Deepfake Video Call Drove $25M Wire Transfer Scam

ZDNet Security · High sophistication
Last updated July 30, 2026

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic impersonation can override normal suspicion.

How the attack worked

A finance employee received suspicious emails and then was invited to join an urgent video conference to approve wire transfers. On the call, deepfake video renders of his coworkers appeared, giving the appearance of a legitimate internal meeting. That realism was enough to override his earlier doubts, and he went on to complete several wire transfers during the session.

Why it succeeded

The core reason this attack worked is that the deepfake video created a stronger signal of trust than the suspicious emails that preceded it. The worker had reason to be cautious, but seeing familiar faces on a live call reduced that doubt. This shows how synthetic media can be used specifically to neutralize the skepticism that email-based warning signs would normally trigger. Attackers also don't need to fool basic camera checks; they can inject synthetic video directly into the data stream using virtual cameras or tampered and emulated devices, which means simple visual verification is not a reliable control on its own.

What to watch for

  • Urgent requests to join a video call specifically to approve payments or wire transfers
  • Pressure to complete multiple transfers within a short window
  • Suspicious emails that are later followed by a call that seems to "confirm" their legitimacy
  • Any process where a single video interaction is treated as sufficient proof of identity for a financial decision

How to build resistance

Organizations should treat video calls as untrusted for money movement decisions. Payment instructions delivered or confirmed on a video call should always be verified through a separate, known-good channel, such as calling a previously verified phone number or requiring a secondary approver who was not on the call. Earlier warning signs, like suspicious emails, should not be dismissed just because a later interaction appears more convincing; those signals should trigger a pause and independent verification rather than being overridden.

Because attackers can bypass simple camera checks, verification programs should layer multiple signals, including device recognition, location, and behavioral analytics, with additional step-up verification whenever something does not align. This reduces reliance on any single input, including video realism, as proof of identity.

Finally, as biometric verification becomes more common for account recovery and identity checks, it is worth remembering that biometric identifiers such as a face or fingerprint cannot be changed if they are ever compromised, unlike a password. Understanding how biometric data is stored, used, protected, and deleted is an important part of managing this risk across both personal and organizational contexts.

This technique aligns with known adversary behaviors for phishing via voice or video (T1566.002) and impersonation for information gathering (T1598).

Key findings

  • Attackers used deepfake video renders of colleagues on a conference call to convince a finance worker to make wire transfers.
  • The victim had concerns about earlier emails, but the realism of the deepfake call reduced their doubts.
  • Experts warn that attackers can bypass camera checks by injecting synthetic video via virtual cameras or tampered/emulated devices.
  • Defenses should layer verification signals (device, location, behavior) rather than relying on a single method like video alone.
  • Biometric privacy risk: biometric identifiers can’t be changed if compromised; users should understand storage, use, and deletion policies.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Treasury, Executives/Approvers, Security awareness training audiences.
  • Affected industries: Professional services (architecture/design), Technology/online services (account recovery/identity verification).
  • Attack channels: email, website.
  • Impersonated: Coworkers/leadership (deepfake video conference participants).

Red flags to watch for

  • Urgency and pressure to move money quickly
  • Emails seem suspicious but are ‘validated’ by a meeting invite/call
  • Unusual payment requests or multiple transfers requested in a short time window
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers use deepfakes to steal money?

A finance worker was convinced to join a conference call featuring deepfake renders of his colleagues, and the realistic video overrode his earlier suspicion about related emails, leading him to complete several wire transfers.

Can deepfake video bypass camera verification checks?

Yes. Attackers can bypass camera checks entirely by injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices, so video alone should not be treated as proof of identity.

What should organizations do to prevent this kind of fraud?

Verification should be layered with device recognition, location, and behavioral analytics, and payment requests should always be confirmed through a separate, known-good process rather than relying on a video call.

Why did the victim ignore his earlier doubts about suspicious emails?

Although he was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes shown on the call, illustrating how convincing synthetic video can override normal caution.

Read the video transcript

Imagine joining a video call with your whole finance team… and every single person on screen is a deepfake. That actually happened: a finance worker got an email saying, “Hi, please join this conference call now to review and urgently approve today’s wire transfers,” then saw deepfake versions of coworkers on the call and sent out multiple wires. Here’s the scary part: he was already suspicious of the emails, but the realistic faces on video overruled his gut. Attackers can even bypass camera checks by injecting synthetic video through virtual cameras or tampered devices. So if a call pushes you to move money fast, treat the video as untrusted: stop, and confirm the request through a separate known-good channel before you send a single wire.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026