SubscribeBTCSCAMWallet Test
Front page / Deepfake fraud · Hong Kong
highDeepfake fraud · Hong Kong

How a deepfake video call cost engineering firm Arup $25 million

A Hong Kong finance clerk joined a routine video meeting with his 'CFO' and colleagues. Every face on the screen was AI-generated. He wired HK$200 million before anyone realized.

DP
Dev Patel
Staff Reporter · MAY 16, 2024 · 5 min read
Painting: Renaissance archive · Source: CNN Business

The message that started it looked mundane. In mid-January 2024, a finance employee in the Hong Kong office of Arup — the London-headquartered engineering group whose past projects include the structure of the Sydney Opera House and Beijing's 'Water Cube' aquatics center — received a note purporting to come from the firm's UK-based chief financial officer, describing a confidential transaction, per CNN and the South China Morning Post. The worker was uneasy, but agreed to join a video call to discuss it.

On the call sat people the employee recognized: the CFO and several colleagues, looking and sounding exactly as they should, per Hong Kong police accounts reported by CNN. What he could not tell was that he was the only real human present. Every other participant was a deepfake — AI-generated video and audio modeled on genuine Arup staff. Reassured by the familiar faces and voices, he did as he was told.

Over roughly a week in January, he made 15 transfers totalling HK$200 million — about US$25 million — to five Hong Kong bank accounts, per figures police gave reporters. The scheme unravelled only when the employee later checked in with head office. Arup confirmed to the Financial Times that fabricated voices and images had been used, while stressing that its own systems were not breached and its finances were unaffected.

Why the call worked

Business-email-compromise fraud once hinged on a single spoofed email that an alert employee might question. The Arup case shows how generative AI strips away that friction. Attackers can build convincing avatars from material executives themselves make public — conference talks, recorded panels, media interviews — then stage a live 'meeting' that manufactures the social proof of seniority and consensus. The pressure to comply becomes almost irresistible.

Speaking publicly after the loss, Arup's global chief information officer, Rob Greig, said the firm faces a rising volume and sophistication of attacks and urged other companies to treat the case as a warning, per reporting on the incident. As of that reporting, no arrests had been announced, no suspects publicly identified, and none of the money recovered. Hong Kong police disclosed the case in February 2024 without naming the victim; Arup was identified only in May.

**Protect your finance team** - Verify unusual or urgent payment requests through a separate, known channel — call back on a saved number, never one supplied in the request. - Treat secrecy and time pressure as red flags; a legitimate transaction survives a pause and a second approver. - Don't let live video or voice 'confirm' identity — deepfakes now clone both. Ask something only the real person would know. - Require multi-person sign-off and out-of-band confirmation for large or first-time transfers. - Limit how much executive audio and video you publish; it is raw material for clones.

The wider lesson, security researchers stress, is that 'seeing and hearing' is no longer proof of identity. When a face and a voice can be fabricated in real time, controls have to live in process — verification, dual authorization, and a culture where pausing a payment is never punished.

— Sources: [CNN Business](https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk) · [CFO Dive](https://www.cfodive.com/news/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai/716501/)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING