Failure AtlasFinance · Fraud · 2024

Arup and the Deepfake on the Video Call

A finance employee in Hong Kong joined a video call with the CFO and several colleagues. Every face on the call was synthetic. Fifteen transfers and 25 million dollars later, the company found out.

Failure typeMixed (synthetic media against a human control)
Where it failedPeople · Process
FiledJul 2026
The missing control

Payment authority rested on recognizing faces and voices, and no out-of-band verification stood in front of an unusual transfer. Two controls were absent: a callback on a known channel before money moved, and a second approver who was not on the meeting.

NIST RMFThreat-model synthetic media against every control that authenticates a person.
ISO 42001Impact assessment includes how AI in the wild attacks your own processes.
EU AI ActDeepfake transparency duties exist because seeing is no longer verifying.
STAMPThe verification step was spoofable, so the control structure had a hole at its center.
PlainA face on a screen is not identity. Call back on a number you already had.

In January 2024, a finance employee in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House, received an email that claimed to come from the company’s UK-based chief financial officer. It described a confidential transaction. The employee was suspicious, and rightly so. It read like phishing.

Then came the video call. On it were the CFO and several colleagues, faces and voices the employee recognized. Reassured, the employee followed the instructions from the call and made fifteen transfers, about 200 million Hong Kong dollars, roughly 25.6 million US, to five local bank accounts. Every person on that call except the victim was a deepfake, built from publicly available footage of real executives. The fraud surfaced only when the employee later checked with the UK head office. Hong Kong police disclosed the case in February 2024, and Arup confirmed in May that it was the victim. No internal system was breached. Nobody hacked anything. The attackers counterfeited people.

Where it failed

The initial suspicion worked. The employee doubted the email, which is exactly what training is supposed to produce. What failed was the verification step itself. The check the employee performed, joining a call and seeing familiar faces, was the thing the attackers had manufactured. Once the check is spoofable, performing it diligently makes things worse, because it converts doubt into confidence.

The deeper break was in process. A payment of this size could be authorized on the strength of a meeting, with no verification through a separate channel and no second approver outside the room. That process was built for a world where a live video of your CFO was proof. That world ended quietly, sometime before January 2024, and the process did not notice.

The employee was not careless. The one check available to them was the exact thing the attackers had faked.

How it could have been caught

The controls are old ones, and they work precisely because they do not care what the attacker can fake. A callback to the CFO on a number already on file, not one from the email or the invite, ends this attack in one phone call. A second approver, reached independently, ends it too. So does a hard rule that new payee accounts and unusual amounts trigger a delay and a challenge on a separate channel. None of this is AI. That is the point. The defense against synthetic media is procedure that does not route through the medium being synthesized.

What it means for AI

Any organization that still treats a face, a voice, or a video call as authentication should sit with this one. Generative tools have made convincing synthetic identity cheap, and the first place it cashes out is payments fraud, the oldest game there is. Due diligence now has to ask a new question of every approval chain: which steps assume that seeing or hearing a person proves it is them, and what happens when that assumption fails.

The agentic version is close behind. An AI agent that approves invoices, resets credentials, or releases funds on the strength of a request that looks and sounds right is this same employee, minus the capacity for suspicion. Verification has to run out-of-band, on channels and secrets the attacker cannot generate, and anything irreversible needs a second, independent yes. Identity is now just another input, and it should be treated as untrusted until it is verified through something that cannot be faked.


Back to the Atlas