The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio.
Social Engineering Examples·5 sources
In March 2019, the CEO of the UK subsidiary of a German energy company (also described in press accounts as the company's managing director) received a phone call he believed was from his own boss, the CEO of the German parent company, referred to in press reports only by the first name "Johannes." The caller's voice had been synthetically generated using AI voice-cloning software to mimic the real parent-company CEO's voice, reportedly including his slight German accent and characteristic speech rhythm.
Believing the call genuine, and having received supporting payment instructions by email, the UK CEO wired €220,000 (about $243,000) to a bank account in Hungary that was described to him as belonging to a supplier awaiting urgent payment. The fraudster called back twice more: once to falsely claim the money had already been reimbursed, and again to request an additional transfer (reporting does not indicate this second request exceeded the first €220,000).
On this third call, the UK CEO became suspicious because the promised reimbursement had never arrived and the call originated from an unfamiliar Austrian number; he was separately in contact with the actual parent-company CEO at the time, which exposed the fraud and allowed the second transfer to be stopped. The stolen funds were reportedly moved on from Hungary through additional accounts, including one in Mexico, and were never recovered.
The parent company's crime/fraud insurer, Euler Hermes, paid the claim; its executive Rüdiger Kirsch disclosed the case to the Wall Street Journal, which published the first report on August 30, 2019, with broader media pickup (Washington Post, Forbes, and others) following in the first week of September 2019. This was the first widely reported instance of AI voice-cloning technology being used to commit a real-world financial fraud.
The scheme combined classic CEO-fraud social engineering with a new technical capability: real-time AI voice cloning. The CEO of the UK subsidiary (described in some press accounts as the company's managing director) received a phone call that he believed was from his own boss, the CEO of the German parent company (referred to in reporting only by the first name "Johannes").
The voice was reported by Euler Hermes to have reproduced not just the general sound of the parent-company CEO's voice but distinctive characteristics such as a slight German accent and his particular speech "melody," which is why the UK CEO did not question it. The caller instructed him to urgently wire €220,000 to a Hungarian supplier, and follow-up payment details arrived by email, lending the request the appearance of a legitimate, previously-discussed supplier payment.
The UK CEO complied. The fraudster then called back a second time, falsely claiming the funds had already been reimbursed, and initiated a third call requesting an additional transfer (sources do not indicate this second request was for a larger amount than the first). This time the UK CEO grew suspicious: the promised reimbursement had not shown up, and the incoming call displayed an Austrian number rather than the expected German one.
Crucially, the suspicion was confirmed because he was simultaneously in contact with the real parent-company CEO by phone, exposing the discrepancy and allowing the second transfer to be halted before it went out.
The lure: a phone call carrying the actual parent-company boss's voice, accent, and speaking style, immediately followed by an email with concrete payment details, giving the request both auditory and documentary legitimacy, plus the classic urgency/confidentiality framing of CEO fraud. The tell: no independent, pre-established callback verification was used for the first transfer; the story unraveled only on the third contact when the promised reimbursement hadn't materialized and the caller ID (an unexpected Austrian number) didn't match the expected origin, at the same moment the UK CEO happened to be reaching the genuine parent-company CEO through a separate channel.
The initial €220,000 transfer was completed and the money moved through further accounts (reportedly including Mexico) and was never recovered. A follow-up request for an additional transfer (sources do not indicate this was for a larger amount than the first) was stopped after the UK CEO grew suspicious (a promised reimbursement never arrived and a follow-up call came from an unexpected Austrian number) and cross-checked with the real parent-company CEO by phone.
Euler Hermes, the parent company's fraud/crime insurer, covered the loss under the client's policy. No suspects were publicly identified and no arrests, indictments, or prosecutions tied to the case have been reported.
This is regarded as the first publicly documented criminal use of AI voice-cloning/deepfake audio to defraud a company, marking an inflection point where "hearing is believing" could no longer be assumed safe. It demonstrated that voice, long treated as an intuitive authentication signal in business communication, could be synthetically reproduced well enough to defeat human judgment even when the imitated details (accent, cadence) were highly specific to the impersonated individual, and even when the target was the victim company's own CEO, someone who might otherwise be assumed to have the seniority and scrutiny to resist such a scheme.
The case became the canonical reference point cited across cybersecurity, insurance, and AI-safety discussions for why organizations need callback/out-of-band verification procedures for financial requests regardless of how convincing a voice sounds, and why crime/fraud insurance policies needed to explicitly address AI-enabled social engineering as a covered peril.
