A Deepfake Video Call Convinced an Employee to Wire $26 Million to Scammers
What happened
In January 2024, a finance worker at Arup's Hong Kong office joined a video call that appeared to include the company's CFO and several other colleagues. The faces on screen looked right. The voices sounded familiar. Over the course of the call, the worker was instructed to authorize a series of wire transfers. They did. The money, HKD 200 million, roughly USD 26 million, left the accounts without a second check.
Every person on that call except the employee was a fabrication. Scammers had used deepfake technology to reconstruct the likenesses and voices of real Arup staff, drawn from publicly available video and audio, and rendered them convincingly enough that the target had no reason to pause. The worker had reportedly received an initial message that felt suspicious, but the video call appeared to resolve that doubt. That is exactly what it was designed to do.
The fraud was not discovered until May 2024, months after the transfers cleared. Arup confirmed publicly that it had been the target. Hong Kong police had announced the case in February 2024 following an investigation; by that point the company had already absorbed the loss. The total transferred across multiple transactions made this one of the largest deepfake-enabled financial frauds on record at the time.
What the incident turns on is a gap that most corporate communication infrastructure had not anticipated: a video call, long treated as a high-confidence identity signal, can be counterfeited at scale. The employee followed a rational process. They received instructions from who appeared to be the CFO, confirmed by visible colleagues in a live call, and complied. The problem was not human error in the ordinary sense. The problem was that the verification layer everyone implicitly trusted, the visual and audio signal of a face in a call, had quietly become unreliable.
This is a documentation failure as much as a security one. There was no mechanism to log what produced the video stream the employee saw, no identity attestation attached to the call, and no audit trail that would have let anyone verify afterward whether the participants were genuine. A provable record of what a system produced and who it claimed to represent would not have stopped the initial deception, but it would have shortened the gap between transfer and discovery, and given investigators something concrete to trace. As deepfake tools reach mass availability, the question is no longer whether a face in a call can be faked; it is whether the infrastructure around that call can prove it was not.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.