Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

December 19, 2024

A global cybercrime network, Storm-2139, is suspected to have exploited stolen credentials and created custom tools aimed at bypassing AI governance and safety guardrails. The network reportedly generated harmful deepfake content, such as nonconsensual intimate images of celebrities, which disabled content moderation, hijacked AI access, and resold illicit services. Microsoft disrupted the operation in December 2024, filing a lawsuit, and later identified key members in February 2025. This incident underscores the need for vigilance and guardrails in AI governance to prevent such harmful activities, as part of our commitment to safe and secure AI practices. For those interested in shaping Project Cerebellum's Harm Prevention efforts, JOIN US here.

Learn more about how this incident maps to the HISPI Project Cerebellum TAIM (Govern) function.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
unidentified-storm-2139-actor-from-illinois, unidentified-storm-2139-actor-from-florida, storm-2139, ricky-yuen-(cg-dot), phat-phung-tan-(asakuri), arian-yadegarnia-(fiz), alan-krysiak-(drago)
Alleged developer
unidentified-storm-2139-actor-from-illinois, unidentified-storm-2139-actor-from-florida, storm-2139, ricky-yuen-(cg-dot), phat-phung-tan-(asakuri), arian-yadegarnia-(fiz), alan-krysiak-(drago)
Alleged harmed parties
victims-of-deepfake-abuse, openai, microsoft, celebrities, azure-openai-customers, ai-service-providers

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/955

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.