Local AI Automation
AI Security

Everyone on the Call Was Fake: The $25 Million Arup Deepfake Scam

How a deepfake CFO on a video call convinced an Arup employee to send HK$200 million, and what the scam teaches businesses about trusting video.

Piyabhum Sornpaisarn9 min read
Share
Pixel art hero illustration — an abstract landscape of circuit traces and connected workflow nodes (artwork for "Everyone on the Call Was Fake: The $25 Million Arup Deepfake Scam")

Everyone on the Call Was Fake: The $25 Million Arup Deepfake Scam

The video call looked completely normal.

That was the whole problem.

In early 2024, a finance employee at Arup — the engineering firm behind the Sydney Opera House and Beijing's Bird's Nest stadium — sat down in the company's Hong Kong office and joined a video conference. On screen were the company's UK-based chief financial officer and several other senior executives. People he recognized.

Their faces moved. Their voices sounded right. On screen, the executives laid out the details of a confidential transaction the company needed to make.

Everything about the call said trust this.

So he did.

By the time anyone realized the truth, the employee had pushed HK$200 million — about US$25.6 million — out of the company in 15 transfers.

The catch: everyone else on that call was a deepfake.

Direct answer

In early 2024, scammers used AI deepfakes of Arup's CFO and other executives in a video conference, convincing a Hong Kong finance employee to authorize 15 transfers totaling about US$25.6 million. The fake faces and voices were built from publicly available video and audio, and the attack never touched Arup's IT systems. The lesson: video can no longer be trusted as proof of identity — verify any request that moves money through a second channel.

The Call That Erased Every Doubt

The scam started with messages. The employee received communications that appeared to come from the CFO, asking him to carry out a secret transaction.

And here is the detail that makes this case human: at first, the employee was suspicious. The messages looked like phishing. Something felt off.

Then came the video call.

Hong Kong police later described what happened next. The employee joined a multi-person video conference where everyone else on screen was an AI recreation. The fake executives looked and sounded so much like the real people that the employee's doubts simply dissolved. As police put it, he dropped his concerns after the call because the participants looked and sounded just like colleagues he recognized.

That is the entire fraud, in one sentence. No hacked systems. No stolen passwords. Just a person who checked with his own eyes and ears, and saw exactly what he expected to see.

The money went out in 15 transfers. Hong Kong media reported the payments landed in five local bank accounts.

The Discovery

The fraud only came to light when the employee later checked with the company's headquarters — and learned that no such transaction had ever been authorized.

Hong Kong police received the report on January 29, 2024. By then, the full HK$200 million had already left the company.

Police went public in early February, describing one of the first cases of its kind in the city. Acting Senior Superintendent Baron Chan Shun-ching, of the force's cybersecurity division, gave reporters a line that still lands hard today:

"In the multi-person video conference, it turns out that everyone he saw was fake."

Chan also explained how the criminals built their cast. "Scammers found publicly available video and audio of the impersonation targets via YouTube," he said, "then used deepfake technology to emulate their voices... to lure the victim to follow their instructions."

One more detail worth noting, because it changes how people picture the attack: the fake videos were pre-recorded. They did not involve live dialogue with the victim. The criminals did not need real-time AI conversation. A few convincing clips of familiar faces, played back in the right order, were enough.

At the time of the February briefing, police said no arrests had been made in the case. Hong Kong media later reported that some of the money had been intercepted or recovered, though authorities have shared few details about how much.

A Company the World Knows

For three months, nobody outside the investigation knew which company had been hit. Police do not name victims during active cases.

Then, in May 2024, the Financial Times reported that the victim was Arup — the British engineering and design firm founded by Ove Arup in 1946, responsible for landmarks the whole world recognizes. Its Hong Kong office, opened in 1976, is the firm's largest practice in Asia Pacific. Arup confirmed the incident publicly within a day.

Its statement was calm, precise, and honest:

"Back in January, we notified the police about an incident of fraud in Hong Kong. Unfortunately, we can't go into details at this stage as the incident is still the subject of an ongoing investigation. Our financial stability and business operations were not affected and none of our internal systems were compromised."

That last clause matters. The attack did not touch Arup's IT systems. No firewall was breached. No software failed. The criminals walked through the front door in the shape of the people who are normally allowed to hold it open.

Rob Greig, Arup's global chief information officer, added: "Like many other businesses around the globe, our operations are subject to regular attacks, including invoice fraud, phishing scams, WhatsApp voice spoofing, and deepfakes. What we have seen is that the number and sophistication of these attacks has been rising sharply in recent months."

He called it "an industry, business, and social issue."

How Do You Fake a Person?

A deepfake is media made by AI that shows a real person doing or saying something they never did. The word itself comes from a Reddit user who, in 2017, posted AI-generated face swaps. What started as a novelty is now cheap, fast, and convincing.

Face swapping works like a digital mask. Software trains on many photos or video frames of a target person. Then it paints that person's face over someone else's, frame by frame, adjusting for lighting and angle. The more public footage of you that exists, the better the mask.

Voice cloning is the same idea for sound. A model listens to short recordings of someone speaking and learns the shape of their voice — the pitch, the rhythm, the accent, the way they pause. Then it can read any new sentence in that voice.

In the Arup case, police said the criminals simply pulled publicly available video and audio from YouTube and fed it into deepfake tools. No inside help. No stolen recordings. The raw material was already online.

Two more terms matter here.

First, real-time deepfakes. Open-source tools exist that can face-swap live video as it streams, which has researchers warning about interactive fake video calls. Worth remembering, though: the Arup attackers did not even need that. Pre-recorded clips did the job.

Second, cheapfakes. Not every fake is AI. Slowing down a clip, cutting away context, reusing old audio under new headlines — these low-tech edits fool plenty of people without any machine learning at all.

