Arup Deepfake Call Triggers $25M Transfer

Cyber Defense Magazine · High sophistication
Last updated August 31, 2026

The article warns that AI is making impersonation and social engineering more convincing, citing a real 2024 case where Arup was reportedly tricked during a video conference featuring a digitally cloned senior manager. The core lesson is to validate requests through policy and independent verification, not by how “real” a person looks or sounds.

How the Arup Incident Worked

The source article cites the 2024 Hong Kong case involving Arup as a real-world example of deepfake-enabled fraud. Fraudsters reportedly used a digitally cloned senior manager during a video conference to help induce $25 million in transfers. The scenario did not rely on a suspicious email or an obviously fake caller. Instead, it inserted a convincing synthetic figure of authority directly into a legitimate business workflow: a payment approval process conducted over video.

Why This Kind of Attack Succeeds

The article frames deepfakes as trust-substitution tools rather than simple fake videos. That distinction matters because the danger is not the technical trick itself, it is what the trick replaces: the human judgment that normally underlies approval decisions. A synthetic executive in a video call or a cloned voice in a payment workflow can inject synthetic authority into real business processes, particularly around finance, treasury, and accounts payable functions where urgency and hierarchy already shape decision-making.

What to Watch For

Key red flags described in connection with this style of attack include:

  • A high-value transfer request made during a call without independent verification
  • Pressure to treat a request as normal simply because it appears to come from a senior leader
  • Process exceptions, such as bypassing an approved channel or policy step, justified by urgency or authority

These red flags are less about spotting a technical flaw in the video or audio and more about recognizing when a workflow is being pushed outside its normal controls.

Building Resistance to Deepfake-Enabled Fraud

The core lesson from this incident is a shift in how validation questions are framed. Rather than asking whether a call looks or sounds authentic, the recommended question is whether the request is valid under policy, made through an approved channel, and confirmed with independent verification. Practical steps that align with this guidance include:

  • Requiring independent callbacks or secondary confirmation for high-value transfers, regardless of how the request was delivered
  • Applying dual approval controls to payment workflows so no single video call or voice message can authorize a transfer
  • Training finance, treasury, and executive staff that sophisticated social engineering may build trust gradually rather than arriving as an obvious one-off phishing attempt

Because the most effective AI-enabled social engineering is designed to resemble an ongoing relationship rather than a single suspicious message, organizations with payment approval workflows, including engineering and professional services firms, benefit from treating authority and familiarity as insufficient grounds for approving financial transactions on their own.

Key findings

  • The article cites a real incident: “The 2024 Hong Kong deepfake fraud involving Arup… reportedly used a digitally cloned senior manager in a video conference to help induce $25 million in transfers.”
  • It frames deepfakes as “trust-substitution tools” that insert synthetic authority into real workflows (e.g., payments).
  • It recommends shifting validation from “Does this look or sound authentic?” to “Is this request valid under policy… with independent verification?”

Who’s being targeted

  • Commonly targeted roles: Finance/Treasury, Accounts Payable, Executives and budget owners, Anyone who approves or initiates payments.
  • Affected industries: Engineering and professional services, Any organization with payment approval workflows.
  • Attack channels: vishing.
  • Impersonated: Senior manager/executive (digitally cloned).

Red flags to watch for

  • A high-value transfer request is made during a call without independent verification
  • Pressure to treat the request as normal because it appears to come from a senior leader
  • Process exceptions (channel/policy bypass) justified by urgency or authority
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the Arup deepfake case?

Fraudsters reportedly used a digitally cloned senior manager during a video conference to help induce $25 million in transfers, according to the 2024 Hong Kong incident cited in the source article.

Why are deepfakes considered trust substitution tools?

The article frames deepfakes as trust substitution tools because they insert synthetic authority into real business workflows, such as payment approvals, rather than simply faking a video.

How should organizations verify payment requests to resist this kind of attack?

The recommended approach shifts the question from whether a request looks or sounds authentic to whether it is valid under policy, made through an approved channel, and confirmed with independent verification.

Which roles are most at risk from deepfake enabled payment fraud?

Finance and treasury staff, accounts payable teams, executives, and anyone who approves or initiates payments are the primary targets described in the source material.

Read the video transcript

Fraudsters reportedly used a digitally cloned senior manager in a video conference to help steal $25 million from Arup. Here’s the trick: the deepfake ‘boss’ joins a normal-looking video meeting, sounds urgent, and tells finance to push through high-value transfers as if it’s just routine business. Deepfakes are trust-substitution tools: they swap in synthetic authority. The red flag isn’t the video quality; it’s a big payment request made on a call, with pressure to skip normal approval steps. If anyone asks for a payment on a call, even your ‘boss’, pause and do one thing: hang up and confirm the request through your normal payment process and an independent callback.

MITRE ATT&CK techniques

Similar attacks

Deepfake CFO Video Call Triggers $25M Fraud

Deepfake CFO Video Call Triggers $25M Fraud

The article describes real-world deepfake and identity-fraud incidents where attackers used believable human impersonation to manipulate employees. In one case, a staff member at Arup joined a video call with what appeared to be the CFO and was tricked into sending about $25M across multiple wire…

August 21, 2026
Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026