Case Library / Vishing (Voice Phishing) / UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)

UK Energy Firm AI Voice-Clone CEO Fraud (Euler Hermes Case)

The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio of his German parent company's own CEO's voice, marking the first widely reported criminal use of AI voice-cloning technology, disclosed by insurer Euler Hermes.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In March 2019, the CEO of the UK subsidiary of a German energy company (also described in press accounts as the company's managing director) received a phone call he believed was from his own boss, the CEO of the German parent company, referred to in press reports only by the first name "Johannes." The caller's voice had been synthetically generated using AI voice-cloning software to mimic the real parent-company CEO's voice, reportedly including his slight German accent and characteristic speech rhythm. Believing the call genuine, and having received supporting payment instructions by email, the UK CEO wired €220,000 (about $243,000) to a bank account in Hungary that was described to him as belonging to a supplier awaiting urgent payment. The fraudster called back twice more: once to falsely claim the money had already been reimbursed, and again to request an additional transfer (reporting does not indicate this second request exceeded the first €220,000). On this third call, the UK CEO became suspicious because the promised reimbursement had never arrived and the call originated from an unfamiliar Austrian number; he was separately in contact with the actual parent-company CEO at the time, which exposed the fraud and allowed the second transfer to be stopped. The stolen funds were reportedly moved on from Hungary through additional accounts, including one in Mexico, and were never recovered. The parent company's crime/fraud insurer, Euler Hermes, paid the claim; its executive Rüdiger Kirsch disclosed the case to the Wall Street Journal, which published the first report on August 30, 2019, with broader media pickup (Washington Post, Forbes, and others) following in the first week of September 2019. This was the first widely reported instance of AI voice-cloning technology being used to commit a real-world financial fraud.

How the Attack Worked

The scheme combined classic CEO-fraud social engineering with a new technical capability: real-time AI voice cloning. The CEO of the UK subsidiary (described in some press accounts as the company's managing director) received a phone call that he believed was from his own boss, the CEO of the German parent company (referred to in reporting only by the first name "Johannes"). The voice was reported by Euler Hermes to have reproduced not just the general sound of the parent-company CEO's voice but distinctive characteristics such as a slight German accent and his particular speech "melody," which is why the UK CEO did not question it. The caller instructed him to urgently wire €220,000 to a Hungarian supplier, and follow-up payment details arrived by email, lending the request the appearance of a legitimate, previously-discussed supplier payment. The UK CEO complied. The fraudster then called back a second time, falsely claiming the funds had already been reimbursed, and initiated a third call requesting an additional transfer (sources do not indicate this second request was for a larger amount than the first). This time the UK CEO grew suspicious: the promised reimbursement had not shown up, and the incoming call displayed an Austrian number rather than the expected German one. Crucially, the suspicion was confirmed because he was simultaneously in contact with the real parent-company CEO by phone, exposing the discrepancy and allowing the second transfer to be halted before it went out.

The Lure & the Tell

The lure: a phone call carrying the actual parent-company boss's voice, accent, and speaking style, immediately followed by an email with concrete payment details, giving the request both auditory and documentary legitimacy, plus the classic urgency/confidentiality framing of CEO fraud. The tell: no independent, pre-established callback verification was used for the first transfer; the story unraveled only on the third contact when the promised reimbursement hadn't materialized and the caller ID (an unexpected Austrian number) didn't match the expected origin, at the same moment the UK CEO happened to be reaching the genuine parent-company CEO through a separate channel.

Outcome

The initial €220,000 transfer was completed and the money moved through further accounts (reportedly including Mexico) and was never recovered. A follow-up request for an additional transfer (sources do not indicate this was for a larger amount than the first) was stopped after the UK CEO grew suspicious (a promised reimbursement never arrived and a follow-up call came from an unexpected Austrian number) and cross-checked with the real parent-company CEO by phone. Euler Hermes, the parent company's fraud/crime insurer, covered the loss under the client's policy. No suspects were publicly identified and no arrests, indictments, or prosecutions tied to the case have been reported.

Why It Matters

This is regarded as the first publicly documented criminal use of AI voice-cloning/deepfake audio to defraud a company, marking an inflection point where "hearing is believing" could no longer be assumed safe. It demonstrated that voice, long treated as an intuitive authentication signal in business communication, could be synthetically reproduced well enough to defeat human judgment even when the imitated details (accent, cadence) were highly specific to the impersonated individual, and even when the target was the victim company's own CEO, someone who might otherwise be assumed to have the seniority and scrutiny to resist such a scheme. The case became the canonical reference point cited across cybersecurity, insurance, and AI-safety discussions for why organizations need callback/out-of-band verification procedures for financial requests regardless of how convincing a voice sounds, and why crime/fraud insurance policies needed to explicitly address AI-enabled social engineering as a covered peril.

