Every person on that video call was fake, and the wire went through anyway#
In January 2024, a finance employee in Arup’s Hong Kong office received an email that looked like it came from the engineering firm’s UK-based CFO, requesting a confidential transaction. He was skeptical, as he’d been trained to be. Then he joined a video call to confirm it, and saw the CFO, along with several familiar colleagues, discussing the deal in real time. His doubt dissolved. Over the course of that day he authorized 15 wire transfers totaling $25.6 million.1
Every face and voice on that call was an AI-generated deepfake, built from publicly available conference footage and interviews of Arup’s own executives. As Hong Kong police put it afterward, “everyone he saw was fake.”1 No one has been arrested, and the money hasn’t been recovered.
Six months later, an executive at Ferrari got a different kind of test. WhatsApp messages from an unfamiliar number, apparently from CEO Benedetto Vigna, described an urgent acquisition and pushed him to sign an NDA fast. A follow-up call carried a startlingly accurate clone of Vigna’s voice, accent included. Something about the tone still felt off, so the executive asked one question the caller couldn’t script: the title of a book Vigna had recommended to him days earlier. The line went dead.2
One of those stories is a $25 million loss and a live case study in a law-enforcement file. The other is a near-miss that a single well-placed question turned into a save. The gap between them is not better technology. It’s whether the organization had already decided, before the call ever came in, that a familiar face and voice would never be sufficient authorization on their own.
Why 2026 is the year this stopped being a hypothetical#
Deepfake fraud has been technically possible since well before Arup. What changed by mid-2026 is that it graduated from notable incident to tracked category, at scale.
For the first time in the IC3’s 25-year history, the FBI’s 2025 Internet Crime Report broke out AI-enabled fraud as its own line item: 22,364 complaints and $893 million in losses, a figure the Bureau itself describes as a conservative floor given how much AI-assisted fraud still gets filed under ordinary BEC or investment-fraud categories.3 Business email compromise overall accounted for $3.05 billion across nearly 25,000 incidents, an average of $123,000 per case, and the report specifically calls out voice clones of executives confirming wire instructions and AI-generated personas conducting fake video job interviews as emerging techniques inside that number.3
Gartner saw this coming. Back in February 2024, it predicted that by 2026, deepfakes would push 30% of enterprises to stop trusting identity verification and authentication solutions in isolation.4 That’s this year. The prediction wasn’t about some future capability; it was about this specific one landing on schedule.
The rest of the market data tells a consistent story:
- Volume is industrial, not artisanal. CEO deepfake fraud attempts now target an estimated 400 companies a day, and US deepfake-enabled fraud losses reached roughly $1.1 billion in 2025.5
- Deepfakes are becoming a standard fraud vector, not an edge case. Sumsub’s identity fraud research puts deepfakes at 6.5% of all fraud attempts globally in 2026, up from 0.1% in 2022. That’s a 65x increase in four years.6
- The audio bar for a convincing clone keeps dropping. Commercial voice-cloning tools now produce a usable impersonation from as little as 3 to 30 seconds of source audio, which almost any executive has already put on the public record through an earnings call, a conference keynote, or a podcast.7
- When it lands, it’s not cheap. Organizations that suffer a voice-deepfake incident lose an average of $600,000, and 23% lose more than $1 million.8
None of this requires nation-state capability. It requires a LinkedIn profile, an earnings call recording, and a commercial tool anyone can subscribe to.
Why the old playbook doesn’t catch this#
Most security-awareness training still teaches people to spot phishing by its tells: a mismatched sender domain, an urgent tone, a typo, a link that doesn’t quite match the brand. Deepfake-enabled fraud removes every one of those tells. The email may be clean. The voice is correct. The face on the call is one the target has seen in real meetings for years. What used to require the victim to override obvious suspicion now requires them to override the evidence of their own eyes and ears, which is a much higher bar for an employee working from a training deck built for 2019.
The Arup case is the clearest illustration of why this matters at the control level, not just the awareness level. The employee’s skepticism was correct. His procedure was not: he treated a live video call as sufficient confirmation for a set of financial transactions, because nothing in his organization’s process told him it shouldn’t be. Ferrari’s executive had the same emotional pressure applied, and the difference was a control that didn’t rely on judgment under pressure at all, a piece of shared knowledge the caller couldn’t have.
There’s also a second exposure most finance-fraud conversations miss: identity. The FBI’s report specifically flags AI-generated personas conducting fake video job interviews as a technique now being used to gain network access, with roughly $13 million in documented losses tied to voice and video spoofing during hiring processes in 2025.3 If your recruiting pipeline is a route into your network, and increasingly it is, this isn’t only a CFO problem. It’s an HR and IT problem too.
