
A $25.6M wire transfer was approved on a video call where every face — except the employee taking it — was AI-generated.
That was Arup, February 2024. The finance employee in Hong Kong joined a routine call with familiar faces, familiar voices, a familiar CFO. All of it deepfaked. 15 wire transfers, five bank accounts, gone before anyone thought to call the real CFO's office.
Here's the part most security teams miss. The attackers didn't hold a screen up to a webcam — that's a presentation attack, and liveness checks catch it. They used virtual-camera software to feed synthetic frames straight into the Zoom stream. That's an injection attack, and most "deepfake detection" tools aren't built to see it. Injection attacks like this rose 255% in 2023; face-swap attacks, 704%.
So the uncomfortable math: real-world detection accuracy runs 50–65% (Purdue benchmark), not the 96% you see in lab demos. You cannot stake $25M on a probabilistic alert.
What actually stops this isn't a vendor — it's a process. When we design enterprise deepfake defense, the first control we add isn't a detection tool: it's a mandatory out-of-band verification step. Any financial instruction above a set threshold gets confirmed through a pre-registered callback number before execution. Costs nothing. Works against every variant of synthetic-media fraud.
And the deadline is real: since January 2026, standard cyber insurance policies explicitly exclude deepfake fraud. If it happens to you, the loss is uninsured.
Detection layers add confidence. Process controls add certainty. You need both — designed to work together, vendor-neutral.
One question worth raising with your team today: does your wire-approval workflow still treat a live video call as identity verification? If it does, you have the Arup gap. Save this before your next policy review.
#DeepfakeDetection #CISO #VideoCallFraud #SyntheticMedia #EnterpriseSecurity