Defenses

Post-incident recommendations from the reporting and industry commentary emphasized: out-of-band verification of any urgent wire-transfer request (call back on a known, previously-verified number rather than trusting caller ID or the incoming call itself); dual-approval/maker-checker controls for wire transfers above a threshold, especially to new or first-time payees; treating "urgency + secrecy + unusual payee" as a classic fraud triad regardless of how convincing the requester's voice sounds; executive-level awareness that voice is no longer a reliable authentication factor, even for senior leaders who consider themselves security-savvy; cyber-insurance/crime policies that explicitly cover social-engineering-induced wire fraud (Euler Hermes' payout here helped establish that such policies could and should cover AI-voice-enabled fraud specifically, not just classic BEC).

Sources
  • Fraudsters Used AI to Mimic CEO's Voice in Unusual Cybercrime Case. The Wall Street Journal Secondary. Fetched and confirmed live. Original investigative report first disclosing the case (published August 30, 2019 by Catherine Stupp), based on an interview with Euler Hermes executive Rudiger Kirsch; confirmed content includes the EUR220,000/$243,000 figure, the Hungarian supplier account, the one-hour urgency framing, and identification of the victim as the CEO of a UK-based energy firm whose German parent company's CEO was impersonated. Treated here as the de facto primary account since Euler Hermes is the direct first-party source and no court/regulatory filing is public.
  • Artificial-intelligence voice is used in a theft. The Washington Post Secondary. Fetched and confirmed live. Published September 4, 2019 by Drew Harwell; confirms the managing-director description, the more-than-$240,000 wire to a Hungarian account, the Friday-afternoon timing in March, and Euler Hermes as the disclosing insurer; adds detail on the internal 'false Johannes' framing used by the insurer.
  • In AI first, voice-mimicking software used in a major heist. South China Morning Post Secondary. Fetched and confirmed live; syndicated version of the Washington Post report (published September 5, 2019), corroborating the same core facts (managing director, British energy company, ~US$240,000 to Hungary).
  • A Voice Deepfake Was Used To Scam A CEO Out Of $243,000. Forbes Secondary. Fetched and confirmed live. Published September 3, 2019 by Jesse Damiani; confirms the CEO framing, the EUR220,000/$243,000 figure, the German-accent and speech-'melody' detail attributed to Rudiger Kirsch, and the three-call sequence (initial transfer, false reimbursement claim, follow-up request).
  • Manager at energy firm loses £200,000 after fraudsters use AI to impersonate his boss's voice. The Daily Telegraph Secondary. Confirmed live and on-topic (title, author James Titcomb, and August 31, 2019 date verified via search) but paywalled/access-restricted on direct fetch, so full body text could not be independently read; the GBP200,000 figure it reports is corroborated by other outlets (e.g. City A.M., Computing) citing the same reporting chain.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance of corporate structure and roles: The actors likely researched the relationship between the German parent company and its UK energy subsidiary, and identified both CEOs by name and role, plausibly using public corporate filings, company websites, press coverage, and professional-networking sites, gathering enough detail to know that an urgent call from the parent-company CEO to the UK CEO would be procedurally plausible.
Countering Stage 1: Public corporate structure and executive identity information is intentionally public and cannot realistically be hidden at the scale a company operates; the practical control is to assume attackers already have it and to harden the payment-approval process that this information could be used against, rather than trying to suppress org-chart or leadership visibility.
2
Voice-sample collection: Building a convincing clone of the parent-company CEO's voice typically required a training corpus of his real recorded speech; commercial voice-cloning tools of that era needed such samples, plausibly drawn from publicly available material such as earnings calls, conference talks, webinars, or media interviews featuring the executive.
Countering Stage 2: Reducing the volume of a senior executive's unscripted public speech available online (fewer open-access recorded webinars or conference talks) can modestly shrink the training material available to an attacker, but this is a weak, largely impractical control against a motivated actor and does not eliminate the risk on its own.
3
Voice-clone production: Using AI voice-synthesis/voice-cloning software consistent with the commercially available tools researchers pointed to at the time, the actors generated synthetic audio intended to reproduce not just the target's general vocal timbre but distinctive attributes such as his accent and speech rhythm, aiming to defeat a listener's intuitive sense of a familiar voice.
Countering Stage 3: Voice-clone production happens entirely outside the victim organization using tools and infrastructure it does not control, so there is no realistic technical interdiction at this stage; the effective response is downstream, at the point where a caller's voice is used to authorize action (Stage 4).
