Case file · ARUP 2024

The Arup deepfake scam: the $25 million video call where everyone else was fake

Published 2026-09-29 · 4 min read · Missing control: Verify payment requests out of band

A finance worker in Hong Kong sent about $25 million to criminals after a video meeting in which, police said, every other person on the screen was fake.[2][3] This case file covers how the scheme at engineering firm Arup worked, why no hacking was needed, and the one control that would have stopped the money.

What happened

In January 2024 an employee in the finance team at Arup's Hong Kong office received a message that appeared to come from the company's UK-based chief financial officer. It talked about a secret transaction. The employee's first instinct was the right one: he suspected it was a phishing email.[2]

Then came a video conference. On the call were what looked and sounded like the CFO and several colleagues he recognized. That erased his doubts. Following instructions from the meeting, he made 15 transfers into 5 local bank accounts, totaling HK$200 million, or roughly US$25 million.[1][3][4]

Only afterward did he check with the company's head office, and the fraud came to light. The case was reported to Hong Kong police on January 29, 2024.[2][4] Police described it publicly in February without naming the company. In May 2024 Arup, a London-based design and engineering firm with about 18,500 staff whose projects include the Sydney Opera House, confirmed it was the victim.[1]

How it worked

Nothing was broken into. Arup said fake voices and images were used, that its financial stability and operations were not affected, and that none of its internal systems were compromised.[1] Its chief information officer later called it technology-enhanced social engineering rather than a cyberattack in the usual sense.[5]

Police said the fraudsters collected genuine video and audio of the executives, including from past online meetings and public material, and used artificial intelligence to generate matching fake voices.[3][4] According to police, the videos were largely pre-recorded, and the fake participants did not hold a real back-and-forth conversation with the employee.[4] The criminals also used other channels, including messaging apps, email and one-on-one calls, to make the request feel routine and backed by several people.[3]

The trick was not the technology alone. It was that a single meeting with familiar faces was treated as proof, and a large, secret, urgent payment could be approved by the same person who was being persuaded.

What it cost

The loss was HK$200 million, reported as about US$25 million to US$26 million depending on the exchange rate used.[1][4] At the time police disclosed the case, they said the investigation was ongoing and no arrests had been made.[4] No arrests connected to the Arup theft have been reported since in the sources reviewed for this page.

Arup's CIO said afterward that attacks of this kind happen more often than people realize, and that he was able to make a passable deepfake of himself with free software in about 45 minutes.[5] Hong Kong police separately reported arrests in other schemes that used AI-generated faces to fool identity checks on loan and bank account applications.[2][3]

The missing control

The missing control: verifying payment requests out of band. That means confirming a request to move money through a separate channel the requester does not control, such as calling the executive back on a number already on file, before any money leaves.

The employee did eventually do exactly this, by contacting head office, but only after 15 transfers had gone out.[2][3] A rule that any unusual or confidential payment above a set amount must be confirmed by a call-back to a known number, and approved by a second person who was not on the call, would have forced that check to happen first. A deepfake can copy a face on a screen. It cannot answer the real CFO's desk phone.

What to do in your business

Watch the case
The $25M Video Call Where Everyone Else Was FakeDrops 2026-10-15
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More payments and fraud cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. CNN (via ABC17 News): British engineering giant Arup revealed as $25 million deepfake scam victim
  2. CNN: Finance worker pays out $25 million after video call with deepfake chief financial officer
  3. The Register: Deepfaked CFO scam costs Hong Kong firm $25 million
  4. Hong Kong Free Press: Multinational loses HK$200 million to deepfake video conference scam, Hong Kong police say
  5. World Economic Forum: Arup chief on the lessons learned from a $25m deepfake crime