The Arup deepfake scam: the $25 million video call where everyone else was fake
A finance worker in Hong Kong sent about $25 million to criminals after a video meeting in which, police said, every other person on the screen was fake.[2][3] This case file covers how the scheme at engineering firm Arup worked, why no hacking was needed, and the one control that would have stopped the money.
What happened
In January 2024 an employee in the finance team at Arup's Hong Kong office received a message that appeared to come from the company's UK-based chief financial officer. It talked about a secret transaction. The employee's first instinct was the right one: he suspected it was a phishing email.[2]
Then came a video conference. On the call were what looked and sounded like the CFO and several colleagues he recognized. That erased his doubts. Following instructions from the meeting, he made 15 transfers into 5 local bank accounts, totaling HK$200 million, or roughly US$25 million.[1][3][4]
Only afterward did he check with the company's head office, and the fraud came to light. The case was reported to Hong Kong police on January 29, 2024.[2][4] Police described it publicly in February without naming the company. In May 2024 Arup, a London-based design and engineering firm with about 18,500 staff whose projects include the Sydney Opera House, confirmed it was the victim.[1]
How it worked
Nothing was broken into. Arup said fake voices and images were used, that its financial stability and operations were not affected, and that none of its internal systems were compromised.[1] Its chief information officer later called it technology-enhanced social engineering rather than a cyberattack in the usual sense.[5]
Police said the fraudsters collected genuine video and audio of the executives, including from past online meetings and public material, and used artificial intelligence to generate matching fake voices.[3][4] According to police, the videos were largely pre-recorded, and the fake participants did not hold a real back-and-forth conversation with the employee.[4] The criminals also used other channels, including messaging apps, email and one-on-one calls, to make the request feel routine and backed by several people.[3]
The trick was not the technology alone. It was that a single meeting with familiar faces was treated as proof, and a large, secret, urgent payment could be approved by the same person who was being persuaded.
What it cost
The loss was HK$200 million, reported as about US$25 million to US$26 million depending on the exchange rate used.[1][4] At the time police disclosed the case, they said the investigation was ongoing and no arrests had been made.[4] No arrests connected to the Arup theft have been reported since in the sources reviewed for this page.
Arup's CIO said afterward that attacks of this kind happen more often than people realize, and that he was able to make a passable deepfake of himself with free software in about 45 minutes.[5] Hong Kong police separately reported arrests in other schemes that used AI-generated faces to fool identity checks on loan and bank account applications.[2][3]
The missing control
The missing control: verifying payment requests out of band. That means confirming a request to move money through a separate channel the requester does not control, such as calling the executive back on a number already on file, before any money leaves.
The employee did eventually do exactly this, by contacting head office, but only after 15 transfers had gone out.[2][3] A rule that any unusual or confidential payment above a set amount must be confirmed by a call-back to a known number, and approved by a second person who was not on the call, would have forced that check to happen first. A deepfake can copy a face on a screen. It cannot answer the real CFO's desk phone.
What to do in your business
- Set a call-back rule. Any request to pay a new account, change bank details or make an urgent or secret payment gets confirmed by calling the person on a number from your own records, never one supplied in the message or meeting.
- Require two people for large payments. Pick a dollar threshold and make a second person approve anything above it, someone who was not part of the request.
- Treat secrecy and urgency as red flags. Tell staff in writing that no real executive will ever punish them for pausing a payment to verify it.
- Agree on a code word. For owners and finance staff, a private phrase that is never written in email gives a quick way to test a voice or video that seems off.
- Ask your bank about payment holds. Many banks offer delays, alerts or extra confirmation for first-time payees and large transfers. Turn them on.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- How the Punjab National Bank fraud hid $1.8 billion outside the bank's own books
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- CNN (via ABC17 News): British engineering giant Arup revealed as $25 million deepfake scam victim
- CNN: Finance worker pays out $25 million after video call with deepfake chief financial officer
- The Register: Deepfaked CFO scam costs Hong Kong firm $25 million
- Hong Kong Free Press: Multinational loses HK$200 million to deepfake video conference scam, Hong Kong police say
- World Economic Forum: Arup chief on the lessons learned from a $25m deepfake crime