Every fraud prevention program in existence tells finance staff the same thing: if a payment request seems unusual, verify it through another channel. Pick up the phone. Get on a video call. Confirm with a human being you recognize. That advice was sound for decades. In January 2024 it became the exact mechanism through which a multinational engineering firm lost roughly US$25 million, and the accounting profession has not fully absorbed what that means.

Key Takeaway

In January 2024, a finance employee in the Hong Kong office of Arup, a global engineering and design firm, executed 15 wire transfers totalling approximately US$25.6 million (HK$200 million) after joining a video conference in which the CFO and several recognizable colleagues were all AI-generated deepfakes. Hong Kong police reported the incident in February 2024; Arup publicly confirmed it in May 2024. The critical detail is that the employee initially suspected the originating phishing email and requested verification, and the deepfake video call was what overcame that correct suspicion. Arup's CIO confirmed no systems were compromised and no data was breached: this was social engineering enhanced by technology, not a cyberattack in the conventional sense. The defensive implication is specific and uncomfortable: any control that relies on a human recognizing a face or a voice is now structurally unreliable, and payment controls must move to mechanisms that do not depend on perceptual verification at all.

What Actually Happened At Arup

The sequence is worth reconstructing precisely, because the specific ordering is where the lesson lives. The attack began conventionally: a finance employee in Arup's Hong Kong office received an email purporting to come from the firm's UK-based Chief Financial Officer, describing the need for a confidential transaction and requesting the employee's assistance[1]. Attackers had performed reconnaissance beforehand, collecting information about Arup's organizational structure, the identity of key financial decision-makers, and the general communication style of executive leadership, then crafted an email with a spoofed sender address, executive-consistent language, and an appropriately time-sensitive tone[2].

The employee suspected a phishing scam. This is the part most summaries omit, and it is the most important fact in the entire case. He then joined a video call, on which he saw and heard individuals who looked and sounded like the CFO and several colleagues he recognized[3]. Reassured, he proceeded, ultimately executing 15 separate transfers to five different Hong Kong bank accounts[1]. He did not realize he had been deceived until he subsequently discussed the matter with Arup's head office. Hong Kong police investigation determined that the perpetrators had generated the deepfakes using existing video and audio of the real individuals harvested from publicly available sources, online conferences and virtual company meetings[4].

The Detail Everyone Skips

Popular retellings of this case tend to frame it as an employee being fooled, which quietly implies that a more vigilant employee would have caught it. The actual record does not support that framing, and getting this right matters enormously for how a business designs its own controls. The employee was vigilant. He correctly identified the initial email as suspicious, exactly as fraud awareness training instructs. He then escalated to a richer verification channel, exactly as fraud awareness training instructs. The failure occurred not because he skipped a control, but because the control he correctly applied has been rendered ineffective by the technology.

This distinction determines whether a business draws the right lesson. If the lesson is "train staff to be more careful," the business has learned nothing useful, because carefulness is precisely what failed here. If the lesson is "verification controls that depend on human perception are now structurally obsolete for high-value payments," the business can actually redesign around it. Arup's own CIO, Rob Greig, characterized the incident in terms consistent with this reading: no company systems were compromised and no data was affected, making this technology-enhanced social engineering rather than a traditional cyberattack[3].

The Attack Economics

The reason this category of fraud is expanding rather than remaining a curiosity comes down to a cost asymmetry that current security analysis states directly. Traditional security operates on an economic principle: make attacks expensive enough that they are not worth executing relative to the expected payoff. Deepfake fraud breaks that principle, because the cost of generating a convincing synthetic video and audio impersonation has collapsed while the potential payoff has not[5]. One security analysis of the Arup case estimates the attack itself likely cost under US$10,000 to execute against a US$25 million payoff, and observes that even at a 1-in-100 success rate the economics remain overwhelmingly favourable to the attacker[5].

The input requirement is similarly minimal. Current reporting indicates roughly three seconds of audio material is sufficient to produce a voice clone with approximately 85% accuracy[6]. For any executive who has ever appeared on a recorded webinar, a conference panel, a podcast, an earnings call, or a corporate video, the raw material for cloning their voice is already public and cannot be retrieved. This is not a risk a business can mitigate by restricting future recordings; the exposure for most senior executives already exists.