4
Pretext vishing call: The attacker placed a phone call to the UK CEO using the synthetic voice, impersonating the parent-company CEO and instructing an urgent wire transfer to a purported supplier account in Hungary, leaning on authority and time pressure to discourage the target from pausing to verify.
Countering Stage 4: Treat any phone-only request for an urgent wire transfer as unverified regardless of how convincing the caller's voice sounds, and require a callback to a known, previously-established number before acting, never a number supplied during the call itself.
5
Supporting email: A follow-up email supplied payee and bank-account details, giving the verbal instruction the appearance of routine, already-agreed business correspondence and reinforcing the pretext with documentary backup.
Countering Stage 5: Apply the same skepticism to a supporting email as to the call it accompanies; verify new or changed payee bank details directly with the purported recipient through an independently known contact channel rather than trusting details supplied within the same interaction that requested the payment.
6
Initial payment execution: The UK CEO wired the requested funds, roughly 220,000 euros, to the Hungarian account, completing the attacker's primary financial objective for this stage.
Countering Stage 6: A dual-approval or maker-checker control requiring a second authorized approver for wire transfers above a set threshold, or to new and first-time payees, would have required independent sign-off before the funds left, creating a second chance to catch the fraud before money moved.
7
False-reassurance follow-up call: The fraudster called again, falsely claiming the funds had already been reimbursed, an approach that both delayed suspicion and built apparent trust ahead of a further ask.
Countering Stage 7: Treat any unsolicited call claiming a prior payment issue has been resolved as an event requiring independent confirmation, not as confirmation itself; verify directly with your own finance team or bank rather than accepting the caller's assurance.
8
Second extraction attempt: A third call requested an additional transfer; this call came from an unfamiliar country's number rather than the one associated with the impersonated executive, and the promised reimbursement still had not appeared, prompting the target's suspicion.
Countering Stage 8: Formalize caller-ID or origin-country anomalies on financial-request calls as an automatic trigger for escalation or a transaction hold; in this case an unexpected country code was the detail that ultimately raised suspicion, and making that check a required step rather than a matter of individual alertness generalizes the defense.
9
Cash-out and layering: The stolen funds were reportedly moved onward from the Hungarian account through further intermediary accounts, including one traced toward Mexico, consistent with typical mule-account layering used to frustrate tracing and recovery before the fraud was fully identified.
Countering Stage 9: Once funds are released and layered across cross-border accounts, recovery becomes largely a law-enforcement and banking-network problem outside the victim's direct control; the real leverage remains upstream, at Stage 6's transaction controls and Stage 4's pre-transfer verification, though rapid fraud reporting to the sending and receiving banks within hours can occasionally freeze funds before layering completes.
Quick Facts
Victim
Unnamed UK-based energy firm, a subsidiary of an unnamed German parent company (both companies were not publicly named in reporting; insurer Euler Hermes disclosed the case on the client's behalf). The individual deceived was the CEO/managing director of the UK subsidiary, not a rank-and-file employee.
Location
United Kingdom (victim subsidiary); parent company headquartered in Germany; destination account in Hungary; funds later traced toward Mexico
Date
2019-03 (incident occurred on a Friday afternoon in March 2019, per Euler Hermes; first publicly disclosed by the Wall Street Journal on August 30, 2019, with broader media coverage, including the Washington Post, Forbes, and others, following in the first week of September 2019)
Impact
€220,000 wired to the Hungarian supplier account (reported in US press as approximately $243,000 and in UK press as approximately £198,600/£200,000). Funds were reportedly moved on from the Hungarian account through further accounts (reported destinations included Mexico) and were not recovered. A second transfer attempt was stopped before completion; sources describe it only as an "additional" or "further" transfer and do not confirm it was for a larger amount than the first. Euler Hermes, the parent company's crime/fraud insurer, covered the loss under the company's insurance policy.
Status
Confirmed
Case Type
Real-World Incident
Sector
Critical Infrastructure, Energy & Utilities, Financial Services & Insurance
Related

Related Cases

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and…

Incident 2019Read →

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…

Incident 2020Read →

Hamilton Academical FC £989,000 Vishing Fraud (RBS Bank Impersonation)

Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's sole authorised banking employee into moving nearly £1 million into…

Incident 2017Read →