
In January 2024, a finance employee at global engineering firm Arup dialled into what looked like an ordinary video call. The company's CFO was there, alongside several familiar colleagues. Over the course of that call, the employee authorised fifteen separate wire transfers totalling $25.6 million. Every face on the screen and every voice in the room was generated by artificial intelligence. No real executive was ever on the line.
The case, reported by CNN and later detailed by Fortune, isn't an isolated curiosity — it's a preview of a fraud category now hitting organisations of every size, every week. For leaders who have spent years training staff to spot suspicious emails, the uncomfortable truth is that the newest threat doesn't arrive as text on a screen. It arrives as a voice you recognise and a face you trust.
How a Deepfake Wire Transfer Actually Happens
Deepfake fraud rarely begins with the fake itself. It begins with research most executives never think to guard against — earnings calls, keynotes, podcast interviews, even routine social videos, all become raw material. Voice-cloning tools now need as little as three seconds of audio to produce a convincing replica of someone's voice, and video-generation models can replicate facial movement well enough to survive a live call.
The attack typically follows a four-step chain: reconnaissance, where public appearances train the AI likeness; lookalike contact, where a compromised inbox or a domain one character off from the real one manufactures urgency; the cloned call itself, where the fabricated executive — sounding appropriately stressed — requests an urgent transfer and asks that legal not be looped in; and a fabricated social profile, deployed afterward to make the impersonation look consistent if anyone checks.
That sequencing matters. The greatest vulnerability isn't the sophistication of the deepfake — it's the pressure applied in the minutes before it appears.
The Financial Scale Is Bigger Than Most Boards Realise
The Arup case is dramatic precisely because the number is so large, but it sits inside a much bigger pattern. The FBI's Internet Crime Complaint Center attributed more than $4.6 billion in business email compromise losses to 2024 alone, and voice-cloning-assisted fraud is described as its fastest-growing subset.
More concerning for risk officers: fewer than 5% of victims are believed to report these incidents, whether from embarrassment, reputational concern, or uncertainty about which authority to notify. That gap means publicly disclosed figures likely understate true exposure — a detail that should inform how conservatively finance teams treat their own assumed risk.

Why Spotting the Fake Is No Longer a Reliable Defence
For years, security training has centred on teaching employees to notice something "off" — a stilted voice, an unnatural pause, a wrong background. That advice is aging quickly. Deepfake generation has improved to the point where, in a live, time-pressured call, most employees simply cannot distinguish a synthetic executive from a genuine one.
That shift matters for how businesses allocate security budgets. Detection-based training still has value, but it can no longer be the primary control. The primary control has to be procedural, not perceptual.
The One Habit That Actually Stops It
The defence that reliably works is deceptively simple: independent-channel verification. If a request for an urgent wire transfer arrives — by call, video, or message — the recipient hangs up and calls back on a number already saved in the company directory, never a number supplied during that conversation.
Making this effective requires a formal protocol, not a habit left to individual judgement. Businesses should set a mandatory callback threshold, so any payment above an agreed value triggers second-channel verification without exception, and remove discretion from the moment of pressure — "don't loop in legal" is itself a warning sign, not a reason to comply faster.
The same discipline extends beyond the C-suite. Family offices face a parallel threat, where a cloned voice claiming to be a relative in distress requests an urgent transfer.

Expert Perspective
What makes the Arup case instructive isn't the size of the loss — it's what it reveals about the assumptions companies still build their controls around. For two decades, "verify the person" effectively meant "recognise the voice" or "recognise the face." That assumption has quietly stopped being safe, and most corporate approval workflows haven't caught up.
The businesses most exposed right now aren't the ones with weak technology, but the ones with informal escalation paths, where a stressed-sounding executive on a video call can still talk a finance team past a control that exists on paper but isn't enforced in practice. Rebuilding it doesn't require a large technology investment; it requires treating voice and video as unverified by default, the way a business already treats an unsolicited email attachment.
Expect this category of fraud to keep growing before it plateaus. Cloning tools are getting cheaper, executive video content keeps expanding across podcasts and short-form platforms, and attackers are increasingly patient. Organisations that formalise callback verification now are positioning themselves ahead of a threat that is still accelerating, not behind one that has already peaked.
Key Takeaways
- Arup lost $25.6 million after a finance employee authorised 15 wire transfers on a video call where every participant was an AI-generated deepfake.
- Voice cloning needs as little as three seconds of public audio to produce a convincing replica of someone's voice.
- The attack chain: public research, a lookalike email, a cloned voice or video call, then a fabricated social profile for false consistency.
- The FBI attributed over $4.6 billion in business email compromise losses to 2024, with voice-cloning fraud its fastest-growing category.
- Fewer than 5% of victims report these incidents, so true financial exposure is likely understated.
- Spotting a deepfake in real time is no longer reliable — the technology has outpaced human perception on live calls.
- Independent-channel callback verification, above a fixed threshold with zero exceptions, remains the most effective control available.
Conclusion
Deepfake-enabled fraud is no longer a speculative risk confined to cybersecurity conference slides. It has already cost one engineering firm $25.6 million, and the tools required keep getting cheaper and more convincing. For business leaders, the practical response isn't new software — it's a governance decision: mandate independent verification for high-value transfers, remove exceptions, and revisit that policy as generative AI keeps advancing. Organisations that treat this as an operational standard now will be the ones least affected when the next call comes in.
Related Reading on Our Sites
- Cybersecurity & Risk Advisory Services
- AI Governance Consulting for Enterprises
- Business Email Compromise: A Board-Level Briefing
- Building Operational Security Protocols That Scale
- ZTS Infotech AI News Desk — Archive
External References
- CNN — reporting on the Arup deepfake fraud case
- Fortune — coverage of the Arup deepfake video call fraud
- FBI Internet Crime Complaint Center (IC3) — 2024 Internet Crime Report
-
Writen by Anirban Das
USA:
India: