For most of business history, hearing your boss on a video call settled the matter. That assumption is now expiring. Criminals can generate a convincing live likeness of a chief executive from public conference footage, and have already used it to move real money out of real companies. The costliest case so far took twenty-five million dollars from one firm, and knowing how these frauds unfolded is the difference between spotting one and authorizing the wire.
These attacks rarely begin with the deepfake itself. They open with an ordinary email from a senior figure mentioning a confidential deal, lowering suspicion before the spectacle arrives. The video call comes next, and its only job is to overrule the doubt the email created: a familiar face and voice answering in real time converts a cautious employee into a compliant one. Every documented success has followed this rhythm, the message planting the request and the synthetic meeting silencing the instinct to question it.
How Arup Lost Twenty-Five Million
The benchmark incident struck the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House. In January 2024, a finance employee received an email about a secret transaction and sensibly suspected phishing. His caution collapsed during the video call that followed, where the chief financial officer and several colleagues were all present, all familiar, and entirely synthetic. He made fifteen transfers totaling around twenty-five million dollars before a check with headquarters revealed the truth.
|
Detail |
What Happened |
|
Target |
Finance worker, Hong Kong office |
|
The hook |
Video call of fully AI-generated executives |
|
Transfers |
15 payments to 5 bank accounts |
|
Loss |
Roughly 25 million US dollars |
|
Discovery |
A routine follow-up with the head office |
What makes the case so instructive is the absence of any technical breach. No system was hacked and no password stolen; the attackers simply weaponized trust in familiar faces. The only safeguard that failed was a verification habit that did not yet exist, a gap of procedure rather than technology that any company can close cheaply once it knows to look.
Two Attacks That Failed
The near-misses are as revealing as the loss, because they show exactly where these scams break. At Ferrari, an executive receiving WhatsApp messages and a call that mimicked CEO Benedetto Vigna’s southern Italian accent asked the caller a question only the real CEO could answer, the title of a book he had recently recommended; the impostor vanished. At WPP, the world’s largest advertising group, fraudsters staged a Teams meeting with a voice clone of chief executive Mark Read, but staff recognized the attempt and nothing was paid.
In each case, a single human verification step that the technology could not fake ended the fraud instantly. The deepfake can copy a face, a voice, even a regional accent, but it cannot reach into the shared history between two real colleagues. That unscriptable common ground is where the defense lives, and it costs nothing to use.
Why Verification Is the Whole Game
The lesson connecting every case is that synthetic media defeats sight and sound, so trust has to rest on something else, a principle that reaches beyond the boardroom into ordinary online life across Poland and everywhere else. Regulated operators already lean on it: a licensed casino such as NV Casino verifies identity through documents during account checks rather than trusting a face on a screen. Banks confirm large transfers through a second channel for the same reason. The logic scales down to one employee facing an urgent request, where a code word, a callback to a known number, or a question rooted in shared experience does what a video call no longer can.
Building this into a habit matters more than spotting any individual fake, since the fakes already pass visual and vocal inspection. The rules below ignore the deepfake entirely and verify through a separate channel, turning the principle into a routine anyone can follow under pressure.
- Treat any urgent, secret payment request as suspicious by default, regardless of who appears to be asking.
- Confirm unusual transfers through a second channel, calling back on a number you already trust.
- Agree on a verification word with key colleagues before a crisis, not during one.
- Slow down deliberately, since urgency is the pressure that every one of these scams depends on.
None of these steps requires anyone to detect the fake, which is the point, because the fakes already pass scrutiny and improve with every model release. The defense works precisely because it sidesteps the arms race it cannot win, rather than confronting it.
Cheap Insurance Against an Expensive Trick
Deepfake executive fraud borrows a lifetime of trust in familiar faces and spends it in one rushed transaction. The cases that succeeded lacked an independent check; the cases that failed had it. Closing the gap needs no software, only the discipline to verify a large or secret request through a channel the camera cannot reach. Build that habit before it is needed, and the next convincing face on the call becomes a question to answer rather than an order to obey.
