← Back to list

Every Face on the $25 Million Video Call Was Fake

In early 2024, a finance employee at the engineering firm Arup sat through a video call with his CFO and several colleagues, took…

Mike McNelis in MeetCyber · 2026-07-17 09:54 · 0 claps · 5.0 min read
#cybersecurity #deepfakes #cfo
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Every Face on the $25 Million Video Call Was Fake

In early 2024, a finance employee at the engineering firm Arup sat through a video call with his CFO and several colleagues, took instructions to move money for a confidential deal, and made 15 transfers that added up to around $25 million. Every face on that call was fake. The CFO was AI-generated, and so were the colleagues nodding along. He had actually flagged the original message as suspicious, but once he was looking at familiar faces and hearing familiar voices on a live call, the doubt drained out of him, and the fraud only surfaced later when someone thought to check with the real headquarters.

I keep seeing that story used to argue that we can’t trust video calls anymore. That’s the wrong lesson, and it happens to be the expensive one. The video being fake was never the actual problem. What broke was that one convinced person could move $25 million on the strength of a call, with no step between his decision and the wire that would have caught it.

Seeing only ever felt like a security control.

You are not going to spot the fake

Set aside the fantasy that training people to detect deepfakes solves this. Study after study puts human detection of deepfake video at roughly coin-flip odds, and the people who miss the fake tend to rate their own ability highly, which is the worst possible pairing. You end up with confidence and inaccuracy in the same package. Meanwhile the technology that fooled Arup keeps getting cheaper and faster. The FBI warned back in late 2024 that a few seconds of audio lifted off social media is enough to clone a voice convincingly, and real-time video face-swapping has crossed from research demo to something a motivated crew runs on a laptop.

Detection is an arms race that defenders are structurally set up to lose. The attacker needs one success. Your tools and your people need to be right every single time, against a scheme that costs a fraction of what it pays out. Building your defense on catching the fake means betting that your detectors and your staff will out-improve a global pool of criminals who only have to win once. I wouldn’t put company money on that bet, and neither should you.

The target is the approval, not the network

What makes this different from the breaches most security teams are built to stop is that nothing actually got hacked at Arup. No malware, no stolen credentials. The attackers walked in through a legitimate video call and a legitimate wire process, and the whole thing turned on one moment, a human with payment authority saying yes.

That is why the people who fall for this are usually not the careless ones. Your most seasoned finance manager, the one who has passed every phishing test you have ever thrown at them, is exactly the profile who authorizes the transfer, because the attack isn’t testing whether they can spot a bad link. The real test is whether they will say no to their CFO and four colleagues on a live call demanding an urgent, confidential payment. Most people won’t, trained or not. Saying no in that moment feels like calling your own boss a liar in front of the room. I’ve spent enough time around Fortune 500 finance departments and defense-contractor back offices to know that “the boss is on the line and it’s urgent” beats almost any checklist you have handed the staff. The attack runs on authority and pressure, and those two things were beating good judgment long before anyone could fake a face.

This gets worse before it gets better

These figures come with a warning. A lot of the “deepfake fraud up 3,000 percent” headlines are recycled, loosely scoped junk, and a skeptic is right to ignore them. What still holds up are the load-bearing figures. The FBI logged $2.77 billion in business email compromise losses across more than 21,000 incidents in 2024, and in 2025 it began tracking AI-enabled fraud as its own category, landing near $893 million in the first year it bothered to count. Deloitte’s financial services group projects generative-AI-enabled fraud losses in the US climbing to $40 billion by 2027, up from $12.3 billion in 2023.

The reason it keeps climbing is economics, not novelty. A scheme like Arup reportedly cost its operators a sliver of what it netted, which inverts the assumption security has leaned on for decades, that you win by making attacks too expensive to be worth running. When the attack is cheap and the payout is eight figures, the math only points one way. Gartner has gone so far as to predict that a real share of enterprises will stop treating identity verification as reliable on its own, precisely because a face on a screen no longer proves that a person is real.

What actually holds

The fix has nothing to do with a smarter detector. What holds is a process that assumes the face and the voice can be faked and refuses to let that matter.

Start with the one rule that would have stopped Arup cold. Any high-value or out-of-pattern transfer gets verified out of band, on a channel the requester did not choose, before a dollar moves. Someone calls the executive back on the number already sitting in the company directory. They confirm on the internal system, not the one the request arrived through. Deepfake operations almost always control a single channel, so forcing a second, known channel collapses the whole illusion. The crew can fake the video call, but they can’t also pick up the phone number your team already has for the real person.

A few more, and none of them require buying anything. Put a verbal passphrase on high-value payment approvals, so a familiar face saying “authorize this” means nothing without the word. Require two people to sign off above a set threshold, so no single person and no single call can move real money. And treat the pairing of “urgent” and “confidential” as the tell it is, since that combination exists to isolate one employee and rush them past the moment they would normally stop and verify.

The most important shift is cultural, and it lands on leadership rather than on the finance staff. Make it impossible for anyone to get in trouble for verifying, and make it standard that no video call, however senior the faces on it, moves money on its own. Take the judgment call off the individual and bury it inside the process. The Arup employee “didn’t stand a chance” not because he was gullible, but because his company’s process allowed a video call to move $25 million. There is a decent chance yours would too.

The question worth asking today

Go look at how a wire actually gets approved inside your organization, then ask a blunt question. If a flawless deepfake of you, your voice, your face, the way you carry yourself, got on a call with the right employee and asked for an urgent transfer, is there a single step in your process that would stop it? When the honest answer is no, you have found your next project, and it is a process fix, not a software purchase. Seeing stopped being proof a while ago. The organizations that come through this clean are the ones that already stopped treating it as proof and rebuilt their controls for a world where the face on the screen might be lying to them.


메타데이터
post_id
59c6cf768ea8
slug
every-face-on-the-25-million-video-call-was-fake-59c6cf768ea8
url
https://meetcyber.net/every-face-on-the-25-million-video-call-was-fake-59c6cf768ea8
canonical_url
https://meetcyber.net/every-face-on-the-25-million-video-call-was-fake-59c6cf768ea8
author_url
https://medium.com/@mmcnelis
status
ok
fetched_at
2026-07-17 20:42:13