
A fake CFO just stole $25.6 million from a real company. On a live video call.
In February 2024, an employee at engineering giant Arup joined what looked like a routine video conference. The CFO was there. Other senior leaders were there. Everyone looked and sounded exactly right.
Except none of them were real.
Every single person on that call was an AI-generated deepfake. The employee followed their instructions and made 15 wire transfers across five bank accounts before anyone realized what happened.
Here's what stopped us in our tracks when our team analyzed this case →
Arup's network was never hacked. No malware. No stolen passwords. No breach of their digital systems at all.
The attackers didn't break through the company's walls. They walked through the front door wearing perfect masks built from publicly available YouTube videos and conference footage.
This changes everything about how we think about security. When a face and a voice can be manufactured for almost nothing, "I saw them on the call" is no longer proof of anything.
The old question was "how do we keep attackers out?"
The new question is "how do we know who's actually in the room?"
Our research points to a layered approach → behavioral biometrics that track how people type and move, physiological signals that verify a live human is present, and out-of-band verification that doesn't rely on what you can see or hear.
But we're curious what you think.
If you got a video call tomorrow from your CEO asking you to transfer funds, and everything looked and sounded perfect, what would make you pause?
#DeepfakeFraud #EnterpriseSecurity #AITrust