Post-incident recommendations from the reporting and industry commentary emphasized: out-of-band verification of any urgent wire-transfer request (call back on a known, previously-verified number rather than trusting caller ID or the incoming call itself); dual-approval/maker-checker controls for wire transfers above a threshold, especially to new or first-time payees; treating "urgency + secrecy + unusual payee" as a classic fraud triad regardless of how convincing the requester's voice sounds; executive-level awareness that voice is no longer a reliable authentication factor, even for senior leaders who consider themselves security-savvy; cyber-insurance/crime policies that explicitly cover social-engineering-induced wire fraud (Euler Hermes' payout here helped establish that such policies could and should cover AI-voice-enabled fraud specifically, not just classic BEC).
Social Engineering Examples. “UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)”. Accessed 19 September 2026. https://socialengineeringexamples.com/uk-energy-firm-ai-voice-clone-ceo-fraud-2019
The actors likely researched the relationship between the German parent company and its UK energy subsidiary, and identified both CEOs by name and role, plausibly using public corporate filings, company websites, press coverage, and professional-networking sites, gathering enough detail to know that an urgent call from the parent-company CEO to the UK CEO would be procedurally plausible.
Public corporate structure and executive identity information is intentionally public and cannot realistically be hidden at the scale a company operates; the practical control is to assume attackers already have it and to harden the payment-approval process that this information could be used against, rather than trying to suppress org-chart or leadership visibility.
Building a convincing clone of the parent-company CEO's voice typically required a training corpus of his real recorded speech; commercial voice-cloning tools of that era needed such samples, plausibly drawn from publicly available material such as earnings calls, conference talks, webinars, or media interviews featuring the executive.
Reducing the volume of a senior executive's unscripted public speech available online (fewer open-access recorded webinars or conference talks) can modestly shrink the training material available to an attacker, but this is a weak, largely impractical control against a motivated actor and does not eliminate the risk on its own.
Using AI voice-synthesis/voice-cloning software consistent with the commercially available tools researchers pointed to at the time, the actors generated synthetic audio intended to reproduce not just the target's general vocal timbre but distinctive attributes such as his accent and speech rhythm, aiming to defeat a listener's intuitive sense of a familiar voice.
Voice-clone production happens entirely outside the victim organization using tools and infrastructure it does not control, so there is no realistic technical interdiction at this stage; the effective response is downstream, at the point where a caller's voice is used to authorize action (Stage 4).
The attacker placed a phone call to the UK CEO using the synthetic voice, impersonating the parent-company CEO and instructing an urgent wire transfer to a purported supplier account in Hungary, leaning on authority and time pressure to discourage the target from pausing to verify.
Treat any phone-only request for an urgent wire transfer as unverified regardless of how convincing the caller's voice sounds, and require a callback to a known, previously-established number before acting, never a number supplied during the call itself.
A follow-up email supplied payee and bank-account details, giving the verbal instruction the appearance of routine, already-agreed business correspondence and reinforcing the pretext with documentary backup.
Apply the same skepticism to a supporting email as to the call it accompanies; verify new or changed payee bank details directly with the purported recipient through an independently known contact channel rather than trusting details supplied within the same interaction that requested the payment.
The UK CEO wired the requested funds, roughly 220,000 euros, to the Hungarian account, completing the attacker's primary financial objective for this stage.
A dual-approval or maker-checker control requiring a second authorized approver for wire transfers above a set threshold, or to new and first-time payees, would have required independent sign-off before the funds left, creating a second chance to catch the fraud before money moved.
The fraudster called again, falsely claiming the funds had already been reimbursed, an approach that both delayed suspicion and built apparent trust ahead of a further ask.
Treat any unsolicited call claiming a prior payment issue has been resolved as an event requiring independent confirmation, not as confirmation itself; verify directly with your own finance team or bank rather than accepting the caller's assurance.
A third call requested an additional transfer; this call came from an unfamiliar country's number rather than the one associated with the impersonated executive, and the promised reimbursement still had not appeared, prompting the target's suspicion.
Formalize caller-ID or origin-country anomalies on financial-request calls as an automatic trigger for escalation or a transaction hold; in this case an unexpected country code was the detail that ultimately raised suspicion, and making that check a required step rather than a matter of individual alertness generalizes the defense.
The stolen funds were reportedly moved onward from the Hungarian account through further intermediary accounts, including one traced toward Mexico, consistent with typical mule-account layering used to frustrate tracing and recovery before the fraud was fully identified.
Once funds are released and layered across cross-border accounts, recovery becomes largely a law-enforcement and banking-network problem outside the victim's direct control; the real leverage remains upstream, at Stage 6's transaction controls and Stage 4's pre-transfer verification, though rapid fraud reporting to the sending and receiving banks within hours can occasionally freeze funds before layering completes.
Browse by what this case has in common with others in the library.
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
The Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…