The first known AI voice scam: how a fake boss's call took $243,000
In March 2019 the chief executive of a British energy company sent about $243,000 to a supplier because his boss asked him to on the phone. The boss never called. The voice was generated by software, in what the company's insurer described as the first case it had seen of criminals using AI to mimic a voice for fraud.[1][2] This case file covers how the calls unfolded, what the loss was, and the simple check that would have stopped it.
What happened
The victim company was a UK energy firm owned by a German parent. Its chief executive took a call from someone who sounded exactly like the head of the parent company. He later said he recognized the slight German accent and the rhythm of his boss's speech.[2][3]
The caller said a payment of €220,000, about $243,000, had to go to a Hungarian supplier urgently, within the hour.[1][4] The executive made the transfer. The money did not stay in Hungary for long. It moved on to Mexico and then to other accounts.[2][3]
Then the voice called again, this time to say the parent company had repaid the UK firm for the transfer. A third call followed, asking for another payment. By then the executive had noticed that no repayment had arrived and that the call was coming from an Austrian number. He refused the second payment.[1][3]
How it worked
This was an old scam with a new costume. Fraud that impersonates a senior executive to rush a payment has been around for years, usually by email. What changed here was the voice. According to the insurer's fraud expert, the criminals most likely used commercially available software to produce speech that sounded like the parent company's chief executive.[3]
The rest was pressure. The call came from a trusted person, involved a supplier payment that sounded routine, and carried a short deadline that left no time to think. The follow-up call about a refund was designed to calm the target and set up a second payment. The scheme only stopped when the story stopped adding up: the promised money never landed, and the number was wrong.[1]
What it cost
The loss was €220,000. The company's insurer, Euler Hermes Group, covered the full amount of the claim.[4] The insurer shared the details with the press but did not name the companies involved, and no suspects were identified.[2][3]
The larger cost was the precedent. By 2025 the FBI was warning that criminals were sending AI-generated voice messages that impersonated senior U.S. officials, and telling the public to verify any such contact independently through official channels before acting.[5] The trick that looked novel in 2019 had become routine.
The missing control
The missing control: callback verification before urgent payments. Any request to move money that comes by phone, email or message is confirmed by calling the requester back on a number you already have on file, not one the caller provides.
This one habit would have ended the scam on the first call. The real head of the parent company would have answered and said he had asked for nothing. It does not matter how good the fake voice is, because the check never relies on recognizing a voice. Security researchers who covered the case made the same point: confirm by walking into the boss's office or by placing the call yourself, rather than trusting a call you received.[1] A rule that new suppliers get paid only after their bank details are checked would have added a second barrier.
What to do in your business
- Write a callback rule. Any request to pay, change bank details or buy gift cards gets confirmed by calling the person back on a number from your own records. Put it in writing and apply it to the owner too.
- Treat urgency as a warning sign. Tell staff that a request to pay within the hour, or to keep it quiet, is a reason to slow down, and that no one will be blamed for checking.
- Check new payees before the first payment. Confirm a new supplier's bank details through a contact you found yourself, and hold the first payment until that is done.
- Agree on a code word. Owners and the people who handle money can set a phrase to use for unusual requests. A cloned voice will not know it.
- Check your insurance. Ask your insurer whether your policy covers social engineering and payment fraud, and what proof of verification they expect.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- How the Punjab National Bank fraud hid $1.8 billion outside the bank's own books
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Sophos: Scammers deepfake CEO's voice to talk underling into $243,000 transfer
- Forbes: A voice deepfake was used to scam a CEO out of $243,000
- Gizmodo: Scammer successfully deepfaked CEO's voice to fool underling into transferring $243,000
- PaymentsJournal: It happened! AI deep fake mimicked a CEO's voice and stole EUR 220,000
- Bitdefender: FBI warns of scammers impersonating US officials in deepfake scam campaigns