Skip to main content
High News report Investigation Opened

University of Hong Kong: a law student made about 700 indecent AI-generated images of some 20 to 30 classmates and teachers; the privacy watchdog opened then closed a criminal probe

In February 2025 a University of Hong Kong (HKU) law student was found, by friends who saw the files on his laptop, to have used free online AI software to make about 700 indecent and deepfake images of some 20 to 30 women, including university and former schoolmates and secondary-school teachers, using photos taken from their social media. Victims went public in July 2025, and HKU's initial response, a warning letter and a demand that he apologise, drew wide criticism. Hong Kong's Privacy Commissioner opened a criminal investigation on 15 July 2025 but announced on 17 December 2025 that it was ending the probe for insufficient evidence, as no victim was willing to provide further information. Hong Kong law criminalised distribution, not creation, of such images.

AI System

AI deepfake / image-generation software (free online tools, not named)

Occurred

Feb 2025

Reported

12 July 2025

Event location

Hong Kong SAR China

Platform

other

What the evidence supports

AI involvement: supported. Multiple outlets and the victims' own account report the student used free online AI software to generate indecent/deepfake images from the women's social-media photos; the student admitted using the software (per the victims' account carried by HKFP and NBC). The specific tools are not named.

AI-to-person relation

  • Depicted or impersonated the person

Core relations are communication, acting on someone’s behalf, and depiction or impersonation. Decision and claim relations are retained as contextual cases.

Someone else’s AI use. Settings: Education, Privacy, Justice.

Claim status: Corroborated

In February 2025 an HKU law student was found to have used free online AI software to make indecent/deepfake images of some 20 to 30 women (about 700 image files including deepfakes and unedited saved photos), taken from their social-media accounts; there was no allegation he distributed them.

Causal attribution: The victims' Instagram account (carried by HKFP and NBC) and AFP reporting (CBS); the 700 figure is images, and outlets vary between 'at least 20' and '20 to 30' women.

  • News report (supports): 'a University of Hong Kong (HKU) law student fabricated pornographic deepfakes of at least 20 women'; 'no allegation so far that the student spread the deepfake images'; 'a friend discovered the images on the student's laptop'.
  • News report (supports): 'Around 20 to 30 women... were affected'; 'in February, the student had admitted to using screenshots of the social media accounts... to generate pornographic images using free online artificial intelligence software'; 'there were 700 images involved - including deepfakes as well as unedited images'.
  • News report (supports): 'The images were organized into folders named after the victims, totaling 700+ images'; 'discovered on his laptop reported to the university in February'; 'not known to have been widely distributed'.

Claim status: Corroborated

HKU initially issued a warning letter and demanded an apology (about 60 words, shown to victims in April 2025), and made class adjustments; the response drew wide criticism after victims went public on 12 July 2025.

Causal attribution: HKU statements and the victims' account, carried by three outlets.

  • News report (supports): 'The University has already issued him a warning letter and demanded him a formal apology'; the 60-word apology letter; 'class adjustments'.
  • News report (supports): 'HKU proposed a verbal reprimand and warning letter'; the ~60-word apology 'most victims found... insincere'.
  • News report (supports): 'The university said it had issued a warning letter to the student and told him to apologise'; lawmakers/advocates' criticism.

Claim status: Corroborated

Hong Kong's Privacy Commissioner opened a criminal investigation on 15 July 2025.

Causal attribution: PCPD announcement, 15 July 2025.

  • News report (supports): 'Hong Kong's Office of the Privacy Commissioner for Personal Data said Tuesday... has begun a criminal investigation into the incident'.
  • News report (supports): 'The probe, announced Tuesday by the Office of the Privacy Commissioner for Personal Data'.

Claim status: Documented

On 17 December 2025 the PCPD announced it was ending the investigation for insufficient evidence, as no victim was willing to provide further information, and released anti-deepfake guidance for schools and parents.

Causal attribution: unwire.hk report of the PCPD press conference (Privacy Commissioner Ada Chung), 17 December 2025.

  • News report (supports): '私隱專員公署今日(17 日)宣布,因證據不足未能進一步跟進... 由於未有受害人願意提供進一步資料,目前未有足夠證據提出起訴'; 'AI 深度偽造技術(Deepfake)投訴... 5 宗'; new school/parent guidance.

Claim status: Corroborated

Hong Kong law criminalises publication or distribution of non-consensual intimate images (including AI-generated ones) but not their mere creation, leaving victims without a clear route to prosecution.

Causal attribution: Legal analysis carried by three outlets and the victims' statement.

  • News report (supports): 'under section 159AAE of the Crimes Ordinance, it is unlawful to disseminate deepfake intimate images... without their consent'; creation not covered.
  • News report (supports): 'the city's regulations covered acts of voyeurism and the publication or distribution of images - rather than their creation'.
  • News report (supports): 'Hong Kong law only criminalises the distribution of intimate images... but not the generation of them'.

What remains unknown

  • The student is not identified beyond 'a male law student' and faced no prosecution; whether HKU took any further disciplinary action is not established.
  • The exact number of women is reported as 20 to 30 (NBC: 'more than a dozen'); the precise count is unresolved.
  • The creation start date is reported by The Standard as about May 2024 but is not firmly established in the sources read here.
  • Whether any victim later came forward with evidence after the December 2025 closure is not established.
Source reading, translation and location

News report · en · Source inspected

Read in English on 2026-09-17 via the Internet Archive capture 20251105074941 (CBS live returns HTTP 406); datePublished 2025-07-15. CBS/AFP: at least 20 women, PCPD criminal probe, legal gap.

