The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio of his German parent company's own CEO's voice, marking the first widely reported criminal use of AI voice-cloning technology, disclosed by insurer Euler Hermes.
Reviewed by the Social Engineering Examples team.
In March 2019, the CEO of the UK subsidiary of a German energy company (also described in press accounts as the company's managing director) received a phone call he believed was from his own boss, the CEO of the German parent company, referred to in press reports only by the first name "Johannes." The caller's voice had been synthetically generated using AI voice-cloning software to mimic the real parent-company CEO's voice, reportedly including his slight German accent and characteristic speech rhythm. Believing the call genuine, and having received supporting payment instructions by email, the UK CEO wired €220,000 (about $243,000) to a bank account in Hungary that was described to him as belonging to a supplier awaiting urgent payment. The fraudster called back twice more: once to falsely claim the money had already been reimbursed, and again to request an additional transfer (reporting does not indicate this second request exceeded the first €220,000). On this third call, the UK CEO became suspicious because the promised reimbursement had never arrived and the call originated from an unfamiliar Austrian number; he was separately in contact with the actual parent-company CEO at the time, which exposed the fraud and allowed the second transfer to be stopped. The stolen funds were reportedly moved on from Hungary through additional accounts, including one in Mexico, and were never recovered. The parent company's crime/fraud insurer, Euler Hermes, paid the claim; its executive Rüdiger Kirsch disclosed the case to the Wall Street Journal, which published the first report on August 30, 2019, with broader media pickup (Washington Post, Forbes, and others) following in the first week of September 2019. This was the first widely reported instance of AI voice-cloning technology being used to commit a real-world financial fraud.
The scheme combined classic CEO-fraud social engineering with a new technical capability: real-time AI voice cloning. The CEO of the UK subsidiary (described in some press accounts as the company's managing director) received a phone call that he believed was from his own boss, the CEO of the German parent company (referred to in reporting only by the first name "Johannes"). The voice was reported by Euler Hermes to have reproduced not just the general sound of the parent-company CEO's voice but distinctive characteristics such as a slight German accent and his particular speech "melody," which is why the UK CEO did not question it. The caller instructed him to urgently wire €220,000 to a Hungarian supplier, and follow-up payment details arrived by email, lending the request the appearance of a legitimate, previously-discussed supplier payment. The UK CEO complied. The fraudster then called back a second time, falsely claiming the funds had already been reimbursed, and initiated a third call requesting an additional transfer (sources do not indicate this second request was for a larger amount than the first). This time the UK CEO grew suspicious: the promised reimbursement had not shown up, and the incoming call displayed an Austrian number rather than the expected German one. Crucially, the suspicion was confirmed because he was simultaneously in contact with the real parent-company CEO by phone, exposing the discrepancy and allowing the second transfer to be halted before it went out.
The lure: a phone call carrying the actual parent-company boss's voice, accent, and speaking style, immediately followed by an email with concrete payment details, giving the request both auditory and documentary legitimacy, plus the classic urgency/confidentiality framing of CEO fraud. The tell: no independent, pre-established callback verification was used for the first transfer; the story unraveled only on the third contact when the promised reimbursement hadn't materialized and the caller ID (an unexpected Austrian number) didn't match the expected origin, at the same moment the UK CEO happened to be reaching the genuine parent-company CEO through a separate channel.
The initial €220,000 transfer was completed and the money moved through further accounts (reportedly including Mexico) and was never recovered. A follow-up request for an additional transfer (sources do not indicate this was for a larger amount than the first) was stopped after the UK CEO grew suspicious (a promised reimbursement never arrived and a follow-up call came from an unexpected Austrian number) and cross-checked with the real parent-company CEO by phone. Euler Hermes, the parent company's fraud/crime insurer, covered the loss under the client's policy. No suspects were publicly identified and no arrests, indictments, or prosecutions tied to the case have been reported.
This is regarded as the first publicly documented criminal use of AI voice-cloning/deepfake audio to defraud a company, marking an inflection point where "hearing is believing" could no longer be assumed safe. It demonstrated that voice, long treated as an intuitive authentication signal in business communication, could be synthetically reproduced well enough to defeat human judgment even when the imitated details (accent, cadence) were highly specific to the impersonated individual, and even when the target was the victim company's own CEO, someone who might otherwise be assumed to have the seniority and scrutiny to resist such a scheme. The case became the canonical reference point cited across cybersecurity, insurance, and AI-safety discussions for why organizations need callback/out-of-band verification procedures for financial requests regardless of how convincing a voice sounds, and why crime/fraud insurance policies needed to explicitly address AI-enabled social engineering as a covered peril.
Post-incident recommendations from the reporting and industry commentary emphasized: out-of-band verification of any urgent wire-transfer request (call back on a known, previously-verified number rather than trusting caller ID or the incoming call itself); dual-approval/maker-checker controls for wire transfers above a threshold, especially to new or first-time payees; treating "urgency + secrecy + unusual payee" as a classic fraud triad regardless of how convincing the requester's voice sounds; executive-level awareness that voice is no longer a reliable authentication factor, even for senior leaders who consider themselves security-savvy; cyber-insurance/crime policies that explicitly cover social-engineering-induced wire fraud (Euler Hermes' payout here helped establish that such policies could and should cover AI-voice-enabled fraud specifically, not just classic BEC).
Two Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's sole authorised banking employee into moving nearly £1 million into…