Can Humans Detect This? The Data Says No

The natural defensive instinct, training staff to spot deepfakes, deserves direct examination against the available evidence rather than optimistic assumption. Studies cited in current security reporting indicate humans correctly identify high-quality deepfake videos in only approximately 24.5% of cases, and roughly 70% of survey respondents report they cannot reliably distinguish a real voice from a cloned one[6]. A detection rate of roughly one in four against a determined attacker is not a control; it is a coin flip weighted against the defender.

The practical conclusion current security analysis draws from this is unambiguous and worth stating plainly: human detection is not a reliable protective mechanism, and technical controls and process safeguards must therefore carry the main defensive burden[6]. Deepfake awareness training retains genuine value, an employee who knows this attack category exists is more likely to insist on a secondary control, but it should be understood as raising the probability that a proper control gets invoked, not as itself constituting the control.

This Is BEC, Not Hacking

Correctly classifying this attack determines which part of a business's defences should be responsible for stopping it. Deepfake executive impersonation is, structurally, business email compromise (BEC) with an added credibility layer, not a novel technical intrusion[7]. BEC has worked for years on the same underlying pattern: an attacker poses as a senior figure and directs an urgent payment. What deepfakes add is a defeat mechanism for the specific verification step that organizations had adopted precisely to counter BEC[7].

This classification matters practically because it locates the defence in the right place. No firewall, endpoint protection product, or network security control would have prevented the Arup loss, because no system was breached. The control that failed was a finance process control, and the control that must replace it is also a finance process control. Businesses that respond to deepfake fraud by escalating IT security spending, while leaving payment authorization processes unchanged, have addressed the wrong layer entirely.

The Scale Question, Handled Carefully

Figures circulate widely on the growth of deepfake fraud, and they deserve careful handling rather than uncritical repetition, because a meaningful share originate from vendors selling detection products. Reported figures include US deepfake-based fraud losses reaching approximately US$1.1 billion in 2025, roughly triple the prior year's US$360 million, and a Deloitte projection that generative-AI-enabled fraud could reach US$40 billion by 2027[6]. One independent analysis reviewing this literature offers a caution worth repeating: many percentage-growth figures for deepfake incidence come from vendor reports with their own methodologies and should be treated with appropriate skepticism[7].

What is not in dispute, and what a business should actually plan against, is narrower and better evidenced: the Arup case is documented and confirmed by the victim organization and Hong Kong police; the FBI issued a public IC3 warning in May 2025 regarding campaigns impersonating senior officials using AI-generated voice messages[7]; and similar voice-cloning attempts have been reported against other organizations including LastPass[3]. The direction and existence of the threat are well established even where specific growth multiples should be discounted.

Why Finance Functions Specifically

Finance and accounting functions are the primary target of this attack class for reasons that are structural rather than incidental. They possess payment authority, which is the actual objective. They routinely handle confidential transactions where secrecy is a plausible and expected feature rather than a red flag, which is precisely the cover the Arup attackers used. They operate under genuine time pressure around settlement deadlines. And they frequently interact with senior executives across geographies through exactly the video-conferencing channels that deepfakes now compromise, often without the in-person familiarity that might otherwise create a baseline for detecting something subtly wrong.

There is also a hierarchical dynamic worth naming. A junior or mid-level finance employee receiving an urgent, confidential instruction from someone who appears to be the CFO faces a real professional cost to refusing or delaying, and a much less visible cost to complying. Any control framework that ultimately depends on a subordinate having the confidence to say no to an apparent executive instruction is relying on individual courage as a security mechanism, which is an unreliable foundation regardless of the deepfake question.

The Controls That Actually Work

Current security guidance converges on a specific set of measures, and their common property is instructive: none of them require anyone to correctly perceive whether a person is real[6].

Two-channel verification above a defined threshold. Any transfer above a set amount requires confirmation through a second, independent channel not initiated by the requester, meaning the verifier controls the channel rather than accepting whatever channel the requester proposes.

Callback using internally registered numbers only. The callback must go to a number retrieved from the company's own directory, never a number supplied in the request itself. This single control would have defeated the Arup attack, because the attackers controlled the video channel but not Arup's internal directory.

Pre-agreed code words for sensitive transactions. A shared secret established in advance, through a secure channel, that an impersonator cannot know regardless of how convincingly they render a face or voice. This is genuinely low-tech and genuinely effective precisely because it does not depend on perception at all.

Mandatory time delays on unusual transactions. Urgency is the attacker's primary tool; a structural delay on transactions outside normal patterns removes it. This is the same pre-commitment logic this publication has recommended for capital decisions and stress-driven spending, applied to fraud defence.

