Case Library / Vishing (Voice Phishing) / Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake AI-generated Zoom "government meeting" that appeared to feature PM Lawrence Wong and other senior officials.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

A Singaporean businessman with prior interactions with government officials was drawn into an elaborate impersonation scam that used deepfake AI to fabricate an entire Zoom video conference appearing to feature Prime Minister Lawrence Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, Monetary Authority of Singapore representatives, foreign officials (Canada's foreign minister, the UAE president's senior diplomatic adviser), and private-sector names (BlackRock, Dubai International Financial Centre). The pretext was a request for "urgent funding assistance" tied to the real-world Strait of Hormuz crisis. After being lured via WhatsApp and a spoofed email, signing a fake NDA, and attending the deepfake video conference, which closed with a fabricated PM Wong personally thanking him for attending, the victim was contacted again and induced to wire at least S$4.9 million (~US$3.8 million) in multiple transactions to a corporate bank account supplied by the scammers. The Singapore Police Force disclosed the case in a 14 May 2026 news release and published recovered footage with forensic deepfake analysis on 16 May 2026.

How the Attack Worked

The scam unfolded in stages combining messaging-app impersonation, spoofed email, forged documents, and a fabricated video conference. (1) Initial contact: the victim received a WhatsApp message from a profile using the photo and name of Secretary to the Cabinet Wong Hong Kuan, instructing him to attend a meeting with PM Lawrence Wong. (2) Email lure: he then received an email from WongHongKuan.secretarycabinet@proton.me (a Proton Mail address, not a genuine government domain) purportedly from the Cabinet Secretary, requesting "urgent funding assistance" tied to the Strait of Hormuz crisis, with an attached fake government "letter of guarantee" bearing a reproduction of PM Wong's signature promising reimbursement within 15 business days. (3) Control/legitimacy steps: the victim was told to sign a non-disclosure agreement and provide a copy of his identification card, both of which added a veneer of official process and discouraged him from discussing the "meeting" with others. (4) The deepfake meeting: after signing the NDA, he was invited to a Zoom video conference that appeared to include PM Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, representatives of the Monetary Authority of Singapore, Canada's foreign minister, the UAE president's senior diplomatic adviser, and private-sector figures from BlackRock and the Dubai International Financial Centre. He was introduced as a private-sector participant; the meeting proceeded with a briefing on the Strait of Hormuz situation and closed with a deepfake PM Wong personally acknowledging the victim's attendance. In reality every official in the call had been fabricated with deepfake AI. (5) Extraction: after the call, a scammer posing as a lawyer contacted the victim by WhatsApp and induced him to wire funds in multiple transactions to a corporate bank account supplied by the scammers. He grew suspicious afterward, contacted the real Cabinet Secretary, and only then learned he had been scammed.

The Lure & the Tell

The lure combined a personalized WhatsApp approach (using a real official's name and photo), a spoofed email from a Proton Mail address impersonating the Cabinet Secretary, a forged "letter of guarantee" carrying a fake reproduction of PM Wong's signature, an NDA to enforce secrecy, a geopolitical urgency hook (the real-world Strait of Hormuz crisis), and finally a full deepfake Zoom "meeting" populated with recognizable named officials and organizations (Singapore's president, PM, a minister, MAS, foreign ministers, BlackRock, DIFC) to manufacture social proof and authority at a scale far beyond a single spoofed voice call. The tell, per Singapore Police Force's forensic review of the recovered footage: (1) speech did not synchronize with the speakers' lips, indicating pre-recorded inauthentic audio; (2) all "speakers'" audio was broadcast from a single account rather than from each individual call participant; and (3) the video showed a distorted background and a partially obscured/misaligned Zoom logo, indicating AI manipulation of the footage.

Outcome

The Singapore Police Force disclosed the loss in a public advisory on 14 May 2026 warning that scammers were targeting business professionals with prior government interactions, then followed up on 16 May 2026 with a second release publishing recovered footage from the deepfake Zoom conference and a technical breakdown of the deepfake indicators. PM Lawrence Wong personally posted on Facebook the same day (14 May) warning the public that messages purporting to arrange meetings on his behalf via the "Cabinet Secretary" were scams. No arrests specific to this S$4.9 million case were publicly announced in the sources reviewed; police did note that three people had been arrested and charged on 9 May 2026 for suspected SIM-card offences connected to earlier cases using the same modus operandi (fake NDA-gated virtual meetings with impersonated senior officials), though it is not confirmed those arrests relate to this specific victim's loss.

Why It Matters

This is one of the most detailed publicly documented real-world cases of deepfake video technology being used not just to impersonate a single individual on a call, but to fabricate an entire multi-participant, multi-institution virtual meeting, convincingly simulating a head of government, a head of state, a cabinet minister, a central bank, foreign officials, and named global financial institutions simultaneously. It shows that deepfake social engineering has moved beyond one-on-one voice-clone "urgent boss" scams into large-scale, geopolitically-themed group deception capable of extracting multi-million-dollar sums from a single sophisticated victim. It also demonstrates that having genuine, prior legitimate contact with real officials does not protect a target: it can be actively exploited to make the impersonation more credible. The case prompted an unusual direct public rebuttal from the impersonated sitting Prime Minister and a national police advisory with technical deepfake-detection guidance, illustrating how governments are now treating deepfake impersonation of officials as an emerging national fraud-prevention priority.