The gap between board awareness and operational readiness#
Deepfake fraud has clearly reached the board’s attention; it makes the risk-register conversations now, in a way it didn’t two years ago. Operational readiness hasn’t caught up. Roughly 80% of companies still have no deepfake-specific incident response plan, and 32% of leaders say they have no confidence their employees could recognize a deepfake attempt if one arrived today.8
That gap is the actual risk. It’s not that the technology is unstoppable. It’s that most organizations have not yet converted “we know this is a threat” into a written procedure that a finance employee under pressure, at 4pm on a Friday, with a real-looking CFO on the call, can follow without having to make a judgment call in real time.
What the organizations that don’t become the next case study are doing#
The controls that actually hold up against this threat are boring, procedural, and cheap relative to a $25 million loss. None of them depend on being able to detect a deepfake in real time, which is the right design choice, because detection is a losing arms race and verification is not.
- Out-of-band callback verification, every time. Any request for a payment, credential change, or access grant that arrives by video, voice, or message gets confirmed through a separate channel, to a number already on file, never a number supplied in the request itself.
- Pre-agreed passphrases for high-risk teams. Finance, HR, and executive assistants carry a rotating verbal codeword that any executive must supply before an out-of-cycle transaction request is honored. It’s the corporate version of the Ferrari question, made systematic instead of lucky.
- Dual approval and a mandatory delay above a set threshold, with no override by seniority. If the rule is “any transfer over $X requires two approvers and a 24-hour hold,” that rule has to survive a CEO who appears to be personally, urgently overriding it. That’s precisely the scenario deepfake fraud is built to create.
- Redefine what “authorized” means. The clean fix is procedural, not technological: no financial transaction or access change is authorized by voice or video alone, full stop, regardless of how convincing the caller is.
- Put deepfake scenarios into the incident-response tabletop you already run. Most tabletops still rehearse ransomware and phishing. Very few rehearse “the CFO calls and it isn’t the CFO.”
- Treat detection tooling as a second layer, not the plan. Vendors in this space (Reality Defender, Adaptive Security, and others) add real value, but a detection product bought after this year’s board meeting doesn’t substitute for the callback and codeword controls above, which work even against a deepfake good enough to fool the tool.
What to actually decide this quarter#
- Confirm, in writing, that your organization has a mandatory out-of-band verification step for any unusual payment or access request, and that it has no seniority-based exception.
- Set the dollar threshold and time delay for dual approval, and pressure-test it against the exact scenario Arup lived through: an apparently real executive insisting it can’t wait.
- Ask your recruiting and IT onboarding teams whether video interviews and remote-hire identity checks have any deepfake-specific verification at all. For most companies today, the honest answer is no.
- Run one tabletop exercise this year built around a deepfaked executive call, not a phishing email.
- Name an owner for this risk. Right now, in most organizations, no single function is accountable for deepfake fraud specifically, it sits in the gap between the CISO, the CFO, and HR.
The strategic read#
The technology that makes this threat possible isn’t going to get less convincing, and detection tools will never close that gap completely; they’re chasing a target that improves every quarter. What separates Arup’s outcome from Ferrari’s wasn’t better software. It was whether a simple, low-tech verification step existed before the call came in.
That’s the useful news buried in an otherwise unsettling set of numbers. This is a threat that responds to procedural discipline more than it responds to budget. The organizations that avoid becoming next year’s case study will be the ones that treat “no transaction is authorized by voice or video alone” as a governance decision made this quarter, not a lesson learned after their own version of that January phone call.
CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’” and “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee”. ↩︎ ↩︎
MIT Sloan Management Review, “How Ferrari Hit the Brakes on a Deepfake CEO”. ↩︎
FBI Internet Crime Complaint Center, 2025 IC3 Annual Report; coverage via SecureWorld and Malwarebytes. ↩︎ ↩︎ ↩︎
Gartner, “Gartner Predicts 30% of Enterprises Will Consider Identity Verification and Authentication Solutions Unreliable in Isolation Due to AI-Generated Deepfakes by 2026” (February 2024). ↩︎
Sumsub, “More Sophisticated, and More AI-Driven, Than Ever: Top Identity Fraud Trends to Watch in 2026”. ↩︎
CybelAngel, “Voice Cloning Is the New BEC: Deepfake CEO Fraud in the US”. ↩︎
Adaptive Security, Deepfake Statistics 2026: The Data Security Leaders Need to Know. ↩︎ ↩︎
