Deepfake CFO Call Triggers $25M Transfer Scam

Hacker Noon Cybersecurity · High sophistication
Last updated July 30, 2026

A worker received an email that appeared to be from the company’s CFO requesting a confidential transaction. When the employee tried to verify, attackers escalated to a video call using AI deepfakes of the CFO and other colleagues, convincing the employee to make 15 transfers totaling about $25 million. The piece argues AI-driven personalization is making phishing far more effective and harder to spot by “looking for mistakes.”

How the attack unfolded

The attack began with a simple, targeted email. A finance employee received a message that appeared to come from the company's UK-based CFO, asking him to handle a confidential transaction. When he attempted to verify the request rather than acting on it blindly, the attackers did not back off. Instead, they escalated the deception by putting him on a video call featuring what looked like the CFO and other recognizable colleagues. In reality, every face and voice on that call was an AI-generated deepfake, built from publicly available footage of company executives. Convinced by what he saw and heard, the employee executed fifteen separate transfers totaling around $25 million before contacting head office and learning the truth.

Why this approach succeeded

The scam worked because it exploited the exact instinct employees are trained to use: verify before you act. Normally, hearing a familiar voice or seeing a familiar face on a call is treated as strong proof of identity. This attack turned that assumption against the victim by faking the verification step itself. The pretext also leaned on secrecy, framing the request as a "confidential transaction," which discouraged the employee from looping in additional colleagues who might have spotted the fraud. The polish of the lure mattered too. There were no obvious grammar mistakes or awkward phrasing to raise suspicion, since the request looked plausible and contextually accurate.

What to watch for

  • Requests framed as urgent or confidential, especially those discouraging normal escalation or second opinions
  • Verification that happens entirely within attacker-controlled channels, such as a reply email or a call initiated by the requester
  • High-value payment instructions that bypass standard approval processes or multi-person sign-off
  • Video or voice calls used as the sole proof of identity for a financial decision

Building resistance to this technique

Organizations in finance, treasury, and payments roles should treat any request for a payment or transfer as unverified until confirmed through a channel the recipient initiates independently, such as calling a known number from an internal directory rather than one provided in the suspicious message. Since deepfakes can convincingly replicate familiar colleagues, video and voice should no longer be treated as sufficient proof of identity for high-risk approvals. Awareness training should also move away from teaching staff to look for spelling or grammar errors, since modern lures can be polished, well-researched, and context-aware. Finally, employees should assume that publicly available information, such as LinkedIn profiles and company websites, will be used to make impersonation attempts feel internally consistent and legitimate.

Key findings

  • Attackers used an email impersonating the UK-based CFO to initiate a “confidential transaction” request.
  • When the target attempted to confirm, attackers used a video call with AI deepfakes of recognizable executives and colleagues to overcome skepticism.
  • The victim executed “fifteen transfers totalling around 25 million dollars” before discovering the call participants were fake.
  • The deepfakes were created from “publicly available footage of Arup executives.”
  • The article cites research claiming AI-written phishing lures can significantly increase click-through rates (example given: 54% vs 12%) due to personalization.

Who’s being targeted

  • Commonly targeted roles: Finance/Treasury, Accounts Payable, Executives and Executive Assistants, Anyone authorized to approve or initiate payments.
  • Affected industries: Professional services, Engineering and design, Corporate finance / treasury operations.
  • Attack channels: email, vishing.
  • Impersonated: Company CFO (and other colleagues) using AI deepfake video.

Red flags to watch for

  • Unusual secrecy and pressure around a payment (“confidential transaction”)
  • Verification happens only on attacker-controlled channels (email/video call), not via known internal contacts
  • Process bypass: high-value transfers executed without standard payment controls/escalation
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attackers convince the employee to transfer money?

The employee received an email posing as the UK-based CFO requesting a confidential transaction. When he tried to verify the request, the attackers escalated to a video call using AI deepfakes of the CFO and other colleagues, which overcame his skepticism.

How much money was transferred in this scam?

The employee made fifteen transfers totaling around $25 million before calling head office and discovering the call participants were fake.

Why didn't the employee catch the fraud sooner?

The deepfakes were built from publicly available footage of executives, making the faces and voices on the call appear convincingly real and familiar.

What should employees do differently to avoid this kind of scam?

Verify money movement requests through an independent channel you choose, such as a known phone number, rather than trusting the same email or call chain the request arrived through.

Read the video transcript

Imagine getting an email from our CFO: “Please handle a confidential transaction.” Looks normal, grammar perfect, sender name looks right. That’s what happened in a real case. When the employee tried to confirm, they were put on a video call with what looked and sounded like the UK-based CFO and familiar colleagues. Every face, every voice, was an AI deepfake built from public footage. On that fake call, they were calmly walked through fifteen bank transfers totalling about 25 million dollars. No bad grammar, no obvious slip-ups, just a believable story using names, roles, and details scraped from public sites like LinkedIn and company pages. Here’s the move: if you ever get a payment or “confidential transaction” request, even on video, pause, and confirm it using a phone number or channel you look up yourself, not the one in the email or the call.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

July 31, 2026