25 Million Dollar AI Deepfake Fraud
A Hong Kong employee was suspicious of an unusual money request. Then familiar executives appeared on screen.
A Hong Kong employee was suspicious of an unusual money request. Then familiar executives appeared on screen.
By the time the call was over, criminals had persuaded the company to send away about **US$25.6 million**.
In late January 2024, an employee in the Hong Kong office of engineering giant Arup received what appeared to be a message from the company’s chief financial officer in the UK. It involved confidential transactions and a huge amount of money — exactly the kind of request a finance worker should be suspicious of.
And the employee was suspicious.
That was the problem. The scammers were ready for it.
##The Video Call Was the Weapon
The employee was invited to a video conference. Familiar senior executives appeared on the screen. Their faces looked right. Their voices sounded right. The CFO seemed to be sitting there with other coworkers, discussing the transaction like a normal group of executives handling something sensitive.
The meeting made the strange request suddenly feel real.
But none of those executives were actually there.
Hong Kong authorities later said the video conference had been created using publicly available video clips and recordings of the people being impersonated. The meeting was prerecorded rather than genuinely interactive.
By the end of the scam, the employee had authorized transfers to five local bank accounts totaling roughly **HK$200 million — about US$25.6 million**.
The employee had tried to verify the suspicious request by seeing the people involved. The criminals had prepared specifically for that verification.
For years, anti-fraud advice has been simple: if an email looks suspicious, don’t trust it. Call the person. Get them on video. Make sure the request really came from them.
The Arup scam turned that advice upside down.
## They Didn’t Hack the Computer. They Hacked Trust.
Arup later confirmed that fake voices and images had been used. The company said its internal computer systems had not been compromised and that the incident did not threaten its financial stability or normal operations.
That makes the scam even more interesting.
The criminals apparently did not need to break deeply into the company’s network or seize control of its banking software. Instead, they attacked something much older: the trust between people who already knew each other.
A scammer used to have to send an email that vaguely sounded like your boss. Now, if enough public video and audio exists, they can potentially create something that looks and sounds like your boss too.
And the fake does not have to survive a two-hour interrogation.
Police said the Arup conference was prerecorded, with no genuine back-and-forth between the employee and the fake executives. After the video portion ended, payment instructions continued through instant messaging.
The illusion only had to survive long enough to make the next instruction believable.
## A Familiar Face Became Evidence
Humans are extremely good at recognizing familiar people. You hear a family member on the phone and know who it is before they even introduce themselves. You recognize your manager walking across a room without asking for ID.
Normally, those shortcuts work incredibly well.
Deepfakes attack those shortcuts directly.
The employee was not looking at an obvious cartoon face or listening to a terrible robotic voice. The fake meeting supplied several pieces of social evidence at once. The CFO appeared to be there. Other coworkers appeared to be there. The conversation involved confidential business, which helped explain why the situation seemed unusual.
None of those signals had to be perfect by themselves. Together, they only had to be convincing enough.
That is what separates this from the old fake-CEO-email scam. Criminals have impersonated executives for years. AI does not invent the fraud.
It makes one of our best verification tools less reliable.
Hong Kong authorities said they recorded three deepfake-related fraud cases between 2023 and May 2024. In another case, an employee at a multinational trading company reportedly spent almost 30 minutes in a video conference with a fake CFO before being instructed to transfer nearly HK$4 million.
The technology did not need to become perfect before it became useful to criminals.
## Then Ferrari Got the Call
A few months later, an executive at Ferrari received WhatsApp messages that appeared to come from CEO Benedetto Vigna.
The story sounded familiar: there was an urgent and highly confidential acquisition, secrecy was essential, and the unusual phone number was supposedly necessary because the deal was too sensitive to discuss through normal channels.
Then the fake Vigna called.
The voice reportedly sounded remarkably similar to the real Ferrari CEO, even reproducing his southern Italian accent. But the executive noticed slight mechanical qualities in the voice and decided to test him.
He asked what book Vigna had recommended to him a few days earlier.
The caller could not answer.
The call ended.
The deepfake had the voice and the identity. What it did not have was a private memory shared between two real people.
## We Are Running Out of Easy Ways to Prove Someone Is Real
The Ferrari trick worked, but it is not a permanent solution. Personal information can leak. Conversations can be exposed. Future AI systems may have access to much larger collections of personal and corporate information.
The larger lesson is that identity can no longer depend on one familiar signal.
A face on Zoom is not necessarily proof. A familiar voice on the phone is not necessarily proof. A message carrying the boss’s name is not necessarily proof. Even several of those things together may not be enough if they are all arriving through channels an attacker can imitate.
Hong Kong police have recommended verifying unusual financial requests through independent, already-known channels rather than trusting video or audio alone. Call the person using a number you already have. Follow established approval procedures. Make sure the request is confirmed somewhere outside the suspicious conversation.
Deepfake fraud does not require creating a flawless synthetic human.
It only requires creating one convincing enough to get you through the next decision.
The Arup employee noticed that something felt wrong. They became suspicious. They looked for more evidence and tried to see the real people behind the request.
Its been a long time now that we can’t believe anything we see or hear.