Dual authorization that cannot be satisfied by one deceived person. Requiring two independent authorizers for payments above a threshold means an attacker must successfully deceive two people through two separate verification processes, which multiplies attack cost substantially.

The Insurance Question Nobody Asks Until After

A question worth resolving before an incident rather than during one: would a loss of this kind actually be covered? The answer is frequently less favourable than businesses assume, and the reason traces directly to the classification discussed above. Because a deepfake-enabled payment fraud typically involves no system compromise, the loss often falls outside the scope of a conventional cyber policy's coverage for network intrusion, data breach, or ransomware, and instead lands in the territory of social engineering fraud or funds transfer fraud, which many policies treat as a separate, sub-limited endorsement rather than core coverage, if they cover it at all.

The practical consequence is that a business can hold what it believes to be comprehensive cyber insurance and discover, after a seven-figure loss, that the applicable sub-limit is a small fraction of the loss, or that coverage is conditioned on having followed specific verification procedures the business did not actually have documented. That last condition is worth particular attention: some social engineering endorsements require the insured to have performed a documented out-of-band verification, meaning the same callback control described below functions simultaneously as a fraud defence and as a coverage precondition. Reviewing this with a broker before an incident, specifically asking how the policy would respond to an authorized-but-deceived transfer with no system compromise, is a short conversation that materially changes the downside.

A Worked Case: The Callback That Wasn't

A Canadian mid-market manufacturer received an apparent instruction from its CEO, travelling internationally, to expedite a payment to a new supplier for a time-sensitive component order. The controller, following company policy, requested verification. The requester proposed a video call, which proceeded, and on which the CEO appeared and confirmed the instruction, along with a person introduced as the supplier's account manager.

The controller nonetheless applied the company's written policy, which specified callback to a number retrieved from the internal directory rather than any number or channel offered by the requester. The call to the CEO's registered mobile reached the actual CEO, who had made no such request and was not on any video call. The attempt failed at that step, not because the controller detected anything wrong with the video, she later confirmed she had found it entirely convincing, but because the policy did not permit the video call to substitute for the directory callback regardless of how convincing it was.

The transferable point is that the control worked precisely because it was mechanical and non-discretionary. A policy stating "verify through an appropriate channel" would have permitted the video call to satisfy it. A policy specifying "callback to the number in the internal directory, and no other channel substitutes" did not.

The Small Business Version Of This Attack

Canadian small and mid-sized businesses sometimes read cases like Arup's, a multinational firm, a US$25 million loss, and conclude the threat is scaled to organizations far larger than themselves. The attack economics discussed above argue the opposite. Because the marginal cost of generating a deepfake is low and falling, attackers do not need a US$25 million payoff to justify the effort; a $40,000 transfer from a small business is comfortably profitable against a sub-$10,000 attack cost, and small businesses typically have weaker payment controls, less segregation of duties, and no dedicated fraud function.

The raw material is also readily available at small-business scale. An owner who has appeared on a local business podcast, posted a video to the company's social media, or spoken at an industry event has provided sufficient audio for cloning. The relevant question for a smaller business is not whether it is a large enough target, but whether its payment authorization process would survive a convincing impersonation of its owner, and for most businesses operating on informal trust between a small team, the honest answer is that it would not.

What Not To Rely On

Several intuitive defences deserve explicit warnings. Asking the person to turn their head or perform an unusual movement was briefly effective against early deepfake systems and should not be relied upon now; detection capabilities improve on both sides and treating a liveness trick as a control invites false confidence. Recognizing subtle audio or visual artifacts founders on the 24.5% detection rate discussed above. Trusting a call because it came through the company's own conferencing platform confuses the transport channel with participant identity; a legitimate meeting link says nothing about whether the face inside it is genuine. Assuming an attacker would not know internal details underestimates the reconnaissance phase, which in the Arup case included organizational structure, decision-maker identities, and executive communication style[2].

The Case At A Glance

For quick reference: the Arup loss totalled approximately US$25.6 million (HK$200 million) across 15 transfers to five Hong Kong bank accounts, executed in a single day. Discovery was January 2024; Hong Kong police reported it in February 2024; Arup publicly confirmed in May 2024. Estimated attacker cost: under US$10,000. Human deepfake video detection accuracy: approximately 24.5%. Audio required to clone a voice at ~85% accuracy: approximately three seconds. No arrests had been announced and the funds remained unrecovered as of the most recent reporting reviewed for this article.

