A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and colleagues were all AI-generated.
Social Engineering Examples·6 sources
In mid-January 2024, a finance-department employee in the Hong Kong office of British engineering firm Arup received a message purporting to come from the company's UK-based chief financial officer, referencing a confidential transaction that needed to be carried out. The employee was initially suspicious, since the request had the hallmarks of a phishing attempt.
The employee was then invited to a video conference call. On the call appeared what looked and sounded like the company's CFO along with several other colleagues. All of them were in fact deepfake recreations. Reassured by the familiar faces and voices, the employee proceeded to make a series of transfers. Hong Kong Police said the staff member made 15 transfers totalling HK$200 million (about US$25.6 million) to five different Hong Kong bank accounts over roughly a week.
The scam was discovered only after the employee later followed up with the group's headquarters. Hong Kong Police received a report of the incident on 29 January 2024, by which point the money was already gone. At a February 2024 briefing, acting senior superintendent Baron Chan Shun-ching described it as the first case in the city in which a bogus multi-person video conference was used in this way, with everyone on the call except the victim being fabricated.
Arup was not named by police at the time. In May 2024 the Financial Times identified the victim as Arup through two people familiar with the matter, and Arup confirmed it, stating it had "notified the police about an incident of fraud in Hong Kong" in January and that "fake voices and images were used." Arup added that its financial stability and operations were not affected and that none of its internal systems were compromised.
Recon/contact: Fraudsters used publicly available video and audio of the target executives (reportedly sourced from material like YouTube/public appearances) to build convincing synthetic likenesses, then opened with a message impersonating the UK-based CFO about a "confidential transaction." Rapport/legitimacy: They escalated from text to a live-feeling video conference populated by a deepfaked CFO plus multiple fake "colleagues," which manufactured social proof and authority and overcame the employee's initial doubt.
Exploitation: Under the cover of secrecy and urgency, the victim was instructed to execute payments. Police noted the deepfake participants were essentially pre-rendered and did minimal live interaction beyond prompting the victim to introduce themselves, limiting the chance of exposure. Payout: 15 separate transfers to five accounts spread over about a week, discovered only when the employee checked with headquarters.
This is an awareness-level summary, not an operational guide.
Pretext: a "confidential/secret transaction" ordered by the CFO, reinforced by a video call full of recognizable senior figures. Red flags visible in hindsight: an unusual payment request arriving first as a message that felt like phishing; secrecy and pressure discouraging normal verification; a request to bypass standard multi-party payment controls; call participants who mostly did not interact naturally; and instructions to split a large sum across many transfers to multiple unfamiliar accounts.
Any one of these warranted out-of-band confirmation with headquarters before moving funds.
HK$200M (~US$25.6M) transferred and lost. Investigation remained ongoing with no arrests reported at the time of Arup's confirmation. Arup said its systems were not breached and operations were unaffected; the firm's global CIO publicly discussed the case to raise awareness of deepfake fraud.
One of the first and largest publicly known deepfake video-conference frauds, it showed that seeing and hearing trusted executives on a live call is no longer proof of identity. It moved deepfake-enabled BEC-style fraud from theoretical to a concrete eight-figure loss at a sophisticated global firm, underscoring that payment authorization controls, not visual trust, are the real defense.
Mandatory out-of-band verification for large or unusual payments (call the executive back on a known number, independent of the requesting channel). Enforce multi-person approval and dual authorization for high-value transfers regardless of who "appears" to approve. Treat secrecy/urgency around payments as a red flag requiring escalation. Establish live-verification challenges (e.g., unexpected questions or actions) and codewords for sensitive requests.
Reduce reliance on public executive audio/video where feasible, and train finance staff specifically on deepfake video-call scenarios.
Real-time detection on the call itself is the emerging control for this attack class; see deepfake video detection methods for how the current approaches work and where they fail.
Social Engineering Examples. “Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)”. Accessed 19 September 2026. https://socialengineeringexamples.com/arup-deepfake-cfo-video-call-2024
Attackers identified Arup's CFO and several colleagues as impersonation targets and collected publicly available video/audio of them (reporting points to material like broadcast interviews and other public appearances), the kind of footage a public company's leadership routinely generates, and enough to train a likeness/voice model of each person.
Public exposure of unscripted executive video/audio is very hard to fully prevent for a company of Arup's size; the realistic response is assuming this material already exists and hardening what happens downstream, not trying to suppress it.
That footage was used to build deepfake video and voice models good enough to sustain a live-feeling group video call, not just a single pre-recorded clip of one person.
There is no practical way to block deepfake creation from already-public footage. The correct control sits at the verification stages that follow, not at content-generation itself.
A text-based message impersonating the CFO opened the scheme by raising a 'confidential transaction,' establishing the cover story and a reason for secrecy before any video was shown.
Treat any message demanding confidentiality or secrecy around a financial transaction as an automatic trigger for independent manager-level review, regardless of who appears to be asking.
The target was invited onto a call populated by the deepfaked CFO and several deepfaked 'colleagues' at once, manufacturing social proof that a single deepfaked caller could not achieve alone.
Establish a live verification challenge for high-value requests made over video (an unexpected, hard-to-script question or action), and never treat 'I saw and heard them on a call' alone as sufficient proof of identity for a financial instruction.
Hong Kong Police noted the fake participants did little live interaction beyond prompting the victim to introduce himself, consistent with attackers keeping synthetic personas passive to reduce the chance a technical glitch would break the illusion.
Train staff to notice when 'colleagues' on a call are unusually static or don't engage in normal cross-talk, and make it normal to ask direct, unscripted questions a passive deepfake would struggle to answer.
Reassured by the call, the employee bypassed normal verification and proceeded to authorize payment on the 'CFO's' instruction.
Enforce mandatory out-of-band verification (call back a known, independently sourced number) plus dual authorization for any large or unusual wire, with no exception for seniority or secrecy demands.
The victim executed 15 separate wire transfers over about a week to five different Hong Kong bank accounts, splitting the HK$200M total across multiple accounts and transactions, a structuring pattern that is harder to freeze quickly than one large transfer.
Bank-side monitoring for multiple same-week wires to newly added or unfamiliar payees can flag structuring patterns before all tranches clear; a single approved 'total transaction' cap also forces a second review before a scheme can be split into many smaller transfers.
Browse by what this case has in common with others in the library.
A Singaporean finance professional in her 50s lost S$1.2 million.
A scammer spoofed a New Zealand bank's real phone number, posed as its fraud team.
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
Dow Chemical and Sasol paid PR firms who subcontracted a private intelligence firm to run over 120 dumpster-diving raids on…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…