The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic “colleagues,” approved about $25 million in transfers. The piece argues that these multi-channel, trust-based attacks bypass traditional email filtering because the “payload” is human manipulation, not malware.
How the Attack Worked
The fraud began the way many business email compromise attacks do: with an email impersonating a senior executive, in this case the company's UK-based CFO. The message created urgency around a set of transfers that needed to be processed quickly. When the targeted employee hesitated, the attackers did not give up. Instead, they escalated to a live video call featuring what appeared to be several familiar colleagues. In reality, these were synthetic, deepfake representations. Convinced by what they saw and heard, the employee approved 15 transfers totaling about $25 million.
Why It Succeeded
This attack succeeded because it moved beyond the inbox. Traditional phishing defenses are built to scan for malicious links or attachments, but here the payload was human manipulation, not malware. There was no file to detonate in a sandbox and no suspicious URL to flag. The video call added a layer of apparent legitimacy: seeing and hearing familiar-looking colleagues is a powerful trust signal, and most employees have never been trained to question whether a video call could be faked. The combination of urgency, authority impersonation, and a multi-channel follow-up gave the target little room to pause and verify through normal channels.
What to Watch For
- Urgent requests to process transfers quickly, especially when framed as time-sensitive or confidential
- Requests that push a live video or voice call as reassurance or proof of identity, rather than relying on documented approval processes
- An unusual number or value of transfers compared with normal business activity
- Any pressure to skip or shortcut standard payment verification steps, even when the request appears to come from a known executive
Building Resistance
Security teams should extend their threat model past email into voice and video, since this case involved a call, not just a message. Employees in finance, accounts payable, treasury, and executive assistant roles are the most likely targets, since they are positioned to approve payments. Awareness training should teach staff that a familiar-looking face or voice on a call is not sufficient proof of identity, and that any request to change payment details or approve unusual transfers should trigger out-of-band verification through a separate, trusted channel. Encouraging employees to slow down and follow a documented approval process, particularly when a request relies on urgency or secrecy, can help interrupt the pressure tactics that made this scheme effective. Organizations should also recognize that confidence in countering deepfakes is often low industry-wide, which makes proactive training and verification procedures especially important for any organization that combines email with video calling and collaboration tools.
Key findings
- A real-world multi-step fraud at Arup began with a phishing email impersonating the CFO and escalated to a deepfake video call to close the scam.
- The Arup victim approved 15 transfers totaling about $25 million after being convinced by a video call where multiple “colleagues” were synthetic.
- The article claims modern attacks often have no malicious attachment/link to scan because the core tactic is impersonation and trust exploitation across channels.
- It cites survey data suggesting many organizations lack confidence in countering deepfakes and that vendor/partner impersonation is common.
Who’s being targeted
- Commonly targeted roles: Finance/AP/Treasury, Executives and Executive Assistants, Anyone who can approve payments, Security awareness training teams.
- Affected industries: Engineering and design services, Professional services, Any organization using email + collaboration/video calling.
- Attack channels: email, vishing.
- Impersonated: Company CFO and several internal colleagues (deepfake video).
Red flags to watch for
- Urgency/pressure to bypass normal payment verification steps
- Request to rely on a live video call as “proof” of identity
- Unusual number/value of transfers compared with normal business activity
Frequently asked questions
How did the Arup deepfake scam start?
The attack began with a phishing email impersonating the company's UK-based CFO, then escalated to a deepfake video call to convince the employee to act.
How much money was lost in the Arup case?
The employee approved 15 transfers worth about $25 million after being convinced by the deepfake video call.
Why do these attacks bypass traditional email filters?
The core tactic is impersonation and trust exploitation across channels rather than malicious attachments or links, so there is often nothing malicious for email security tools to scan.
How can organizations defend against deepfake video call fraud?
Treat payment and bank-detail changes as requiring out-of-band verification regardless of who appears to request them, and train staff that voice and video can be faked.
Read the video transcript
Imagine this: an email from your CFO, “I need you to process urgent transfers today. I’ll explain on a quick call.” That’s how the Arup fraud started. When the employee hesitated, they got a live video call: it looked like the CFO and familiar colleagues, but they were deepfakes. Fifteen transfers. About twenty‑five million dollars gone. Here’s the twist: there was no bad link, no attachment to scan. The whole payload was pressure on a live call, “it’s urgent, keep this quiet, just push the payments through.” So if you ever get an urgent payment request, even on video, pause, and confirm it through your documented approval process before moving a cent.