Noesa
← The Casebook

Hong Kong · 2024

Everyone else on the video call was fake. He paid out $25 million.

A finance worker joined a conference call with his CFO and colleagues. Not one of them was a person.

Published 15 August 2026

What happened

A staff member in the Hong Kong office of Arup, the British engineering firm, received a message appearing to come from the company's UK-based chief financial officer about a confidential transaction [1][2].

The request was unusual enough to raise doubts, so it was followed by a video conference. On the call were the CFO and other colleagues the employee recognised. Every one of them was an AI-generated fake, built from material of Arup executives [1][2].

Reassured by the call, the employee made a series of transfers to five different Hong Kong bank accounts, totalling HK$200 million — roughly US$25 million [1].

Arup reported the fraud to Hong Kong police in early 2024. It was not publicly identified as the victim until May that year, when it confirmed to the Financial Times that false voices and images had been used, declining to give further details [1][2].

Note what did not happen: nothing was hacked. No system was breached, no password stolen, no malware involved. The entire attack ran on the assumption that seeing and hearing someone is the same as knowing who they are [1][2].

Where the same technology helps

The generative video and voice models behind this are the same ones doing genuinely valuable work — dubbing a film into forty languages, giving someone who has lost their voice a synthetic one built from old recordings, letting a small team produce training material they could never have filmed. The technology has no opinion about which it is doing. What changed is not that a new kind of villain appeared, but that a cheap, general capability arrived in a world whose verification habits quietly assumed that capability did not exist [1][2].

Where it burned

For most of living memory, a face and a voice on a live call were sufficient proof of identity — not because anyone reasoned it through, but because faking them in real time was too hard to be worth it. That assumption was load-bearing in a great many business processes, and it stopped being true without anyone updating the processes. The employee here was not careless. He did the thing careful people do: he was suspicious of an email, so he escalated to a richer channel to check. That is exactly the move that used to work [1][2].

The tell

Verify identity through a channel the person contacting you does not control. If someone asks you to move money or send data, hang up and call them back on a number you already had.

Notice this check does not require you to spot the fake. Detection is a losing game — the fakes get better every quarter, and you only need to be fooled once. Callback verification works whether or not the video was convincing, because it does not depend on your judgement about the picture at all; it depends on who owns the channel. Any process where the request and the confirmation travel through the same channel the attacker chose is a process with no verification in it, however many people appear on the screen.

Share this case

The image has the link printed on it, so it still leads back here.

The check is a habit, and habits are trained. Catch the AI: verify before you trust is five days of exactly this — the difference between a check that touches something independent and one that does not.

Sources

Every source below was opened and read. Last verified 15 August 2026.

  1. [1] Scammers siphon $25M from engineering firm Arup via AI deepfake 'CFO'Grace Noto, CFO Dive, 17 May 2024
  2. [2] Incident 634: Deepfake CFO scam at a multinational engineering firmAI Incident Database (Responsible AI Collaborative), 2024