Deepfake Video Call Led to $25M Transfer

Proton Blog · High sophistication
Last updated August 31, 2026

The article explains how generative AI is making phishing and impersonation more convincing, so “bad grammar” is no longer a reliable warning sign. It cites a real case in Hong Kong where fraudsters used deepfake video to impersonate senior colleagues on a video meeting and tricked a finance worker into transferring about $25 million. It recommends shifting training toward verification steps (out-of-band callbacks, multi-person approvals, and strong credential protections) rather than judging email wording alone.

How the attack worked

In a widely referenced 2024 incident, fraudsters used deepfake video to impersonate senior colleagues during a video meeting with a finance worker in Hong Kong. The fake executives requested an urgent, high-value transfer, and the employee, believing the call was legitimate because the people on screen looked familiar, processed the payment. The result was a transfer of about $25 million based entirely on instructions given during that call.

This case illustrates a broader shift described in the source material: generative AI now allows attackers to convincingly impersonate trusted people across text, voice, and video, not just email. That means the old advice to watch for bad grammar or awkward phrasing no longer holds up as a reliable warning sign.

Why it succeeded

The scenario worked because it exploited trust in visual and audio cues rather than exploiting a technical vulnerability. A few conditions made it effective:

  • The request came through a real-time video call, which felt more credible than a text-based message.
  • The urgency and authority of "senior colleagues" pressured the employee to act quickly.
  • The payment appears to have bypassed normal verification or change-control steps, relying instead on the visual confirmation of familiar faces.

What to watch for

Organizations in finance, accounts payable, treasury, payroll, and related roles should treat certain patterns as red flags:

  • Pressure for a large, urgent payment introduced during a live call rather than through standard channels.
  • Approval decisions that rest on recognizing a voice or face rather than following documented verification procedures.
  • Requests that skip or shortcut the normal payment or change-control process.

As the source material notes, seeing a familiar face on a call is no longer enough to approve a sensitive request, since both voice and video can be synthetically generated.

How to build resistance

Defending against this style of attack means shifting verification away from "does this look and sound right" toward structured, out-of-band checks:

  • Verify any unusual, sensitive, or urgent request through a separate trusted channel, not the phone number or contact details supplied during the suspicious call itself.
  • Use contact details the business already trusts, such as a saved vendor number or internal directory entry, rather than anything provided in the request.
  • Require a second approver for high-risk actions like large transfers, new vendor bank details, or privileged access changes, so no single person's judgment can authorize the transaction alone.
  • Reinforce credential protections, including unique passwords and multi-factor authentication, since these attacks often depend on abusing legitimate contexts and access, not just the deepfake media itself.

Training that focuses on process discipline, rather than trying to visually or audibly detect a deepfake, gives finance and approval teams a more durable defense.

Key findings

  • AI makes phishing messages more fluent, targeted, and scalable, reducing reliance on obvious errors as a detection cue.
  • Attackers can impersonate trusted people and contexts using AI across multiple media (text, voice, video).
  • A real incident is referenced where a finance worker was tricked via deepfake video impersonation into transferring about $25 million.
  • Recommended defenses emphasize verification processes (out-of-band verification, multi-person approval) and credential protections (unique passwords, MFA).

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Payroll, Executive assistants, HR, Procurement/Vendor management, IT helpdesk/service desk.
  • Affected industries: Small and medium-sized businesses (cross-industry), Finance/Accounting departments (cross-industry).
  • Attack channels: teams.
  • Impersonated: Senior colleagues (e.g., CFO/executives) using deepfake video.

Red flags to watch for

  • Pressure for a large, urgent payment during a call
  • Approval is based on “seeing” familiar faces rather than normal verification steps
  • Request bypasses normal payment/change-control process
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the deepfake video call scam work?

Fraudsters used AI-generated deepfake video to impersonate senior colleagues during a video meeting, pressuring a finance worker to transfer about $25 million based on instructions given during the call.

Why didn't recognizing familiar faces prevent the fraud?

Deepfake technology can generate a familiar face or voice on a call, so seeing or hearing someone you recognize is no longer reliable proof of their identity for approving sensitive requests.

What defenses help against deepfake-driven payment fraud?

Recommended defenses include out-of-band verification through trusted contact channels, requiring a second approver for high-risk payment actions, and strong credential protections like unique passwords and MFA.

Who is most at risk from this type of attack?

Finance, accounts payable, treasury, and payroll staff are primary targets, since they are the ones authorized to move money or approve vendor and payment changes.

Read the video transcript

Imagine a Teams call where your CFO and leadership team ask you to move $25 million… and every single one of them is fake. In 2024, a finance worker in Hong Kong was tricked into transferring about $25 million after deepfake video copies of their senior colleagues joined a call and said, “We need you to process this transfer now.” Here’s the trap: you see familiar faces on screen, feel the pressure of a huge, urgent payment, and skip the normal approval steps, because it “looked” real. But seeing a familiar face on a call is no longer proof of anything. If a video or voice call asks for money, credentials, or access changes, stop. Don’t trust the call, verify it through a separate, trusted channel before you do anything.

MITRE ATT&CK techniques

Similar attacks

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

Deepfake CFO Scam Turns Phishing Into Video Wire Fraud

The article describes how modern phishing can start with an email impersonation and then move into live deepfake video calls to pressure employees into sending money. It cites a widely reported case at engineering firm Arup where an employee, convinced by a deepfake video call featuring synthetic…

August 19, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Deepfake Video Call Drove $25M Wire Transfer Scam

Deepfake Video Call Drove $25M Wire Transfer Scam

The article discusses Google’s new selfie-video account recovery, but it also highlights a real deepfake-enabled fraud case. In that incident, a finance employee joined a video call showing deepfake versions of coworkers and was persuaded to send multiple wire transfers, illustrating how realistic…

July 23, 2026
Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social media messages, and even AI-generated videos to push victims to spoofed IC3 websites or to hand over more personal and financial information,…

July 21, 2026
Interpol Sting Hits Black Axe Scam Networks

Interpol Sting Hits Black Axe Scam Networks

Interpol said Operation Jackal IV arrested dozens and disrupted West Africa–linked criminal networks tied to scams and money laundering, including Black Axe. The cases described include a call-center “investment” scam, romance/investment scams targeting retirees, and sextortion of teenagers on…

August 25, 2026