The article highlights that deepfakes are being used in real social-engineering incidents, including audio and video calls that impersonate trusted leaders. It cites a well-known 2024 Hong Kong case where scammers used a fake video meeting to pose as a company’s CFO and colleagues, leading an employee to transfer over $25 million.
Key findings
- Gartner reports many CISOs have seen deepfake-enabled social engineering via employee audio and video calls within the past 12 months.
- A cited real-world case involved a finance employee joining a video call that appeared to include the CFO and colleagues, resulting in a transfer of more than $25M to scammer-controlled accounts.
- Gartner recommends making verification the default for any risky request and hardening high-risk workflows like account recovery, privileged access, and payment authorization.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Treasury, Executive Assistants, Executives, IT Service Desk (account recovery).
- Affected industries: Cross-industry (finance and payment authorization functions).
- Attack channels: vishing.
- Impersonated: Company CFO and several colleagues (via deepfake video meeting).
Awareness takeaways
- Treat any high-risk request (payments, access, account recovery) as ‘verify by default,’ even if it appears to come from a trusted leader on a call.
- Add stronger controls around payment authorization, privileged access, and account recovery, since attackers actively target these workflows.
- Prepare incident response for multi-channel impersonation (email + calls + video) and AI-manipulated interactions, not just traditional phishing emails.
Red flags to watch for
- Unusual urgency and pressure to transfer large sums quickly
- Payment destination is provided/changed during a call rather than through established channels
- No out-of-band verification before executing a high-risk transaction
Read the video transcript
A finance employee joined a video call with their CFO and teammates… and sent $25 million straight to scammers. This was a deepfake video meeting. The CFO’s face and voice were AI-generated, plus fake coworkers, all pushing an urgent wire transfer to new accounts shared on the call. Here’s the trap: urgent pressure, a huge payment, and new bank details given only on the call. No email trail. No standard approval. No second check outside that meeting. If a call asks for money, access, or account changes, assume deepfake until proven real. Hang up, then verify through your normal channel before you do anything.