In February 2024, a finance employee at the Hong Kong office of the British engineering group Arup received a message purporting to be from the company's UK-based chief financial officer about a confidential transaction.
The employee's first reaction was suspicion - it looked like phishing. Then came the video call. On the screen: the CFO, speaking, plus several other colleagues the employee recognized. Their faces, their voices, their mannerisms. The doubt dissolved.
Over the following days the employee made 15 transfers totaling about HK$200 million - roughly US$25.6 million - to five local bank accounts. Every person on that call except the victim was an AI-generated deepfake. The fraud surfaced only when the employee later checked with head office.
Hong Kong police called it one of the largest deepfake frauds on record. Arup confirmed it was the victim and said its systems and data were not compromised - the attack never touched a firewall. It went through a person.
The Deepfake - a 25-minute interactive module where learners face the same pressure, make the call, and drill out-of-band verification until it is reflex.
Get team accessPlay the free demo