. The attack surface is no longer bounded by resources or technical sophistication, only by the availability of a target.
- No enforcement action landed in this window. The BRICS selfie circulated through official diplomatic channels for days. Matryoshka's infrastructure is intact. Oxibet's ads were still running at publication. The VanDoeselaars have not recovered their money. Detection tells you what happened after content has traveled; provenance at the generation layer is the intervention that changes the sequence before harm accumulates.
Watching next week
- Matryoshka's next salvo. Linvill predicted more salvos as November approaches; which races get targeted next, and whether X acts on the accounts distributing the content, will reveal both the operation's scope and the platform's posture.
- Ofcom's September 30 deadline. UK platforms must have hash-matching for deepfake intimate images deployed by month's end or face fines up to 10 percent of global annual revenue.
- BRICS diplomatic fallout. Whether any government formally objects to Russia's embassy distributing AI-fabricated imagery of allied leaders at a multilateral summit will establish, or signal the absence of, a diplomatic norm around state use of synthetic media.
The Deepfake Watchlist publishes every Thursday. Subscribe to receive it in your inbox, or follow Zohaib Ahmed on LinkedIn for the weekly social companion. Track every documented incident in the Resemble Deepfake Incident Database, and read the full methodology in our 2026 Midyear Deepfake Threat Report.