The cost of all this is the uncomfortable part. Face-swap software is available for free. Voice cloning services charge a few dollars a month. The barrier to entry for impersonating an executive is now essentially a laptop and some patience. AI went from a tool businesses deliberately adopt to infrastructure everyone — including attackers — is exposed to, which is quietly reshaping which AI business models survive.

This is why "I saw them on camera" no longer ends an argument.

This Was Not the First Time

The Arup case grabbed headlines because the amount was enormous. But it sits on a longer timeline.

In 2019, the CEO of a UK energy subsidiary received a phone call from what sounded exactly like his boss, the head of the German parent company. The voice asked him to wire about €220,000 (roughly US$243,000) to a Hungarian supplier. He did. The Wall Street Journal reported it as one of the first known cases of AI voice spoofing used in a major fraud.

In 2020, a bank manager in Hong Kong authorized about US$35 million in transfers after calls from someone who sounded like a company director he knew and had done business with. The voice was cloned. The case only became public in 2021, when investigators described it to Forbes.

Then 2024 turned into a highlight reel:

  • WPP — the world's biggest advertising group — said criminals used publicly available footage of CEO Mark Read, combined with a cloned voice, to set up a fake Teams meeting and impersonate him. The attempt failed.
  • LastPass — employees were targeted with deepfake audio of the company's CEO, sent through WhatsApp. The unusual channel tipped people off, and nothing was lost.
  • Ferrari — an executive got WhatsApp voice notes from someone who sounded like CEO Benedetto Vigna, describing a big confidential acquisition. Suspicious, the executive asked a question only the real Vigna could answer. The caller hung up.

And in the same February 2024 briefing where police described the Arup case, they revealed something wider: six people had been arrested in connected scams, stolen Hong Kong ID cards had been used to make 90 loan applications and open 54 bank accounts, and on more than 20 occasions AI deepfakes had slipped past facial-recognition checks.

A year later, an Arup chief told the World Economic Forum the lesson bluntly: "This happens more frequently than people realize."

What Businesses Should Do

No single tip stops this. But a few rules make the attack much harder.

Verify through a second channel. The rule is simple: a request that moves money gets confirmed on a different channel than the one it arrived on. Video call asks for money? Call back on a number you already know. Message asks for money? Confirm in a video call. Never verify using the same door the request came through.

Make big payments a two-person job. The Arup employee could move HK$200 million alone. Payment approval rules — two approvers, amount limits, segregated duties — would have added a human checkpoint exactly where the scam depended on one person's judgment.

Use pre-agreed code words. Ferrari's defense was a version of this: a shared question only the real person could answer. For companies, a simple rotating code phrase confirmed out of band costs nothing and defeats a pre-recorded video completely.

Assume your executives are already "on tape." Anyone who has spoken in a recorded earnings call, a podcast, or a conference video has given scammers their raw material. Treat every executive's voice and face as public data — because they are.

Report fast. Arup notified police promptly and went public with a clear statement. That candor helped other companies recognize the same pattern.

What Individuals Should Do

The same tricks target families, not just firms.

Voice cloning has powered a wave of "emergency" scams: a parent gets a call from a voice that sounds exactly like their child, panicking, needing money immediately. The voice is built from clips the person posted online.

Three habits help:

Set a family code phrase. A word or inside joke that only your family knows. If a caller cannot produce it, the call ends.

Hang up and call back. If a "family member" or "bank" calls with an urgent money request, end the call and dial the number you already have. Real people and real institutions accept this.

Slow down. Urgency is the scammer's favorite tool. Real emergencies can survive a five-minute check. Fake ones usually cannot.

FAQ

What is the Arup deepfake scam? In early 2024, an Arup finance employee in Hong Kong joined a video call where the CFO and other executives appeared as AI-generated deepfakes. Convinced the call was real, he authorized 15 transfers of about HK$200 million (US$25.6 million).

How did the deepfakes fool the employee? The scammers used publicly available video and audio of the executives, likely from YouTube, to build face-swapped and voice-cloned fakes. Police said the videos were pre-recorded. The employee was initially suspicious of the messages, but the video call — familiar faces and voices — removed his doubts.

Was anyone arrested, and was the money recovered? Hong Kong police said in February 2024 that no arrests had been made in the Arup case itself, though six people were arrested in connected scams. Media later reported that some of the funds were intercepted or recovered, but authorities have shared few details on how much.

How can businesses protect against deepfake scams? Verify money-moving requests through a second channel, require two approvers for large payments, use pre-agreed code words for voice and video confirmation, and treat executives' recorded voices and faces as public data that scammers can copy.

Are deepfakes like this common now? Similar scams hit a UK energy firm in 2019 (€220,000) and a Hong Kong bank in 2020 (US$35 million). In 2024, WPP, LastPass, and Ferrari all reported deepfake impersonation attempts, and Hong Kong police noted deepfakes had slipped past facial-recognition checks more than 20 times.

The Real Lesson

For a century, the strongest proof we had was the human face. "I saw it with my own eyes." "I heard it from his own mouth."

That proof is gone.

The Arup employee was not stupid, and he was not careless by the standards of 2023. He checked. He saw familiar faces. He heard familiar voices. Everything we were ever taught to trust, he trusted.

The world just changed the rules on him — on all of us — without an announcement.

The new rule is not "trust nothing." It is this: for anything that involves money, verify through a different door than the one the request came through. A different channel. A different device. A question only the real person could answer.

Seeing is no longer believing. Process is.

Newsletter

Get the next guide in your inbox

New articles plus the workflow files from each guide — and instant access to the free download library.

No spam. Unsubscribe anytime.

Related posts