Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI voice clone and repurposed YouTube footage.
Social Engineering Examples·4 sources
WPP CEO Mark Read disclosed in an internal email to company leadership, reported publicly on 10 May 2024 by the Financial Times and The Guardian, that fraudsters had attempted an elaborate AI-enabled impersonation scam against the company. The attackers created a fake WhatsApp account using a publicly available photograph of Read and used it to arrange what appeared to be a Microsoft Teams meeting involving Read and a second senior WPP executive.
During the call, the fraudsters used an AI voice clone together with repurposed YouTube footage to simulate that second executive's live presence, while separately impersonating Read off-camera through the meeting's text-chat window. The pretext was that the actual target, an unnamed WPP "agency leader," was being asked to help set up a new business, with the ultimate goal of extracting money and personal details.
The target became suspicious and did not comply, and the attempt failed with no funds or data lost. WPP confirmed the incident via a spokesperson statement, and Read used the episode to warn staff about increasingly sophisticated, individually tailored AI attacks on senior leaders.
The operation chained a fake profile, a spoofed video meeting, and synthetic media rather than a single deepfake artifact. First, fraudsters built a fake WhatsApp account using a publicly available photograph of CEO Mark Read, giving them a plausible identity to initiate contact. They used that account to arrange a Microsoft Teams meeting that appeared to include Read and a second, unnamed senior WPP executive.
During the live call, the attackers deployed an AI voice clone plus repurposed YouTube footage of that second executive to simulate their real-time presence and voice. The deepfake "performance" was aimed at the second executive's persona, not a live clone of Read's voice. Read himself was impersonated only off-camera, via the meeting's text-chat window, rather than through a live voice clone, likely because sustaining two convincing simultaneous AI personas in one call is harder than one.
With an apparently legitimate two-executive meeting underway, the fraudsters pressed the actual target, a WPP "agency leader," with the pretext that they were being asked to help set up a new business, a rationale intended to justify a later request for money and personal/financial details. Note: several secondary write-ups (e.g., insurance/vendor case studies) simplify this as "scammers cloned Mark Read's voice," but the original reporting, sourced from Read's internal email, indicates the live audio/video deepfake targeted the second executive's identity while Read was impersonated via photo and text only; WPP never named that second executive or the targeted agency leader.
The lure was a seemingly legitimate two-person executive video call: a familiar CEO photo/identity plus a voice-and-video-deepfaked colleague appearing to speak live, used to manufacture instant credibility for an unusual internal ask: help "set up a new business." That combination of recognized faces, a live-sounding voice, and an internally plausible corporate rationale was designed to short-circuit the target's normal skepticism about wire-transfer or data requests.
The tell that broke the scam was not a specific technical glitch WPP disclosed publicly. The company only credited "the vigilance of our people, including the executive concerned," suggesting the targeted leader simply found the request itself, or some aspect of the interaction, suspicious enough to not comply, rather than the deepfake being visually or audibly detected as fake.
The attempt failed: no money was transferred and no personal data was disclosed. WPP characterized the incident as "prevented" thanks to the target's own vigilance, not a technical detection system. Read disclosed the episode in an internal leadership email (reported publicly on 2024-05-10) as a proactive staff-awareness warning rather than as a breach notification.
WPP did not disclose the exact attack date, the identity of the targeted "agency leader," or the identity of the second impersonated executive, and there is no public report of any arrest, named threat actor, or law-enforcement case tied to this specific attempt.
This is one of the earliest and most widely cited named-company examples of a deepfake attack aimed specifically at a senior executive's own organization (rather than an external victim), surfacing in the same period as the successful HK$200m/$25M Arup deepfake video-conference fraud (Hong Kong, Feb 2024). It shows deepfake social engineering evolving from single-person voice-clone phone calls into layered, multi-persona video-meeting impersonation that blends a spoofed messaging profile, a live voice clone, and repurposed public video, raising the perceived credibility of the con.
It also demonstrates that any public figure's existing media footprint (interviews, YouTube appearances, press photos) is now viable raw material for impersonation, and that attackers are consciously targeting internal, senior staff with psychologically tailored pretexts ("help me set up a new business") rather than the generic financial lures used against consumers.
