
Deepfake Video Call Drove $25M Wire Transfer Scam
The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance…
A worker received an email that appeared to be from the company’s CFO requesting a confidential transaction. When the employee tried to verify, attackers escalated to a video call using AI deepfakes of the CFO and other colleagues, convincing the employee to make 15 transfers totaling about $25 million. The piece argues AI-driven personalization is making phishing far more effective and harder to spot by “looking for mistakes.”
The attack began with a simple, targeted email. A finance employee received a message that appeared to come from the company's UK-based CFO, asking him to handle a confidential transaction. When he attempted to verify the request rather than acting on it blindly, the attackers did not back off. Instead, they escalated the deception by putting him on a video call featuring what looked like the CFO and other recognizable colleagues. In reality, every face and voice on that call was an AI-generated deepfake, built from publicly available footage of company executives. Convinced by what he saw and heard, the employee executed fifteen separate transfers totaling around $25 million before contacting head office and learning the truth.
The scam worked because it exploited the exact instinct employees are trained to use: verify before you act. Normally, hearing a familiar voice or seeing a familiar face on a call is treated as strong proof of identity. This attack turned that assumption against the victim by faking the verification step itself. The pretext also leaned on secrecy, framing the request as a "confidential transaction," which discouraged the employee from looping in additional colleagues who might have spotted the fraud. The polish of the lure mattered too. There were no obvious grammar mistakes or awkward phrasing to raise suspicion, since the request looked plausible and contextually accurate.
Organizations in finance, treasury, and payments roles should treat any request for a payment or transfer as unverified until confirmed through a channel the recipient initiates independently, such as calling a known number from an internal directory rather than one provided in the suspicious message. Since deepfakes can convincingly replicate familiar colleagues, video and voice should no longer be treated as sufficient proof of identity for high-risk approvals. Awareness training should also move away from teaching staff to look for spelling or grammar errors, since modern lures can be polished, well-researched, and context-aware. Finally, employees should assume that publicly available information, such as LinkedIn profiles and company websites, will be used to make impersonation attempts feel internally consistent and legitimate.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The employee received an email posing as the UK-based CFO requesting a confidential transaction. When he tried to verify the request, the attackers escalated to a video call using AI deepfakes of the CFO and other colleagues, which overcame his skepticism.
The employee made fifteen transfers totaling around $25 million before calling head office and discovering the call participants were fake.
The deepfakes were built from publicly available footage of executives, making the faces and voices on the call appear convincingly real and familiar.
Verify money movement requests through an independent channel you choose, such as a known phone number, rather than trusting the same email or call chain the request arrived through.
Imagine getting an email from our CFO: “Please handle a confidential transaction.” Looks normal, grammar perfect, sender name looks right. That’s what happened in a real case. When the employee tried to confirm, they were put on a video call with what looked and sounded like the UK-based CFO and familiar colleagues. Every face, every voice, was an AI deepfake built from public footage. On that fake call, they were calmly walked through fifteen bank transfers totalling about 25 million dollars. No bad grammar, no obvious slip-ups, just a believable story using names, roles, and details scraped from public sites like LinkedIn and company pages. Here’s the move: if you ever get a payment or “confidential transaction” request, even on video, pause, and confirm it using a phone number or channel you look up yourself, not the one in the email or the call.

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance…

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social…

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…