News report · en · Source inspected

Read in English on 2026-09-17 (live, datePublished 2025-07-17). NBC News: 700+ images in victim-named folders, warning letter and 60-word apology, class adjustments, John Lee comment.

News report · en · Source inspected

Read in English on 2026-09-17 (live, datePublished 2025-07-13, correction 2025-07-14). HKFP: 20-30 women, February discovery, 700 images (deepfakes plus unedited), March disciplinary request, ragging analysis.

News report · en · Source inspected

Read in English on 2026-09-17 (live, datePublished 2025-07-13). SCMP: advocates and lawmakers on the creation-vs-distribution legal gap; Education Bureau comment.

News report · zh · Source inspected

Read in Chinese on 2026-09-17 (datePublished 2025-12-17). unwire.hk on the PCPD press conference: probe ended for insufficient evidence, no victim willing to provide further information, 20-30 victims, five deepfake complaints that year, new school/parent guidance. Model reading; no human bilingual review.

Event countries: Hong Kong SAR China. Affected-person countries: Hong Kong SAR China. Court countries: Unknown.

Event: the University of Hong Kong; victims are HKU-connected women in Hong Kong (CBS, NBC, HKFP, SCMP). The PCPD is a regulator, not a court, and no prosecution followed, so court_countries is empty.

Reviewed for publication 2026-09-17: Restored from the deletion of historical artifact rows and converted to facts-v3 under the 2026-09-15 charter, which brings non-consensual AI imagery and harmful artifacts into scope. Some 20 to 30 women had indecent AI images generated from their photos; the harm and the closed investigation are documented across CBS/AFP, NBC, HKFP, SCMP and unwire.hk. First-publication timestamp preserved.

What Happened

In February 2025 a male law student at the University of Hong Kong was found to have used free online AI software to create indecent images of women after friends discovered the files on his laptop. He had taken photos from the social-media accounts of some 20 to 30 women, including university classmates, former primary and secondary schoolmates and secondary-school teachers; an Instagram post by three victims said the material amounted to about 700 images (including deepfakes and unedited photos saved without consent), organised into folders named after the victims. The Standard reported the images dated back to about May 2024. There was no allegation the student distributed the images. When victims approached HKU in March 2025 seeking a disciplinary process, the university cited legal opinion that the conduct likely did not constitute an offence it could address, proposed a verbal reprimand and warning letter, and in April showed victims a roughly 60-word apology; some victims had to share tutorials with the accused. After the victims went public on 12 July 2025, the response drew criticism from lawmakers and advocates, and Chief Executive John Lee said universities bear responsibility for students' conduct. The PCPD opened a criminal investigation on 15 July 2025, treating non-consensual disclosure of personal data with intent to cause harm as a possible offence. On 17 December 2025 Privacy Commissioner Ada Chung announced the office was ending the investigation for insufficient evidence, because no victim was willing to provide further information, while releasing anti-deepfake guidance for schools and parents and noting the office had received five deepfake complaints and two enquiries that year, up from none the year before. Advocates said the episode exposed a legal gap: Hong Kong criminalises distribution, but not creation, of non-consensual intimate images.

Reported harm

Some 20 to 30 women had indecent and deepfake images of themselves generated with AI from their social-media photos; victims reported distress and had to share classes with the accused, and the criminal investigation was closed for insufficient evidence, leaving them without redress.

Psychological DistressReputational HarmExploitation or Abuse

Outcome

Resolved

February 2025: friends found the images on the student's laptop and the matter was reported to HKU. In April 2025 HKU showed victims a roughly 60-word apology letter, which many found insincere; the university said it had issued a warning letter and made class adjustments. 12 July 2025: three victims went public on Instagram. 15 July 2025: the Office of the Privacy Commissioner for Personal Data (PCPD) opened a criminal investigation. 17 December 2025: the PCPD announced it was ending the investigation for insufficient evidence, as no victim was willing to provide further information, and released deepfake guidance for schools and parents; the commissioner said the office would not rule out resuming if victims came forward with evidence. Hong Kong law criminalises publication or distribution of intimate images, including AI-generated ones, but not their mere creation.

People described

Some 20 to 30 women whose images were used, including the male law student's university classmates, former primary and secondary schoolmates, and secondary-school teachers; none is named

People reported harmed in this case

At least 20 people

0 AI participants · 20 other people harmed

CBS and Hong Kong Free Press report 20 to 30 women affected; NBC reports 'more than a dozen'; the PCPD (December 2025) referred to 20 to 30 victims. Documented minimum of 20; the ~700 figure counts images (deepfakes plus unedited saved photos), not people, and is not used as a person count.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2025). University of Hong Kong: a law student made about 700 indecent AI-generated images of some 20 to 30 classmates and teachers; the privacy watchdog opened then closed a criminal probe. NOPE: AI and people. https://nope.net/incidents/2025-hku-deepfake-scandal

BibTeX

@misc{2025_hku_deepfake_scandal,
  title = {University of Hong Kong: a law student made about 700 indecent AI-generated images of some 20 to 30 classmates and teachers; the privacy watchdog opened then closed a criminal probe},
  author = {NOPE},
  year = {2025},
  howpublished = {NOPE: AI and people},
  url = {https://nope.net/incidents/2025-hku-deepfake-scandal}
}

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.