Blog

Deepfake CEO Fraud: How the $25M Arup Attack Worked

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: August 19, 2026

Deepfake CEO on a video call, face distorted by AI artifacts, watched by an employee
TL;DR

Deepfake CEO fraud is a social engineering attack where criminals use AI-generated video or cloned audio of a senior executive to pressure an employee into authorizing a payment or handing over sensitive access. In January 2024, a finance employee at the Hong Kong office of British engineering firm Arup joined what looked like a routine video call with the company's UK-based CFO and several colleagues. Every other person on that call was synthetic. The employee approved 15 transfers to five Hong Kong bank accounts, totaling roughly HK$200 million, or about $25.6 million.

No firewall was breached. No credentials were stolen. No malware ran. The attackers used footage the company had published itself, and the only control standing between them and the money was one person's judgment on a live call.

If you take one thing from this: the fix is not better deepfake detection. It is a payment approval process that does not accept a face or a voice as proof of identity.

What is deepfake CEO fraud?

Deepfake CEO fraud is a payment fraud technique in which attackers impersonate a company executive using AI-generated video, cloned voice, or both, then use that fake identity to authorize a fraudulent transfer. It is a subtype of business email compromise, with one difference that matters enormously: the victim gets what feels like independent confirmation.

Traditional BEC relies on a convincing email. When an employee is suspicious, the standard advice has always been to pick up the phone or hop on a call and confirm with the person directly. Deepfake CEO fraud attacks that exact remedy. The verification step becomes part of the attack.

The label is slightly imprecise, and it is worth naming that. Most documented cases, Arup included, impersonate the CFO or a finance director rather than the CEO, because that is who has payment authority. "Deepfake CEO fraud" has become the catch-all term for executive impersonation with synthetic media, so that is how most people search for it, but when you assess your own risk, look at whoever can approve money moving, not just whoever is on the org chart at the top.

Key Takeaways

  • checkmark

    A plain definition of deepfake CEO fraud and how it differs from ordinary business email compromise

  • checkmark

    A step-by-step reconstruction of the Arup attack, from reconnaissance to the moment the fraud surfaced

  • checkmark

    The three specific control failures that let $25.6 million leave the building

  • checkmark

    Why human deepfake detection does not work, backed by current research

  • checkmark

    Other executive impersonation cases, including two that failed and why they failed

  • checkmark

    A defense checklist you can apply to your payment workflow this quarter

  • checkmark

    Answers to the questions finance and security teams ask most about this attack

In This Article

The Arup attack: what actually happened

Arup is a London-headquartered design and engineering firm with roughly 18,500 employees. Its portfolio includes the Sydney Opera House and Beijing's Bird's Nest stadium. It is not a company with weak security. That is what makes the case useful.

The timeline

January 2024. An employee in Arup's Hong Kong finance function receives an email appearing to come from the firm's UK-based chief financial officer. The message describes a confidential transaction and asks the employee to help execute it discreetly.

The employee is suspicious. Something about a secret transaction request from head office does not sit right, which is exactly the reaction every awareness training program aims to produce. By the standard of most security programs, the training worked.

The video call. The employee is invited to a video conference to discuss the transaction. The CFO is there. So are several colleagues the employee recognizes by face and voice. They discuss the transaction. They apply pressure and confidentiality. The employee's doubt dissolves.

Every participant except the employee was AI-generated.

The transfers. Over the course of the operation, the employee authorizes 15 separate transfers to five different Hong Kong bank accounts, totaling around HK$200 million.

The discovery. The fraud is not caught by a bank, a control, or a detection tool. It surfaces when the employee later follows up with Arup's head office about the confidential transaction and finds that nobody there knows what he is talking about. There was no transaction, no meeting, and no CFO request.

February 2024. Hong Kong police disclose the case publicly without naming the victim, warning businesses about AI deepfake scams using video conferencing.

May 2024. CNN reports that Arup is the victim. Arup confirms fake voices and images were used, and states that its financial stability and operations were unaffected, and none of its internal systems were compromised. Chief information officer Rob Greig later described the incident as technology-enhanced social engineering rather than a technical breach.

The funds were never recovered. As of the most recent public reporting, no arrests have been announced.

How the attackers built the fake

The reconnaissance phase is the part most companies underestimate, because it does not touch anything you can monitor.

Hong Kong police determined that the attackers built the deepfake participants from publicly available video and audio of Arup executives, harvested from online conferences, recorded webinars, press appearances, and company video content. None of that required access to Arup systems. It requires a search engine and patience.

This is the uncomfortable tradeoff at the center of the problem. Your executives are visible on purpose. Keynotes, earnings calls, podcast interviews, and LinkedIn videos are all marketing assets, and they are all training data. The more effective your executive communications program, the cheaper it is to clone your executives. Nobody is suggesting you take the CEO off camera. But the security cost of that footprint is real, and it belongs on the risk register.

The three control failures

The money did not move because one person was gullible. It moved because three things in the process were designed for a world where faces are hard to fake.

Verification happened on the attacker's channel

The employee's doubt was resolved on a call the attacker arranged, using contact details the attacker supplied. Verification only works when the second channel is one you already trust and the target initiates. Calling back a number from the suspicious message is not verification. Neither is joining a meeting link from that message.

One person could authorize the full amount

Fifteen transfers, one approver. Segregation of duties on high-value payments exists precisely so that a single compromised human, whether tricked, coerced, or dishonest, cannot complete the loop alone. Deepfakes do not defeat dual authorization. They defeat single authorization very effectively.

Confidentiality was accepted as a legitimate instruction

"Do not discuss this with anyone" is the load-bearing element of nearly every executive impersonation attack. It isolates the target from the people who would ask an obvious question. Any process that allows secrecy to override normal approval routing has a built-in bypass, and attackers know it.

Why "just train people to spot deepfakes" fails

There is a persistent belief that employees can be taught to notice the tells: the lip sync drift, the glassy eyes, the odd lighting at the hairline, the too-clean audio.

Some of those artifacts are real, and in 2024 many deepfakes had them. The problem is that the research on human detection is bleak and getting worse. iProov's testing found that a vanishingly small share of people correctly identified every deepfake they were shown. Other studies put average human accuracy on high quality synthetic video around a coin flip. Generation quality improves with each model release, while human perception does not improve at all.

Detection tools are better, but not enough to build a control on. Vendors report 90 to 96 percent accuracy in lab conditions, and independent testing consistently finds real-world performance drops sharply, sometimes by half, against fresh generation methods the model has not seen.

Treat detection as a useful signal, not a gate. A control that fails silently 30 to 50 percent of the time is not a control. Process is the gate.

This is not a one-off

Arup is the largest confirmed loss, not an outlier event.

Gartner's September 2025 survey of 302 security leaders found that 62 percent of organizations had experienced a deepfake attack in the prior 12 months, and 37 percent of those leaders had personally encountered a deepfake during a video call.

The FBI's 2025 Internet Crime Report recorded $20.9 billion in total reported losses, with business email compromise accounting for $3.046 billion across 24,768 complaints. That year the FBI added an AI-related descriptor for the first time, logging more than 22,000 complaints and roughly $893 million in losses, while noting that the true figure is almost certainly higher because most victims never realize AI was involved.

Deloitte's Center for Financial Services projects US generative AI-enabled fraud losses reaching $40 billion by 2027, up from $12.3 billion in 2023.

Two near-misses are more instructive than the losses:

In July 2024, someone impersonated Ferrari CEO Benedetto Vigna on a WhatsApp call, using a convincing voice clone and a story about a confidential acquisition. The executive on the receiving end asked a question only the real Vigna could answer, referencing a book Vigna had recommended to him days earlier. The caller hung up.

Also in 2024, an attempt against advertising group WPP used a fake video meeting impersonating a senior leader. It failed against internal scrutiny before any money moved.

Neither was stopped by technology. Both were stopped by a person asking something a model could not know, or by a process that refused to bend.

How to defend against deepfake CEO fraud

Order matters here. The first four items cost almost nothing and stop the overwhelming majority of these attacks.

  1. Require callback verification on a pre-established channel for any payment above a set threshold. The number must come from your directory or HR system, never from the request itself. Make this non-negotiable regardless of who is asking or how urgent it sounds.

  2. Enforce dual authorization on high-value and new-beneficiary payments. Two approvers on separate channels. An attacker who has to deepfake two independent people, each verifying through a system they initiated, is facing a completely different problem.

  3. Establish verbal challenge phrases for executive-level financial requests. A rotating code word, or a personal question with an answer that is not discoverable online. Ferrari's near-miss is the whole argument for this control.

  4. Write a policy that says confidentiality never suspends approval routing. Then have the CEO and CFO say it out loud, in a company meeting, in their own words. The reason this works is that it removes the target's fear of looking foolish for asking. That fear is what the attacker is actually exploiting.

  5. Run deepfake-specific simulations, not generic phishing tests. An employee who has once sat through a synthetic call in a training environment responds very differently to a real one. Reading a slide about deepfakes does not create that.

  6. Set a payment velocity rule. Multiple transfers to new beneficiaries within a short window should trigger review automatically, independent of who approved them. Arup's 15 transfers in a single day would have tripped this.

  7. Reduce and inventory the executive media footprint. You will not eliminate it. You can know what exists, and you can stop publishing high-quality isolated audio of your CFO where you do not need to.

  8. Rehearse the first hour. If a fraudulent transfer is discovered quickly, recovery is possible. The FBI's Recovery Asset Team froze $679 million across roughly 3,900 incidents in 2025, at a 58 percent success rate, but that depends almost entirely on speed. Know who calls the bank, who calls law enforcement, and who has authority to do it at 11pm.

What to do if you think you have been hit

Speed is the only variable you control after the fact.

Call the originating bank immediately and request a recall, then file with the FBI's IC3 the same day if any part of the transaction touches the US, so the Recovery Asset Team can attempt a freeze. Notify law enforcement in the jurisdiction where the funds landed. Preserve the meeting invite, the email headers, the platform logs, and any recording. Then, and this matters more than it sounds, tell the employee involved that they are not in trouble. Fast reporting is the single highest-value behavior in these incidents, and blame is what delays it. Arup's fraud was found because the employee kept talking about the transaction.

The bottom line

The Arup case is not really a story about AI. It is a story about a payment process that treated a familiar face as proof of identity, which was a reasonable assumption for most of corporate history and stopped being one somewhere around 2023.

Every organization currently has some workflow, in finance, in HR, in IT support, that resolves doubt by saying "I spoke to them." Find those workflows. Change what counts as proof. The technology to fake a face is only going to get cheaper, and there is no version of the future where employees get better at catching it.

See it before you approve it

Process controls stop the attack. The problem is that they only fire when someone already suspects something, and the Arup employee stopped suspecting the moment he saw a familiar face.

That is the gap Netarx is built to close. Instead of asking employees to spot a deepfake, Netarx puts a real-time signal on screen during the call, in the email, on the text, telling the person whether the voice, video, or message in front of them is authentic. It works across voice, video, email, SMS, and file uploads, and it pairs media detection with device and identity validation, so the question is not only "is this video real" but "is this actually the person behind it."

Detection alone is not a control. Detection plus a callback rule plus dual authorization is a control that holds. Netarx covers the layer your policy cannot reach: the 40 seconds on a live call when someone has to decide whether the CFO is really the CFO.

See how Netarx detects deepfakes in real time or read why security teams choose Netarx.

SOURCES & REFERENCES

  1. Hong Kong Free Press — "Multinational loses HK$200 million to deepfake video conference scam, Hong Kong police say", 5 February 2024.

  2. CNN — "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'", 4 February 2024. First reporting of the incident, victim unnamed.

  3. South China Morning Post — "'Everyone looked real': multinational firm's Hong Kong office loses HK$200 million after scammers stage deepfake video meeting", 4 February 2024. Senior Superintendent Baron Chan Shun-ching's account of the video call and how the deepfakes were built from publicly available footage.

  4. CNN Business — "Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee", 16 May 2024. Arup confirmed as the victim; company statement that fake voices and images were used and no internal systems were compromised.

  5. World Economic Forum — "'This happens more frequently than people realize': Arup chief on the lessons learned from a $25m deepfake crime", 4 February 2025. Rob Greig, Arup CIO, in his own words: "What happened at Arup — I would call it technology-enhanced social engineering. It wasn't even a cyberattack in the purest sense. None of our systems were compromised and there was no data affected."

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

About $25.6 million, or roughly HK$200 million, moved across 15 transfers to five Hong Kong bank accounts. The funds were not recovered.