The Limits Of This Analysis

Several caveats apply. Reporting on the Arup incident varies slightly across sources on precise dates and amounts; this article uses the most consistently corroborated account, discovery in January 2024, Hong Kong police reporting in February 2024, public confirmation by Arup in May 2024, and approximately US$25.6 million across 15 transfers, and readers should note at least one source reviewed gave a materially different date, which appears to be an error rather than a competing account. As noted above, aggregate market-size and growth figures for deepfake fraud frequently originate from vendors with a commercial interest in the numbers and should be weighted accordingly; this article cites them explicitly as reported figures rather than established fact. Finally, detection technology and attack capability are both advancing, and specific technical detection recommendations dated to 2026 should be revisited periodically rather than treated as durable, which is precisely why this article emphasizes process controls that do not depend on detection at all.

Frequently Asked Questions

What exactly happened in the Arup deepfake case?
In January 2024, a finance employee in Arup's Hong Kong office executed 15 wire transfers totalling approximately US$25.6 million after joining a video call on which the CFO and several colleagues were all AI-generated deepfakes. The employee had correctly suspected the initial phishing email; the video call is what overcame that suspicion. Hong Kong police reported it in February 2024 and Arup publicly confirmed it in May 2024.
Can employees be trained to spot deepfakes?
Not reliably. Studies cited in current security reporting indicate humans correctly identify high-quality deepfake videos only about 24.5% of the time, and roughly 70% of respondents cannot reliably distinguish a cloned voice from a real one. Awareness training helps ensure a proper control gets invoked, but should not itself be treated as the control.
What single control would have prevented the Arup loss?
A mandatory callback to a number retrieved from the company's own internal directory, with no other channel permitted to substitute. The attackers controlled the video channel but had no ability to intercept a call placed to the real CFO's registered internal number.
Is my small business too small to be targeted?
Unlikely to be too small. Security analysis of the Arup case estimates the attack cost under US$10,000 to execute, meaning a far smaller payoff still justifies an attacker's effort. Smaller businesses typically also have weaker payment segregation and fewer authorization layers, which can make them easier rather than harder targets.
Was this a cyberattack? Should our IT team handle it?
Arup's CIO confirmed no systems were compromised and no data was breached. This is business email compromise enhanced by synthetic media, a finance process failure rather than a technical intrusion. The effective controls are payment authorization controls, not network security controls, though both matter.
How much audio does someone need to clone an executive's voice?
Current reporting indicates roughly three seconds of audio is sufficient to produce a clone with approximately 85% accuracy. For any executive who has appeared on a recorded webinar, podcast, panel, or corporate video, that material is already public and cannot be withdrawn.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article draws on incident reporting, police findings, and current fraud research, and is explicit about which figures are well-corroborated and which originate from vendor sources; see References below.

References

  1. PurpleSec. (2026, January 25). Arup Deepfake: How An AI-Generated Video Stole $25 Million. purplesec.us/breach-report/arup-deepfake
  2. PurpleSec. (2026). Arup Deepfake Breach Report, describing the attacker reconnaissance and spear-phishing phase. purplesec.us/breach-report/arup-deepfake
  3. Adaptive Security. (2024, May 16). Arup Deepfake Scam: How $25M Was Stolen via Video Call. adaptivesecurity.com/blog/arup-deepfake-scam-attack
  4. CoverLink Insurance. (2025, August 11). Cyber Case Study: $25 Million Deepfake Scam, citing Hong Kong police investigation findings. coverlink.com/case-study/case-study-25-million-deepfake-scam
  5. Gupta, D. (2026, March 26). The $25 Million Deepfake: Why Your Video Calls Can No Longer Be Trusted. guptadeepak.com/the-25-million-deepfake
  6. SecurityToday. (2026, April 4). Deepfake Voices Stealing Millions from Executive Suites. securitytoday.de/en/2026/04/04/deepfake-attacks-c-suite-ai-voices-ceo-fraud
  7. Hard2bit. (2026). Deepfake CEO Fraud: Voice Cloning Is The New BEC, including its own caution regarding vendor-sourced growth statistics and the FBI IC3 May 2025 public warning. hard2bit.com/en/blog/deepfake-ceo-fraud-voice-cloning-bec-defence

This article discusses publicly reported fraud incidents and general security guidance and is provided for informational purposes. It is not security, legal, or insurance advice. Payment control design should be developed with qualified professionals and confirmed against your own insurer's requirements, since cyber and crime policy coverage for social engineering losses varies significantly.