Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

AI Security Compliance Assessment Scam: Forged Detection Reports Used to Extort Annual Rectification Fees

Victims are typically heads of digital departments or administrative staff at small and medium-sized internet companies and traditional enterprises. They often lack dedicated security teams and have only a superficial understanding of vulnerability IDs, CVE formats, and security assessment processes. At the same time, they fear data breaches, regulatory penalties, or impacts on financing and bidding qualifications. Scammers precisely exploit this 'better safe than sorry' anxiety: a risk notification letter with a fake official seal or a professional-looking vulnerability detail page is enough to make decision-makers skip verification and authorize payments for so-called annual protection or rectification services.

SCAM

Key Fields

FIELD STAMPS
IndustryProfessional Services
RegionChina(中国大陆)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are typically heads of digital departments or administrative staff at small and medium-sized internet companies and traditional enterprises. They often lack dedicated security teams and have only a superficial understanding of vulnerability IDs, CVE formats, and security assessment processes. At the same time, they fear data breaches, regulatory penalties, or impacts on financing and bidding qualifications. Scammers precisely exploit this 'better safe than sorry' anxiety: a risk notification letter with a fake official seal or a professional-looking vulnerability detail page is enough to make decision-makers skip verification and authorize payments for so-called annual protection or rectification services.

骗局怎么运作

  • Step 1: Casting the net to screen targets. Scammers collect company information through public channels like Qichacha or job boards, targeting companies currently hiring AI engineers or those that have just launched AI products. These companies are most concerned about unknown vulnerabilities in their systems and are most likely to believe claims of 'abnormalities detected externally.'
  • Step 2: Establishing contact via forged identity. Impersonating a cybersecurity firm or an 'AI Security Assessment Center,' they call the company's IT head, claiming that a routine scan revealed high-risk vulnerabilities. They use scripts like 'Your interface has been targeted by overseas cybercriminals and may be breached within 48 hours,' creating panic through time pressure.
  • Step 3: Delivering forged reports. They send an email with a professionally formatted risk assessment report, misappropriating real CVE IDs, and including forged red seals and so-called expert signatures. The report is intentionally stuffed with technical jargon like SQL injection and privilege escalation to prevent non-technical managers from debunking it on the spot.
  • Step 4: Pressuring for a contract. They claim that 'failure to rectify will result in reporting to regulatory authorities' or 'hackers have already obtained data, but we can assist in blocking them.' They push an annual protection contract worth tens of thousands of yuan, emphasizing a '40% discount if signed within three days,' using loss aversion to force decision-makers to commit quickly.
  • Step 5: Disappearing after payment. Once the company pays, the scammers either disappear or stall after providing a generic security advice PDF downloaded from the internet. More malicious variants may induce the company to open server permissions during the 'detection' process, allowing them to steal real data for secondary extortion.

红旗信号(看到这些快跑)

  • 🚩 The caller claims to have found vulnerabilities in your system but cannot provide legal authorization for the scan. Legitimate security vendors never perform unauthorized scans of third-party systems to solicit business.
  • 🚩 The vulnerability IDs and descriptions in the report do not match. Searching the IDs on the National Vulnerability Database or the official CVE website reveals that the details do not align with your technology stack.
  • 🚩 The quote and contract use personal accounts for payment, or the company entity does not match the claimed institution. The official seal is blurry and cannot be verified through official channels.
  • 🚩 The scammers create extreme urgency, such as threatening to report you to regulators or claiming data is about to leak within 48 hours. Legitimate institutions provide reasonable remediation timelines rather than using fear-based countdowns.
  • 🚩 They refuse to provide on-site verification or video conferences to demonstrate their work, communicating only via enterprise messaging apps or email, and urge you to bypass legal review processes.

真实案例

  • In February 2024, Hong Kong police reported a deepfake video conference scam: a finance employee at a multinational company was defrauded of approximately HK$200 million (US$25 million) by AI-generated face-swapping videos impersonating the CFO and other colleagues. This case is cited in multiple security reports as a landmark event for the AI trust crisis, demonstrating the lethality of the 'forged identity + urgent instruction' script. (Source: https://cn-sec.com/archives/5122296.html)
  • According to CN-SEC reports in March 2026, AI security attacks and defenses escalated significantly in 2026, with AI Agent-related vulnerabilities surging by 82. Deepfakes were used for large-scale fraud, forcing companies to shift from perimeter defense to trust reconstruction, confirming that the soil for scams involving fake detection reports and internal instructions is expanding.
  • According to the 2026 AI Security Report released by Check Point, AI has shifted from an attack-assist tool to an autonomous executor in the attack chain. The barrier to entry has dropped significantly, and attackers can now obtain forged reports and generate scripts at a low cost through public channels, making it essential for companies to verify every security threat notification received.
  • In February 2024, as reported by Hualong Net, a finance employee at a company in Xi'an, Shaanxi, received a video call from their boss, which was a deepfake. The caller instructed them to transfer 1.86 million yuan to a designated account. After the transfer, the victim realized the fraud while reconciling accounts in an internal group and reported it to the Xi'an police. The police coordinated with the anti-fraud center to urgently freeze the funds and recovered 1.56 million yuan. (Source: https://news.cqnews.net/1/detail/1211564521258766336/web/content_1211564521258766336.html)

Official Stance

  • On March 23, 2026, CN-SEC reported that AI Agent vulnerabilities are surging and deepfakes are being used for large-scale fraud, reminding companies to establish multi-factor verification mechanisms for instructions involving transfers and procurement.
  • In July 2026, Check Point Research released its annual AI Security Report, systematically outlining risks related to identity forgery and corporate data exposure, warning against impersonation and fraud implemented via AI-generated content.
  • On April 30, 2026, Nanjing University's network information security warning advised that high-risk vulnerability information should be based on official vulnerability database disclosures. Companies should verify vulnerability details and remediation plans through official channels to guard against misleading marketing and scams disguised as vulnerability alerts.

How to Protect Yourself

  • ✅ If you receive an external notification claiming your system has vulnerabilities, first check the ID and details on the National Vulnerability Database or the official CVE website. If the ID does not match or the description is inconsistent, it can be considered a forgery.
  • ✅ Establish internal policies: Any procurement of security services must be accompanied by a written assessment from the technical team and reviewed by the legal department. Business heads are prohibited from making unilateral payment decisions under pressure.
  • ✅ When someone claims to be a testing agency, request their inspection and testing qualification certificate number and verify it on the State Administration for Market Regulation platform. Refuse to cooperate with any uncertified institutions.
  • ✅ Never grant external institutions access to servers, code repositories, or account permissions for so-called 'detection.' If a security assessment is needed, only sign a non-disclosure agreement with a legitimate vendor selected through public bidding or official channels.
  • ✅ If you encounter threatening payment demands, retain emails, chat logs, and contracts, report the incident to the police immediately, and report the misuse of regulatory names to local internet information authorities.