The $25 million video call — how deepfake scams actually work
A finance worker joined a routine video call with his CFO and his colleagues. Every face on the screen except his own was fake. Here is exactly how it happened — and the one habit that would have stopped it.
In early 2024, a finance employee at the Hong Kong office of Arup — the global engineering firm that helped build the Sydney Opera House — received an email from the company's UK-based chief financial officer about a confidential deal. It had the hallmarks of a scam, and he nearly ignored it. Then he was invited to a video call. The CFO was on it. So were several colleagues he recognized. They looked right. They sounded right. Reassured, he followed their instructions and sent 15 wire transfers totaling about 25 million dollars. Every single person on that call, except him, was a deepfake.
What actually happened
The email arrived first, mentioning a secret transaction. The employee later said it raised his suspicions — it had the feel of a phishing message, the kind staff are trained to distrust. So far, he was doing everything right.
What changed his mind was the video call. On screen were people who looked and sounded exactly like his chief financial officer and other colleagues he knew. In the face of that, his doubts dissolved. Over the course of a single day he made 15 transfers worth roughly 25 million dollars (about 200 million Hong Kong dollars) to accounts the attackers controlled.
Nobody caught it in the moment. The fraud only came to light when the employee later checked in with the company's head office about the transaction — and discovered no such meeting, and no such instruction, had ever happened. Investigators concluded the attackers had built the fake executives using real video and audio of them, harvested from online meetings and public appearances.
What a deepfake actually is, in plain terms
A deepfake is media — video, audio, or both — generated by AI to show a real person saying or doing something they never said or did. The model studies enough examples of someone's face and voice to produce a convincing synthetic version it can puppet in new footage.
A few years ago this needed a research lab and a lot of source material. Today it needs a laptop, some off-the-shelf software, and a few minutes of footage of the target. And here is the uncomfortable part: executives hand over that footage constantly. Every conference talk, podcast, earnings call, webinar, and company video is training data. The more public and trusted a person is, the easier they are to fake.
Why a smart person still fell for it
It is tempting to think the employee was careless. He was not. He spotted the suspicious email and hesitated — exactly the instinct security training tries to build. What defeated him was that the attackers escalated to the one thing we all treat as proof: a live video call with familiar faces.
Three forces did the work. Authority — the request appeared to come from the CFO, and people comply with senior leaders. Urgency — the deal was framed as confidential and time-sensitive, which shuts down careful thinking. And social proof — it was not one fake person but a whole room of trusted colleagues, all seeming to agree. Our brains are wired to trust a face and a voice. The scam was engineered to exploit exactly that wiring.
The raw material is already public — and you can't take it back
The instinct after a story like this is to ask how to detect the fake. That is the wrong place to start, because the ingredients are already out in the world. Your leaders' faces and voices are on the internet, and they cannot be recalled. Telling executives to stop appearing in public would be both impossible and self-defeating.
So the defense cannot depend on spotting a flawless fake in real time. It has to assume that a convincing impersonation is always possible — and make that impersonation useless. The question is not "can I tell this is fake?" It is "even if this looks completely real, can it actually move money or data on its own?"
Why "just spot the deepfake" is a losing strategy
Tools that detect deepfakes do exist, and they have a role. But betting your money on them is a losing game for two reasons.
First, the technology that makes fakes is improving faster than the technology that detects them. Every detector becomes a training target for the next generation of fakes. Second, even if a subtle artifact exists — a flicker at the jawline, a half-beat of audio lag — you cannot expect a stressed employee on a Friday afternoon to catch it while a video of their boss is giving them instructions. Security that depends on people performing forensic analysis under pressure is not security. It is hope.
The one control that would have stopped it
The scam works only because one person, convinced by what they saw, could move millions on their own. Remove that single point of failure and the whole attack collapses — no matter how perfect the fake.
The control is out-of-band verification: confirming any unusual or high-value request through a separate, trusted channel before acting. Not a number from the email. Not a person on the suspicious call. A known channel you already had — calling the CFO back on the number in your company directory, or walking to a colleague's desk.
Layered on top of that are basic money-movement controls: a second approver for wire transfers above a threshold, mandatory callback procedures for payment changes, and limits that no single employee can override. With those in place, the fake call could have been flawless and still failed, because the money simply could not move on one person's say-so.
What to actually do
For individuals, especially anyone who can move money or change sensitive settings:
Stop treating video and voice as proof of identity — that era is over. If a request is unusual, urgent, and secret, treat those three together as a warning, not a reason to hurry. Verify any payment or sensitive change through a second channel you trust before you act.
For finance and operations teams: require dual authorization for wire transfers above a sensible limit. Put a mandatory callback step on any new or changed payment details. Agree on a verification phrase or process for executive payment requests. And train accounts-payable staff specifically on this scenario — generic phishing training did not prepare anyone for a video call full of fake executives.
The goal is simple: build a process where being fooled by a fake is not enough to cause a loss.
This is the beginning, not the peak
The Arup case is notable because of the amount and the use of a full video call, but the underlying technique is spreading fast and getting cheaper. Cloned voices are already powering "family emergency" phone scams, where a parent hears their child's voice begging for help. Real-time face-swapping on calls is improving. The targets will keep widening from large companies down to small businesses and individuals.
The lesson generalizes well beyond deepfakes. When seeing and hearing can no longer be trusted on their own, trust has to come from process — verification, separation of duties, and channels that an attacker cannot fake — rather than from perception. Build that habit now, while it still feels slightly paranoid. It will feel like common sense soon enough.