A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and colleagues were all AI-generated deepfakes.
Reviewed by the Social Engineering Examples team.
In mid-January 2024, a finance-department employee in the Hong Kong office of British engineering firm Arup received a message purporting to come from the company's UK-based chief financial officer, referencing a confidential transaction that needed to be carried out. The employee was initially suspicious, since the request had the hallmarks of a phishing attempt. The employee was then invited to a video conference call. On the call appeared what looked and sounded like the company's CFO along with several other colleagues. All of them were in fact deepfake recreations. Reassured by the familiar faces and voices, the employee proceeded to make a series of transfers. Hong Kong Police said the staff member made 15 transfers totalling HK$200 million (about US$25.6 million) to five different Hong Kong bank accounts over roughly a week. The scam was discovered only after the employee later followed up with the group's headquarters. Hong Kong Police received a report of the incident on 29 January 2024, by which point the money was already gone. At a February 2024 briefing, acting senior superintendent Baron Chan Shun-ching described it as the first case in the city in which a bogus multi-person video conference was used in this way, with everyone on the call except the victim being fabricated. Arup was not named by police at the time. In May 2024 the Financial Times identified the victim as Arup through two people familiar with the matter, and Arup confirmed it, stating it had "notified the police about an incident of fraud in Hong Kong" in January and that "fake voices and images were used." Arup added that its financial stability and operations were not affected and that none of its internal systems were compromised.
Recon/contact: Fraudsters used publicly available video and audio of the target executives (reportedly sourced from material like YouTube/public appearances) to build convincing synthetic likenesses, then opened with a message impersonating the UK-based CFO about a "confidential transaction." Rapport/legitimacy: They escalated from text to a live-feeling video conference populated by a deepfaked CFO plus multiple fake "colleagues," which manufactured social proof and authority and overcame the employee's initial doubt. Exploitation: Under the cover of secrecy and urgency, the victim was instructed to execute payments. Police noted the deepfake participants were essentially pre-rendered and did minimal live interaction beyond prompting the victim to introduce themselves, limiting the chance of exposure. Payout: 15 separate transfers to five accounts spread over about a week, discovered only when the employee checked with headquarters. This is an awareness-level summary, not an operational guide.
Pretext: a "confidential/secret transaction" ordered by the CFO, reinforced by a video call full of recognizable senior figures. Red flags visible in hindsight: an unusual payment request arriving first as a message that felt like phishing; secrecy and pressure discouraging normal verification; a request to bypass standard multi-party payment controls; call participants who mostly did not interact naturally; and instructions to split a large sum across many transfers to multiple unfamiliar accounts. Any one of these warranted out-of-band confirmation with headquarters before moving funds.
HK$200M (~US$25.6M) transferred and lost. Investigation remained ongoing with no arrests reported at the time of Arup's confirmation. Arup said its systems were not breached and operations were unaffected; the firm's global CIO publicly discussed the case to raise awareness of deepfake fraud.
One of the first and largest publicly known deepfake video-conference frauds, it showed that seeing and hearing trusted executives on a live call is no longer proof of identity. It moved deepfake-enabled BEC-style fraud from theoretical to a concrete eight-figure loss at a sophisticated global firm, underscoring that payment authorization controls, not visual trust, are the real defense.
Mandatory out-of-band verification for large or unusual payments (call the executive back on a known number, independent of the requesting channel). Enforce multi-person approval and dual authorization for high-value transfers regardless of who "appears" to approve. Treat secrecy/urgency around payments as a red flag requiring escalation. Establish live-verification challenges (e.g., unexpected questions or actions) and codewords for sensitive requests. Reduce reliance on public executive audio/video where feasible, and train finance staff specifically on deepfake video-call scenarios.
A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…
A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team, and talked a customer into…
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…