Attackers put a deepfaked CFO and an entire fake executive team on one video call and walked away with $25.6 million.
That was Arup, February 2024. How it worked tells you which defenses matter and which are theater.
The fake faces weren't held to a webcam. Attackers used virtual-camera software to inject synthetic frames straight into the meeting's data stream — the app read it as a normal camera feed.
That distinction is everything. Most "deepfake detection" tools catch presentation attacks — a screen held to a lens. An injection attack bypasses the camera entirely, so those tools never see it.
The model that wore the CFO's face cost under $50, trained on footage scraped from YouTube and LinkedIn — $50 of synthesis against a $25.6 million transfer.
Detection alone wouldn't have saved that finance employee. In production it runs about 50–65% accurate (Purdue benchmark), not the 96%+ shown in the lab. You don't stake the company on a coin-flip alert.
What would have stopped it cost nothing: any wire above a set threshold confirmed through a pre-registered callback number first. No vendor purchase, effective against every variant.
Detection layers add confidence. Process controls add certainty. Since January 2026, standard cyber policies exclude deepfake fraud — so if it lands, the loss is uninsured.
Security teams: would your wire-approval process actually catch this — or does "I saw their face on the call" still count as identity verification?
#DeepfakeDefense #CISO
Published on Facebook · June 23, 2026
On social media
See this post on its original platform
In our archive