Defenses

The Singapore Police Force's public advisory (14 and 16 May 2026) told the public that government officials will NEVER ask, over email, phone, or video call, to transfer money, disclose bank login details, install apps from unofficial app stores, or transfer a call to police/other officials; to never send funds or ID documents to unverified individuals; to independently verify any purported official request through official government channels; and to use the ScamShield app/website or the 24/7 ScamShield Helpline (1799) to check suspicious messages. SPF also published a "3A" detection approach and technical deepfake tells (see lure_and_tell) so the public can visually/aurally scrutinize video calls. For organizations, the case argues for treating any high-value fund-transfer instruction that arrives via a video call or messaging app, however convincing the participants look, as unverified until confirmed through an independent, previously-established channel (e.g., a callback to a known number, not one supplied in the suspicious message), and for building deepfake-detection awareness (lip-sync mismatch, single-source audio, artifact/background distortion) into finance and executive-facing staff training.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: Singapore Police Force's advisory states the scam operators appear to specifically target business professionals who have had prior interactions with government officials, consistent with the attackers likely using OSINT sources such as public event listings, government press coverage, and business or social networks to identify a plausible target and to learn or approximate a real official's name, title, and photo (Secretary to the Cabinet Wong Hong Kuan) for impersonation.
Countering Stage 1: Business professionals' visibility as having government contacts is very hard to suppress at a societal scale; the realistic control is not hiding who has prior official contact but hardening the verification step any purported official request gets checked against, per Stage 4/5 defenses below.
2
Infrastructure setup, spoofed channels and forged documents: Before contact, the operators registered a free Proton Mail address styled to resemble an official government sender (WongHongKuan.secretarycabinet@proton.me), prepared WhatsApp profiles using the cabinet secretary's and prime minister's likenesses, and forged a government-style 'letter of guarantee' document bearing a reproduction of PM Wong's signature.
Countering Stage 2: Recognizing that genuine Singapore government communications use official 'gov.sg' domains, never free webmail providers like Proton Mail, and treating a mismatch as an immediate red flag, would have exposed the email lure before it escalated.
3
AI asset preparation, deepfake video and audio generation: Consistent with SPF's forensic finding that all 'speakers'' audio was broadcast from a single account rather than live from each participant, the operators likely used commercial or freely available deepfake video and voice-synthesis tools ahead of time to prepare pre-recorded, synthetic footage of multiple real senior officials for later playback.
Countering Stage 3: There is no practical user-facing control against deepfake asset preparation happening before an attack begins; the realistic control is downstream detection during the live call itself, per Stage 7 below.
4
Initial contact and authority lure via WhatsApp: The victim received a WhatsApp message from a profile using the Cabinet Secretary's name and photo, instructing him to attend a meeting with PM Wong, opening the approach through a trusted-looking impersonation channel.
Countering Stage 4: Treating unsolicited WhatsApp messages purporting to be from government officials, even ones bearing recognizable names and photos, as unverified, and confirming any such invitation through official government channels before responding, as SPF's advisory recommends, stops the approach at first contact.
5
Pretext escalation via spoofed email and forged document: A follow-up email from the fraudulent Proton Mail address requested urgent funding assistance tied to the real Strait of Hormuz crisis and included the forged letter of guarantee promising government reimbursement within 15 business days, adding documentary legitimacy and geopolitical urgency.
Countering Stage 5: Independently verifying any urgent funding request or 'letter of guarantee' with the purportedly issuing agency through a separately sourced contact channel, rather than one supplied in the message itself, would have caught the forged document before it gained credibility.
6
Secrecy and compliance conditioning via NDA and ID capture: The victim was told to sign a non-disclosure agreement and provide a copy of his identification card, steps that added a veneer of official process, discouraged him from seeking outside verification, and deepened his commitment to the process.
Countering Stage 6: Refusing to sign non-disclosure agreements or share identification documents as a precondition for a purported government meeting, and treating an imposed secrecy requirement itself as a warning sign that prompts outside verification, breaks the compliance-conditioning step.
7
Live deepfake group-meeting execution: The victim joined a Zoom call fabricated with deepfake video and audio of PM Wong, President Tharman Shanmugaratnam, Minister Indranee Rajah, MAS representatives, foreign officials, and named firms such as BlackRock and DIFC, closing with a personalized deepfake acknowledgment of his attendance, manufacturing social proof at a scale beyond a single impersonated caller.
Countering Stage 7: Applying SPF's published deepfake indicators, lip-sync mismatch, single-account audio broadcast for all speakers, and distorted background or logo artifacts, plus an organizational policy that no fund-transfer decision is ever made on the basis of a video call alone, regardless of how many recognizable participants appear, is the strongest available control at this stage.
8
Extraction contact posing as a lawyer: After the call, a scammer posing as a lawyer contacted the victim again via WhatsApp and directed him to wire funds for the 'funding assistance' request.
Countering Stage 8: Treating any fund-transfer instruction that arrives via WhatsApp or another messaging channel from a previously unknown party, including someone claiming to be a lawyer, as unverified until confirmed through an independently sourced phone number, closes off the extraction contact.
9
Payout via money-mule corporate account: The victim transferred at least S$4.9 million in multiple transactions to a corporate bank account supplied by the scammers, completing the extraction of funds.
Countering Stage 9: Bank-side controls such as enhanced due diligence and hold periods on large first-time wires to newly supplied corporate payee accounts, combined with the victim independently verifying payee details through a previously established banking relationship before authorizing the transfer, is the last realistic checkpoint before funds become unrecoverable.
Quick Facts
Victim
Unnamed Singaporean businessman / business professional
Location
Singapore
Date
2026-05-14
Impact
Victim lost at least S$4.9 million (approximately US$3.8 million; reported by some outlets as roughly RM15.3 million), transferred via a series of transactions to a corporate bank account supplied by the scammers. This is described by police as a minimum ("at least") figure.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…

Incident 2026Read →

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

San Diego Coordinated Takedown of Pig-Butchering Scam Compounds: Ko Thet Company, Sanduo Group, Giant Company (2026)

A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad, while a…

Incident 2026Read →