Executive Summary
In 2025, the Nomani investment scam surged by 62%, leveraging sophisticated AI-based deepfake advertisements across major social media platforms including Facebook and YouTube. The scheme utilized convincing fake endorsements and manipulated video content to lure unsuspecting individuals into fraudulent investment schemes. Security firm ESET recorded over 64,000 unique URLs distributing the fraudulent campaign, indicating an expansion both in scale and reach. The attackers exploited trust in familiar faces, rapidly spreading the scam and leading to substantial financial losses and reputational risks for victims and targeted brands.
This incident highlights the growing threat of AI-enabled social engineering, with deepfakes enabling unprecedented scale and believability. As identity manipulation technologies proliferate, organizations and regulators face increased pressure to combat fraud, educate users, and adapt security controls to counter the evolving landscape of digital deception.
Why This Matters Now
AI-driven scams using deepfakes are accelerating in frequency and sophistication, exploiting trust in social platforms and public figures. Organizations are now at increased risk of reputational damage and regulatory scrutiny, while consumers face mounting dangers from rapidly spreading fraud campaigns. Immediate attention is required to bolster detection and user protection capabilities.
Attack Path Analysis
Attackers initiated the scam via widespread social engineering campaigns leveraging AI-generated deepfake ads on multiple social media platforms to lure victims. After users engaged with the fraudulent content, attackers harvested credentials and/or sensitive personal data, potentially escalating access if victims reused passwords across cloud or SaaS accounts. Attackers then leveraged the compromised access for possible lateral movement within SaaS or cloud estates if connected, advancing control over additional assets or services. Command and control was maintained through orchestrated communications over encrypted or legitimate channels to avoid detection. Exfiltration of stolen data, including financial information and credentials, ensued using covert or direct outbound connections. Ultimately, the impact was realized as financial loss, reputational harm, and possible account takeover for affected users and organizations.
Kill Chain Progression
Initial Compromise
Description
Victims were enticed by AI-generated deepfake investment ads on social media, leading to credential harvesting or phishing when users provided sensitive information on malicious sites.
MITRE ATT&CK® Techniques
Spearphishing via Social Media
Phishing
Gather Victim Identity Information
Compromise Accounts
Modify System Image: Web Content
User Execution: Malicious Link
Abuse Elevation Control Mechanism: Social Engineering
Compromise Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness and Training
Control ID: 12.6.1
NYDFS 23 NYCRR 500 – Audit Trail
Control ID: 500.06
DORA – ICT Risk Management - Detection
Control ID: Article 9(2)(d)
CISA ZTMM 2.0 – End-User Security Awareness
Control ID: User Access: Awareness & Training
NIS2 Directive – Incident Handling and Security Awareness
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Investment scams using AI deepfakes directly target financial services clients, exploiting trust in legitimate investment platforms and requiring enhanced egress security measures.
Investment Banking/Venture
AI-generated deepfake investment advertisements undermine sector credibility, necessitating advanced threat detection capabilities and zero trust segmentation for client communications.
Marketing/Advertising/Sales
Social media advertising platforms become attack vectors for deepfake scams, requiring multicloud visibility controls and enhanced policy enforcement across digital campaigns.
Information Technology/IT
IT sectors must implement cloud native security fabrics and anomaly detection systems to combat sophisticated AI-driven social engineering attacks proliferating across platforms.
Sources
- Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Mediahttps://thehackernews.com/2025/12/nomani-investment-scam-surges-62-using.htmlVerified
- ESET Threat Report: AI-driven attacks on the rise; NFC threats increase and evolve in sophisticationhttps://www.eset.com/us/about/newsroom/research/eset-threat-report-h2-2025-1/Verified
- Investor Alert: Attorney General James Warns New Yorkers of Investment Scams Using AI-Manipulated Videoshttps://ag.ny.gov/press-release/2024/investor-alert-attorney-general-james-warns-new-yorkers-investment-scams-usingVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF Zero Trust controls such as segmentation, egress policy enforcement, and anomaly detection would have drastically limited attacker movement, egress, and the ability to exfiltrate sensitive data in the event of successful credential harvesting or cloud access. Continuous monitoring and network visibility also strengthen detection and response against malicious behaviors leveraging encrypted or cross-cloud channels.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious access attempts or authentication anomalies can be detected and alerted.
Control: Zero Trust Segmentation
Mitigation: Identity-based segmentation prevents unauthorized privilege escalation beyond assigned scopes.
Control: East-West Traffic Security
Mitigation: Unauthorized movement between workloads or accounts is restricted and monitored.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline inspection and distributed policy enforcement detect and block known bad outbound connections.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data exfiltration to untrusted domains or IPs can be stopped or alerted.
Centralized, real-time monitoring enables rapid detection and containment of active threats.
Impact at a Glance
Affected Business Functions
- Customer Trust
- Brand Reputation
- Financial Transactions
Estimated downtime: N/A
Estimated loss: N/A
The Nomani scam primarily targets individual consumers, leading to personal financial losses and potential identity theft. While businesses may not experience direct operational disruptions, the widespread nature of such scams can erode customer trust and damage brand reputation, especially if their platforms are used to disseminate fraudulent content.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy egress filtering and policy enforcement to block outbound traffic to suspicious domains and prevent data exfiltration.
- • Utilize Zero Trust Segmentation and east-west traffic controls to limit the blast radius of compromised cloud identities or workloads.
- • Implement continuous anomaly detection and threat monitoring to detect and respond to credential theft or abnormal behavioral patterns.
- • Ensure comprehensive multicloud visibility for rapid identification and containment of incidents across all environments.
- • Regularly validate and update least-privilege access and segmentation policies to minimize privilege escalation and lateral movement risks.



