Submit incident
Documented

A Deepfake Video Call Convinced an Employee to Wire $26 Million to Scammers

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1321View source ↗
LinkedInX

What happened

In January 2024, a finance worker at Arup's Hong Kong office joined a video call that appeared to include the company's CFO and several other colleagues. The faces on screen looked right. The voices sounded familiar. Over the course of the call, the worker was instructed to authorize a series of wire transfers. They did. The money, HKD 200 million, roughly USD 26 million, left the accounts without a second check.

Every person on that call except the employee was a fabrication. Scammers had used deepfake technology to reconstruct the likenesses and voices of real Arup staff, drawn from publicly available video and audio, and rendered them convincingly enough that the target had no reason to pause. The worker had reportedly received an initial message that felt suspicious, but the video call appeared to resolve that doubt. That is exactly what it was designed to do.

The fraud was not discovered until May 2024, months after the transfers cleared. Arup confirmed publicly that it had been the target. Hong Kong police had announced the case in February 2024 following an investigation; by that point the company had already absorbed the loss. The total transferred across multiple transactions made this one of the largest deepfake-enabled financial frauds on record at the time.

What the incident turns on is a gap that most corporate communication infrastructure had not anticipated: a video call, long treated as a high-confidence identity signal, can be counterfeited at scale. The employee followed a rational process. They received instructions from who appeared to be the CFO, confirmed by visible colleagues in a live call, and complied. The problem was not human error in the ordinary sense. The problem was that the verification layer everyone implicitly trusted, the visual and audio signal of a face in a call, had quietly become unreliable.

This is a documentation failure as much as a security one. There was no mechanism to log what produced the video stream the employee saw, no identity attestation attached to the call, and no audit trail that would have let anyone verify afterward whether the participants were genuine. A provable record of what a system produced and who it claimed to represent would not have stopped the initial deception, but it would have shortened the gap between transfer and discovery, and given investigators something concrete to trace. As deepfake tools reach mass availability, the question is no longer whether a face in a call can be faked; it is whether the infrastructure around that call can prove it was not.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
A Deepfake Video Call Convinced an Employee to Wire $26 Million to Scammers
2024