The article describes how criminals are using AI-generated video (“deepfakes”) to impersonate executives and trusted colleagues on live video calls. A real 2024 case at engineering firm Arup shows how a finance employee was convinced by a deepfake CFO and colleagues to send about $25 million across multiple transfers. The piece also outlines repeatable scam patterns (CFO payment approval, fake auditor, fake HR onboarding) and emphasizes using separate-channel verification, not “trusting the face on screen.”
How the attack worked
In this 2024 incident, an employee at an engineering firm's Hong Kong office received a request framed as a confidential transaction. To verify it, the employee asked for a video call, a reasonable instinct that backfired. On the call, the employee saw people who appeared to be the company's CFO and several colleagues. In reality, every person on that call was an AI-generated deepfake, built from publicly available footage of real executives. Believing the request was genuine, the employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered.
Why it succeeded
The scam succeeded because the employee, and the organization's norms, treated a live video call as sufficient proof of identity. Nobody had told the employee that a convincing face on screen is no longer reliable evidence of who is actually speaking. The request was also framed as urgent and confidential, which discouraged normal verification steps, and the payment pattern (multiple transfers, large total) was structured to move quickly before anyone paused to check.
What to watch for
Beyond this specific case, the same deepfake technique can appear in other guises:
- A synthetic persona posing as an auditor sitting through an entire meeting designed to extract system access, security answers, or credentials.
- A synthetic HR contact hosting an onboarding call with a genuinely new hire, using the session to capture details about internal systems, access permissions, or credential recovery information.
- Any video meeting where the underlying ask, once stripped of pleasantries, is really a financial transaction or a set of credentials.
These scenarios work precisely because those meetings are built around the assumption that a video call with a real person is inherently trustworthy.
How to build resistance
Organizations can reduce exposure to this pattern with a few concrete practices:
- Require a second, genuinely separate verification channel (a known phone number, an internal ticketing system) for any financial authorization or credential disclosure, no financial authorization or credential disclosure should ever take place via video call alone.
- Establish pre-agreed code words or gestures for high-risk requests, since these are one of the few things a deepfake genuinely can't produce on demand.
- Give employees explicit, repeated permission to ask "is this really you?" on any call, regardless of who appears to be on screen, including senior leaders.
- Train finance, HR, IT, and compliance staff to recognize when an ordinary-seeming meeting drifts toward requests for money movement, credentials, or security answers.
These steps target the specific weakness this incident exposed: the assumption that seeing a familiar face on a screen is the same as verifying identity.
Key findings
- In a real 2024 incident, Arup’s Hong Kong office was targeted via a deepfake video meeting where multiple “colleagues” appeared on-screen but were AI-generated.
- The victim authorized “fifteen transfers totaling roughly $25 million” before discovering the fraud.
- The target initially suspected phishing and requested a video call to verify, showing that video calls can no longer be treated as proof of identity.
- Attack patterns include: (1) pre-recorded deepfake played on a live call, (2) real-time face swapping in a live call, and (3) fake onboarding/compliance meetings designed to extract access and credentials.
- Recommended controls include code words/gestures, strict rules that video alone cannot authorize payments or credential sharing, and verifying via a separate channel using known contact details.
Who’s being targeted
- Commonly targeted roles: Finance (AP/Treasury), Executives and executive assistants, HR and recruiting/onboarding teams, IT and Service Desk, Compliance/Audit liaisons.
- Affected industries: Engineering and professional services, Finance and payments (cross-industry fraud).
- Attack channels: email, website.
- Impersonated: Company CFO and several internal colleagues (AI-generated), External auditor / compliance reviewer (synthetic persona), HR contact / HR manager (deepfake).
Red flags to watch for
- Request is urgent and confidential, discouraging normal checks
- Verification is pushed onto a video call as ‘proof’ of identity
- Unusual payment pattern (many transfers / large total)
- Asks for credentials or security answers as part of a ‘routine’ meeting
- Uses the normality of a video meeting to reduce skepticism
- Relies on authority/compliance pressure to bypass policy
- Requests credential recovery details or access permissions during a call
- Pressure to comply because it appears to be HR/onboarding
- No secondary verification of the HR person’s identity
Frequently asked questions
How did the deepfake video call scam work?
An employee joined a video call believing it included the company's CFO and several colleagues, but every person on the call was an AI-generated deepfake built from public footage of real executives.
Why did the employee trust the video call?
The employee initially suspected phishing and requested a video call to verify the request, but the video call itself was treated as sufficient proof of identity, since convincing deepfakes are no longer easy to detect by sight.
How much money was transferred in this incident?
The employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered.
What controls can prevent this type of attack?
Recommended controls include pre-agreed code words or gestures, strict policies that video alone cannot authorize payments or credential sharing, and verification through a separate, known channel.
Read the video transcript
In 2024, one finance employee wired $25 million after a single “confidential transaction” video call. They joined a video call with people who looked exactly like their CFO and colleagues. Every person on that call was an AI-generated deepfake, built from public footage. Here’s the trap: they push urgency and secrecy, then say, “Let’s jump on video to prove it’s me.” On that call, they rush you into big payments or an “audit” that quietly asks for system access and security answers. Aha moment: seeing someone on video is no longer proof it’s them. If anyone on a call asks for money movement or credentials, stop and confirm through a separate channel you already trust.