Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The Hacker News · High sophistication
Last updated August 20, 2026

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic “colleagues,” approved about $25 million in transfers. The piece argues that these multi-channel, trust-based attacks bypass traditional email filtering because the “payload” is human manipulation, not malware.

How the Attack Worked

The fraud began the way many business email compromise attacks do: with an email impersonating a senior executive, in this case the company's UK-based CFO. The message created urgency around a set of transfers that needed to be processed quickly. When the targeted employee hesitated, the attackers did not give up. Instead, they escalated to a live video call featuring what appeared to be several familiar colleagues. In reality, these were synthetic, deepfake representations. Convinced by what they saw and heard, the employee approved 15 transfers totaling about $25 million.

Why It Succeeded

This attack succeeded because it moved beyond the inbox. Traditional phishing defenses are built to scan for malicious links or attachments, but here the payload was human manipulation, not malware. There was no file to detonate in a sandbox and no suspicious URL to flag. The video call added a layer of apparent legitimacy: seeing and hearing familiar-looking colleagues is a powerful trust signal, and most employees have never been trained to question whether a video call could be faked. The combination of urgency, authority impersonation, and a multi-channel follow-up gave the target little room to pause and verify through normal channels.

What to Watch For

  • Urgent requests to process transfers quickly, especially when framed as time-sensitive or confidential
  • Requests that push a live video or voice call as reassurance or proof of identity, rather than relying on documented approval processes
  • An unusual number or value of transfers compared with normal business activity
  • Any pressure to skip or shortcut standard payment verification steps, even when the request appears to come from a known executive

Building Resistance

Security teams should extend their threat model past email into voice and video, since this case involved a call, not just a message. Employees in finance, accounts payable, treasury, and executive assistant roles are the most likely targets, since they are positioned to approve payments. Awareness training should teach staff that a familiar-looking face or voice on a call is not sufficient proof of identity, and that any request to change payment details or approve unusual transfers should trigger out-of-band verification through a separate, trusted channel. Encouraging employees to slow down and follow a documented approval process, particularly when a request relies on urgency or secrecy, can help interrupt the pressure tactics that made this scheme effective. Organizations should also recognize that confidence in countering deepfakes is often low industry-wide, which makes proactive training and verification procedures especially important for any organization that combines email with video calling and collaboration tools.

Key findings

  • A real-world multi-step fraud at Arup began with a phishing email impersonating the CFO and escalated to a deepfake video call to close the scam.
  • The Arup victim approved 15 transfers totaling about $25 million after being convinced by a video call where multiple “colleagues” were synthetic.
  • The article claims modern attacks often have no malicious attachment/link to scan because the core tactic is impersonation and trust exploitation across channels.
  • It cites survey data suggesting many organizations lack confidence in countering deepfakes and that vendor/partner impersonation is common.

Who’s being targeted

  • Commonly targeted roles: Finance/AP/Treasury, Executives and Executive Assistants, Anyone who can approve payments, Security awareness training teams.
  • Affected industries: Engineering and design services, Professional services, Any organization using email + collaboration/video calling.
  • Attack channels: email, vishing.
  • Impersonated: Company CFO and several internal colleagues (deepfake video).

Red flags to watch for

  • Urgency/pressure to bypass normal payment verification steps
  • Request to rely on a live video call as “proof” of identity
  • Unusual number/value of transfers compared with normal business activity
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Arup deepfake scam start?

The attack began with a phishing email impersonating the company's UK-based CFO, then escalated to a deepfake video call to convince the employee to act.

How much money was lost in the Arup case?

The employee approved 15 transfers worth about $25 million after being convinced by the deepfake video call.

Why do these attacks bypass traditional email filters?

The core tactic is impersonation and trust exploitation across channels rather than malicious attachments or links, so there is often nothing malicious for email security tools to scan.

How can organizations defend against deepfake video call fraud?

Treat payment and bank-detail changes as requiring out-of-band verification regardless of who appears to request them, and train staff that voice and video can be faked.

Read the video transcript

Imagine this: an email from your CFO, “I need you to process urgent transfers today. I’ll explain on a quick call.” That’s how the Arup fraud started. When the employee hesitated, they got a live video call: it looked like the CFO and familiar colleagues, but they were deepfakes. Fifteen transfers. About twenty‑five million dollars gone. Here’s the twist: there was no bad link, no attachment to scan. The whole payload was pressure on a live call, “it’s urgent, keep this quiet, just push the payments through.” So if you ever get an urgent payment request, even on video, pause, and confirm it through your documented approval process before moving a cent.

Similar attacks

Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026