Skip to content
Back to Blog
high severity September 02, 2026 · 4 min read Unverified claim — what this is

Taiwan romance scam used AI voices on 20,000+ victims — does it affect you?

If you are a customer of Taiwan romance scam used AI voices, here’s what is being claimed, and what it would mean for you.

Taipei prosecutors have indicted 57 people over a romance scam that began in 2022 and took at least NT$900 million from more than 20,000 people, using fake dating-app profiles and AI-cloned voices. This was a fraud ring, not a hack that spilled a company’s customer list. A scary headline does not mean your ID or voice is circulating; the pattern that does matter is a dating-app match that started with a small purchase and then asked for money.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Taiwan romance scam used AI voices on 20,000+ victims — does it affect you?

On 2 September 2026 the Taipei District Prosecutors Office announced it had indicted 57 people over a romance scam that had run since 2022. Prosecutors said a husband-and-wife-led group, Huang Chien-hao and Hsu Hsiang-chi, used fake dating-app profiles and custom AI voice-changing software trained on 22 female staff so other members could impersonate those women in chats and calls. They asked the court for at least 25 years in prison for Huang and 18 years for Hsu, under fraud, money-laundering, and group internet-fraud charges.

Watch Taiwan romance scam used AI voices

Get alerted the next time Taiwan romance scam used AI voices files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about Taiwan romance scam used AI voices’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.

The office said more than 20,000 people were defrauded of at least NT$900 million (about US$28.3 million). Victims were first asked to buy low-cost items for NT$1,000 to NT$2,000, then pulled into fake relationships and pressed for gifts and cash. After searches in May and July 2026, investigators seized luxury cars, 47 watches, about NT$300 million in property and accounts, cash, and 67 computers that held the software.

The story is not that your ID or voice was dumped online

Most coverage leads with the AI tool, the 57 defendants, and the cars that were seized. That makes the case sound like a tech breach — or like a problem that ended when the indictment was filed.

What prosecutors actually described is different. This was not a hack of a dating app, and not a posted list of the public’s home addresses, national ID numbers, or passwords. The 22 voices belonged to women inside the operation. The software let other members sound like those women on the phone. Unless you worked for this group or were cultivated as a customer, nothing in the official account says your biometric data or your government records were stolen and published.

The part that maps onto ordinary life is the opening move. The first ask often looked like shopping, not crime: help someone hit a sales target by buying fish oil, a power bank, or a similar cheap item. After that came warmth, then gifts (phones, appliances, and the like), then cash for living costs, medical bills, or courses. Prosecutors said some of the women met victims in person, and that those meetings were used to extract more. A real-life meeting, or the fact that you only started with a small order, is not proof you were safe. That was the sequence this group used.

The indictment also does not put money back in anyone’s account. Some victims were driven into debt. Seizing watches and cars is not a refund.

What to actually expect

  • You will not get an email from a company saying your account was “in this incident.” Prosecutors did not describe a stolen customer database.
  • A typical “was my email leaked?” search will not tell you whether you were one of the 20,000. Those searches look for dumped files, and that is not what this case is.
  • If you already sent money or gifts in this pattern, do not expect the seized assets to become a repayment in the coming weeks. The case is going to Taipei District Court.
  • The same script — a dating-app match, a small purchase, then a personal emergency — can still arrive from people with no link to this particular group.

What you can and cannot fix

Money, gifts, and private photos or messages already sent to this operation cannot be pulled back. There is no reset. Prosecutors holding 67 computers does not erase what victims already handed over. If you were not in contact with them, this case is not a reason to believe your address or ID number has been published; the office did not describe that kind of leak, so there is nothing from this incident to “remove.”

  • If the pattern matches payments you made, report it to the police and to your bank, and keep the chat logs and transfer records. This is an active criminal case, not a rumor.
  • Stop sending anything else. Further “urgent” asks are part of the same script, including after news of the indictment.
  • Do not pay anyone who offers to recover the funds or to “take your name off the case.” That is a second scam riding on the headlines.
  • Report the profile on the dating app. That can cut off further contact. It cannot guarantee that copies of anything you already sent will disappear.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Taiwan romance scam used AI voices is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High includes account details that can be misused directly
Disclosed September 02, 2026
Last reviewed September 2, 2026
Affected Unconfirmed
Data exposed Victim payments and giftsprivate chats and callsbait dating-app photosstaff voiceprints used for impersonation
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email