Deepfake Video Call Fooled Staff into $25M Transfers

Proton Blog · High sophistication
Last updated September 22, 2026

The article describes how criminals are using AI-generated video (“deepfakes”) to impersonate executives and trusted colleagues on live video calls. A real 2024 case at engineering firm Arup shows how a finance employee was convinced by a deepfake CFO and colleagues to send about $25 million across multiple transfers. The piece also outlines repeatable scam patterns (CFO payment approval, fake auditor, fake HR onboarding) and emphasizes using separate-channel verification, not “trusting the face on screen.”

How the attack worked

In this 2024 incident, an employee at an engineering firm's Hong Kong office received a request framed as a confidential transaction. To verify it, the employee asked for a video call, a reasonable instinct that backfired. On the call, the employee saw people who appeared to be the company's CFO and several colleagues. In reality, every person on that call was an AI-generated deepfake, built from publicly available footage of real executives. Believing the request was genuine, the employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered.

Why it succeeded

The scam succeeded because the employee, and the organization's norms, treated a live video call as sufficient proof of identity. Nobody had told the employee that a convincing face on screen is no longer reliable evidence of who is actually speaking. The request was also framed as urgent and confidential, which discouraged normal verification steps, and the payment pattern (multiple transfers, large total) was structured to move quickly before anyone paused to check.

What to watch for

Beyond this specific case, the same deepfake technique can appear in other guises:

  • A synthetic persona posing as an auditor sitting through an entire meeting designed to extract system access, security answers, or credentials.
  • A synthetic HR contact hosting an onboarding call with a genuinely new hire, using the session to capture details about internal systems, access permissions, or credential recovery information.
  • Any video meeting where the underlying ask, once stripped of pleasantries, is really a financial transaction or a set of credentials.

These scenarios work precisely because those meetings are built around the assumption that a video call with a real person is inherently trustworthy.

How to build resistance

Organizations can reduce exposure to this pattern with a few concrete practices:

  • Require a second, genuinely separate verification channel (a known phone number, an internal ticketing system) for any financial authorization or credential disclosure, no financial authorization or credential disclosure should ever take place via video call alone.
  • Establish pre-agreed code words or gestures for high-risk requests, since these are one of the few things a deepfake genuinely can't produce on demand.
  • Give employees explicit, repeated permission to ask "is this really you?" on any call, regardless of who appears to be on screen, including senior leaders.
  • Train finance, HR, IT, and compliance staff to recognize when an ordinary-seeming meeting drifts toward requests for money movement, credentials, or security answers.

These steps target the specific weakness this incident exposed: the assumption that seeing a familiar face on a screen is the same as verifying identity.

Key findings

  • In a real 2024 incident, Arup’s Hong Kong office was targeted via a deepfake video meeting where multiple “colleagues” appeared on-screen but were AI-generated.
  • The victim authorized “fifteen transfers totaling roughly $25 million” before discovering the fraud.
  • The target initially suspected phishing and requested a video call to verify, showing that video calls can no longer be treated as proof of identity.
  • Attack patterns include: (1) pre-recorded deepfake played on a live call, (2) real-time face swapping in a live call, and (3) fake onboarding/compliance meetings designed to extract access and credentials.
  • Recommended controls include code words/gestures, strict rules that video alone cannot authorize payments or credential sharing, and verifying via a separate channel using known contact details.

Who’s being targeted

  • Commonly targeted roles: Finance (AP/Treasury), Executives and executive assistants, HR and recruiting/onboarding teams, IT and Service Desk, Compliance/Audit liaisons.
  • Affected industries: Engineering and professional services, Finance and payments (cross-industry fraud).
  • Attack channels: email, website.
  • Impersonated: Company CFO and several internal colleagues (AI-generated), External auditor / compliance reviewer (synthetic persona), HR contact / HR manager (deepfake).

Red flags to watch for

  • Request is urgent and confidential, discouraging normal checks
  • Verification is pushed onto a video call as ‘proof’ of identity
  • Unusual payment pattern (many transfers / large total)
  • Asks for credentials or security answers as part of a ‘routine’ meeting
  • Uses the normality of a video meeting to reduce skepticism
  • Relies on authority/compliance pressure to bypass policy
  • Requests credential recovery details or access permissions during a call
  • Pressure to comply because it appears to be HR/onboarding
  • No secondary verification of the HR person’s identity
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the deepfake video call scam work?

An employee joined a video call believing it included the company's CFO and several colleagues, but every person on the call was an AI-generated deepfake built from public footage of real executives.

Why did the employee trust the video call?

The employee initially suspected phishing and requested a video call to verify the request, but the video call itself was treated as sufficient proof of identity, since convincing deepfakes are no longer easy to detect by sight.

How much money was transferred in this incident?

The employee authorized fifteen transfers totaling roughly $25 million before the fraud was discovered.

What controls can prevent this type of attack?

Recommended controls include pre-agreed code words or gestures, strict policies that video alone cannot authorize payments or credential sharing, and verification through a separate, known channel.

Read the video transcript

In 2024, one finance employee wired $25 million after a single “confidential transaction” video call. They joined a video call with people who looked exactly like their CFO and colleagues. Every person on that call was an AI-generated deepfake, built from public footage. Here’s the trap: they push urgency and secrecy, then say, “Let’s jump on video to prove it’s me.” On that call, they rush you into big payments or an “audit” that quietly asks for system access and security answers. Aha moment: seeing someone on video is no longer proof it’s them. If anyone on a call asks for money movement or credentials, stop and confirm through a separate channel you already trust.

Similar attacks

Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Deepfake Video Call Led to $25M Transfer

Deepfake Video Call Led to $25M Transfer

The article explains how generative AI is making phishing and impersonation more convincing, so “bad grammar” is no longer a reliable warning sign. It cites a real case in Hong Kong where fraudsters used deepfake video to impersonate senior colleagues on a video meeting and tricked a finance worker…

August 28, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026