
- In Feb 2024, every executive on a video call was fake except one employee. The synthetic "CFO" approved 15 wire transfers — $25.6M gone to 5 Hong Kong accounts. The training data to fake those faces cost under $50. This is the new wire-fraud playbook. 🧵
- The Arup breach wasn't a technology failure. It was a process failure exploited by convincing tech. Attackers harvested public YouTube, conference and LinkedIn footage of execs, trained voice and face models on consumer GPUs, then joined a routine Zoom call.
- Here's the part most "deepfake detection" misses. The attackers didn't hold a screen up to a webcam. They used virtual-camera software (OBS VirtualCam, the open-source Deepfake Offensive Toolkit) to inject synthetic frames straight into the Zoom stream.
- That distinction is everything. A presentation attack puts a fake in front of a real camera — liveness checks can catch it. An injection attack bypasses the camera; the app treats the synthetic feed as real hardware. Most tools are built for the wrong attack.
- The tools that do work are weaker than the demos suggest. Lab benchmarks claim 96-99% accuracy. Purdue's real-world benchmark put it at 50-65%. You cannot stake a $25M wire on a probabilistic alert that's barely better than a coin flip.
- Humans are no better — trained employees spot deepfakes at ~50%, a coin flip. Meanwhile fraud scaled: Pindrop logged a 1,300% surge in 2025, average enterprise loss ~$680K. Faking a video now starts at $50. Attack and defense costs have fully diverged.
- Then the backstop vanished. Since Jan 2026, standard cyber policies explicitly exclude "AI-generated intermediaries." The loss is uninsured — and a $25M hit clears the SEC materiality bar, so you disclose it on an 8-K within 4 business days. Publicly.
- The vendor market won't save you. Reality Defender, Pindrop, iProov, GetReal each cover one slice — video vs audio vs liveness vs context. None covers all. And the Big 4 you'd call sell $500K policy decks, not detection. One tool, or one consultant, isn't a defense.
- The one control that stops every variant costs nothing: mandatory out-of-band verification. Any financial instruction over a set threshold confirmed via a pre-registered callback before execution. Detection adds confidence. Process adds certainty.
- This is what we build: vendor-neutral defense across video, audio, behavioral and out-of-band layers, mapped to EU AI Act Article 50 (live Aug 2, 2026) and SEC disclosure rules — then red-teamed with real injection attacks before criminals find the gap.
- If your wire-transfer controls still treat a video call as proof of identity, what's your actual stop on a synthetic CFO? Be honest — does your callback rule get enforced, or is it a doc nobody opens under deadline pressure? #DeepfakeFraud #CISO
- We wrote up the full attack mechanics, vendor landscape and layered defense for CISOs here: https://veriprajna.com/solutions/enterprise-deepfake-detection