Finally, it is a rare publicized case where human suspicion, not a technical deepfake-detection tool, is credited with stopping a technically sophisticated AI-enabled attack, reinforcing that verification culture remains the primary defense even as synthetic media improves.
WPP's response was a proactive internal-awareness email from CEO Mark Read to leadership, explicitly telling staff "just because the account has my photo doesn't mean it's me" and warning that attackers now "go beyond emails to take advantage of virtual meetings, AI and deepfakes." Read also flagged that senior leaders face more tailored, "psychological" attacks than the scams that target the general public, implying a need for leadership-specific training rather than generic phishing awareness.
WPP's spokesperson credited "the vigilance of our people, including the executive concerned" as the actual control that stopped the fraud: the targeted individual's own skepticism, not a technical control, defeated the attack. Industry write-ups of the case (Eftsure, Wells Insurance) draw the broader lesson of mandatory out-of-band verification for any unusual request to move money or "set up a new business," regardless of how convincing the accompanying video/voice appears, and treating meeting invites arriving via personal messaging apps (rather than corporate channels/calendars) as a red flag.
Social Engineering Examples. “WPP Deepfake CEO Scam Attempt”. Accessed 19 September 2026. https://socialengineeringexamples.com/wpp-deepfake-ceo-scam-attempt-2024
Fraudsters likely identified WPP CEO Mark Read as a high-value persona to impersonate, and selected an internal WPP "agency leader" as the actual fraud target, consistent with attackers using public sources such as press coverage, corporate leadership pages, and professional-networking profiles to map senior executives and reporting lines before making contact.
Senior-executive visibility (press coverage, corporate bios, professional-networking profiles) is very difficult to suppress at enterprise scale, so the realistic control is not hiding who the CEO or agency leaders are, but hardening the verification processes this information later gets weaponized against.
The attackers obtained a publicly available photograph of Read, per Guardian and Times of India reporting, to stand up a fake WhatsApp account in his name, and separately sourced existing public YouTube footage of a second, unnamed senior WPP executive to reuse as video material for the live call.
A single existing public photo or video clip cannot be reliably taken down or prevented from being reused, so the practical defense is the awareness message Read himself sent staff: a familiar photo or face on a call "doesn't mean it's really them," shifting the burden to skepticism at the point of contact rather than prevention of the asset's existence.
Consistent with the FT/Guardian reporting of an "AI voice clone," the attackers likely used a commercially available voice-cloning service trained on the second executive's public audio (interviews, talks, or other YouTube appearances) to generate a synthetic voice track to pair with the repurposed video footage.
Commercial voice-cloning and video-synthesis tools are broadly available and cannot be blocked by a target organization, so defenses shift downstream to requiring identity verification that does not depend on how convincing a voice or video sounds or looks.
Using the fake WhatsApp account bearing Read's photo, the fraudsters made contact and arranged what appeared to be a legitimate Microsoft Teams meeting involving Read and the second senior executive.
Treating executive contact or meeting invitations that arrive through personal messaging apps like WhatsApp, rather than corporate channels or calendars, as an inherent red flag, and requiring confirmation through a known corporate channel before accepting the meeting.
On the Teams call itself, the attackers played the cloned voice and repurposed YouTube footage to simulate the second executive's real-time presence, while separately impersonating Read off-camera through the meeting's text-chat window, together manufacturing the appearance of an authentic two-executive meeting.
Mandatory out-of-band verification, such as calling back a known corporate number or confirming through a separate, previously established channel, before treating instructions delivered on a video call as genuine, regardless of how authentic the voice or video appears.
With the fabricated meeting's credibility established, the fraudsters pressed the actual target, a WPP agency leader, to help set up a "new business," a pretext WPP said was intended to lead to the extraction of money and personal details; the attempt ended here when the target grew suspicious and refused, before any funds or data changed hands.
In this case, WPP credited the targeted employee's own vigilance and skepticism about the "new business" request as the control that actually stopped the fraud; the broader lesson industry write-ups draw is mandatory, policy-level verification for any request to move money or establish a new business relationship that arrives through an unconventional or high-pressure channel.
Browse by what this case has in common with others in the library.
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
JLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling…