Deepfake CFO Video Call Triggers $25M Fraud

ZDNet Security · High sophistication
Last updated August 21, 2026

The article describes real-world deepfake and identity-fraud incidents where attackers used believable human impersonation to manipulate employees. In one case, a staff member at Arup joined a video call with what appeared to be the CFO and was tricked into sending about $25M across multiple wire transfers. Experts recommend adding low-tech verification steps (like shared verbal passphrases and hardware security keys) so employees aren’t forced to rely on recognizing a face or voice.

Key findings

  • Arup was reportedly defrauded after an employee joined a video call that appeared to include the company CFO, resulting in ~15 wire transfers totaling about $25M.
  • The people on the call were described as AI-generated clones created from public appearances and earnings calls.
  • Experts warn that recognizing a face/voice is no longer reliable authentication for high-value transactions.
  • The article also cites a separate real incident where KnowBe4 hired an attacker using a fake identity, who then used a company workstation in an attempted malware operation.
  • Recommended mitigations include “no-exception” verification steps such as verbal passphrases, hardware security keys, out-of-band callbacks, and dual authorization for high-risk transactions.

Who’s being targeted

  • Commonly targeted roles: Finance, Treasury, Accounts Payable, Executives, HR / Recruiting, IT / Security.
  • Affected industries: Professional services, Cybersecurity services / security awareness training.
  • Attack channels: vishing.
  • Impersonated: Company CFO and other executives (AI deepfake clones).

Awareness takeaways

  • Do not treat a familiar face or voice on a call as proof of identity, use an agreed verification step for high-risk requests.
  • Require “no-exception” controls for high-value transactions (dual approval + out-of-band verification), especially when urgency or authority pressure is used.
  • Adopt phishing-resistant authentication where possible (e.g., hardware security keys) and consider shared verbal passphrases for voice/video verification.

Red flags to watch for

  • Urgency/pressure to bypass normal approval steps
  • Request to send funds to third-party accounts
  • Authentication relies only on recognizing face/voice on a call
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine joining a video call with your CFO… and wiring out $25 million to criminals. That actually happened at Arup. An employee joined a call that looked like the CFO and other execs. Every face and voice on the other side was an AI deepfake clone built from public videos. They were pushed to rush about 15 wire transfers to third-party accounts, based only on a familiar face and voice. As Deepak Gupta put it: seeing and hearing someone is no longer proof they are real. So if anyone on a call asks for a high-value transfer, stop and use our no-exception rule: hang up, then confirm through our approved out-of-band channel before you move a cent.

Similar attacks

Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
Deepfake Zoom Call Tricks CFO Into $500K Transfer

Deepfake Zoom Call Tricks CFO Into $500K Transfer

A real incident described in the article involved criminals using a deepfake Zoom call where all participants (including the CFO’s boss) were fabricated, convincing a Singaporean CFO to transfer US$500,000. The article focuses on Fraunhofer SIT’s prototype to detect deepfakes in live video calls…

August 5, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026