What happened
A staff member in the Hong Kong office of Arup, the British engineering firm, received a message that appeared to come from the company's UK-based chief financial officer about a confidential transaction [1][2].
The request was unusual enough to raise doubts, so it was followed by a video conference. On the call were the CFO and other colleagues the employee recognised. Every one of them was an AI-generated fake, built from material of Arup executives [1][2].
Reassured by the call, the employee made a series of transfers to five different Hong Kong bank accounts, totalling HK$200 million — roughly US$25 million [1].
Arup reported the fraud to Hong Kong police in early 2024. It was not publicly named as the victim until May that year, when it confirmed to the Financial Times that false voices and images had been used, and declined to give further details [1][2].
Note what did not happen: nothing was hacked. No system was breached, no password stolen, no malware involved. The entire attack ran on the assumption that seeing and hearing someone is the same as knowing who they are [1][2].
Where the same technology helps
The video and voice tools behind this are the same ones doing genuinely valuable work. They dub a film into forty languages. They give someone who has lost their voice a synthetic one built from old recordings. They let a small team produce training videos they could never have filmed. The technology has no opinion about which it is doing. What changed is not that a new kind of villain appeared. A cheap, general capability arrived in a world whose habits for checking who someone is quietly assumed it did not exist [1][2].
Where it burned
For most of living memory, a face and a voice on a live call were proof enough of who someone was — not because anyone reasoned it through, but because faking them live was too hard to be worth it. A great many business processes rested on that assumption, and it stopped being true without anyone updating the processes. The employee here was not careless. He did the thing careful people do: he was suspicious of an email, so he moved to a richer channel to check. That is exactly the move that used to work [1][2].
The tell
Verify identity through a channel the person contacting you does not control. If someone asks you to move money or send data, hang up and call them back on a number you already had.
Notice this check does not require you to spot the fake. Detection is a losing game — the fakes get better every quarter, and you only need to be fooled once. Calling back works whether or not the video was convincing, because it does not depend on your judgement of the picture at all. It depends on who owns the channel. It is like a bank that tells you to phone the number on the back of your card, never the one in the text message. Any process where the request and the confirmation travel through the same channel the attacker chose has no verification in it, however many people appear on the screen.
The check is a habit, and habits are trained. Catch the AI: verify before you trust is five days of exactly this — the difference between a check that touches something independent and one that does not.
Sources
Every source below was opened and read. Last verified 15 August 2026.
- [1] Scammers siphon $25M from engineering firm Arup via AI deepfake 'CFO' — Grace Noto, CFO Dive, 17 May 2024
- [2] Incident 634: Deepfake CFO scam at a multinational engineering firm — AI Incident Database (Responsible AI Collaborative), 2024