The Containment Era is here. →Explore

Executive Summary

In 2025, the Nomani investment scam surged by 62%, leveraging sophisticated AI-based deepfake advertisements across major social media platforms including Facebook and YouTube. The scheme utilized convincing fake endorsements and manipulated video content to lure unsuspecting individuals into fraudulent investment schemes. Security firm ESET recorded over 64,000 unique URLs distributing the fraudulent campaign, indicating an expansion both in scale and reach. The attackers exploited trust in familiar faces, rapidly spreading the scam and leading to substantial financial losses and reputational risks for victims and targeted brands.

This incident highlights the growing threat of AI-enabled social engineering, with deepfakes enabling unprecedented scale and believability. As identity manipulation technologies proliferate, organizations and regulators face increased pressure to combat fraud, educate users, and adapt security controls to counter the evolving landscape of digital deception.

Why This Matters Now

AI-driven scams using deepfakes are accelerating in frequency and sophistication, exploiting trust in social platforms and public figures. Organizations are now at increased risk of reputational damage and regulatory scrutiny, while consumers face mounting dangers from rapidly spreading fraud campaigns. Immediate attention is required to bolster detection and user protection capabilities.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The scam used AI-generated deepfake videos to imitate trusted public figures and promote fake investment schemes on major social media platforms, increasing credibility and victim impact.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying CNSF Zero Trust controls such as segmentation, egress policy enforcement, and anomaly detection would have drastically limited attacker movement, egress, and the ability to exfiltrate sensitive data in the event of successful credential harvesting or cloud access. Continuous monitoring and network visibility also strengthen detection and response against malicious behaviors leveraging encrypted or cross-cloud channels.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious access attempts or authentication anomalies can be detected and alerted.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based segmentation prevents unauthorized privilege escalation beyond assigned scopes.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unauthorized movement between workloads or accounts is restricted and monitored.

Command & Control

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline inspection and distributed policy enforcement detect and block known bad outbound connections.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Outbound data exfiltration to untrusted domains or IPs can be stopped or alerted.

Impact (Mitigations)

Centralized, real-time monitoring enables rapid detection and containment of active threats.

Impact at a Glance

Affected Business Functions

  • Customer Trust
  • Brand Reputation
  • Financial Transactions
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

The Nomani scam primarily targets individual consumers, leading to personal financial losses and potential identity theft. While businesses may not experience direct operational disruptions, the widespread nature of such scams can erode customer trust and damage brand reputation, especially if their platforms are used to disseminate fraudulent content.

Recommended Actions

  • Deploy egress filtering and policy enforcement to block outbound traffic to suspicious domains and prevent data exfiltration.
  • Utilize Zero Trust Segmentation and east-west traffic controls to limit the blast radius of compromised cloud identities or workloads.
  • Implement continuous anomaly detection and threat monitoring to detect and respond to credential theft or abnormal behavioral patterns.
  • Ensure comprehensive multicloud visibility for rapid identification and containment of incidents across all environments.
  • Regularly validate and update least-privilege access and segmentation policies to minimize privilege escalation and lateral movement risks.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image