A finance employee at the Hong Kong office of engineering giant Arup joined what looked like a routine video call. On the screen were several familiar faces, including the company’s CFO, discussing a confidential transaction that required urgent action. Reassured by the people he could see and hear, the employee made 15 transfers totaling roughly $25 million (HK$200 million) to five Hong Kong bank accounts.
None of the people on that call were real. Every face and every voice, including the CFO’s, had been synthesized using AI. The fraud only came to light when the employee later checked in with headquarters directly, by which point the money was gone.
The Arup case, confirmed by the Financial Times in 2024, is now one of the most cited examples of deepfake CEO fraud in the world, and for good reason: it shows exactly how far this threat has moved beyond the crude “spoofed email from the boss” scams security teams have trained employees to spot for years. Attackers no longer need to fake a signature or an email domain. They can fake the person.
From Phishing Email to Cloned Executive
Business email compromise (BEC) has always relied on impersonation, tricking an employee into believing an instruction came from someone with authority. What has changed is the fidelity of the impersonation. AI voice cloning scam techniques and real-time deepfake video generation now let attackers reproduce not just the words a CEO or CFO might use, but their actual voice, cadence, and on-camera likeness.
The technical barrier to entry has nearly disappeared. Researchers at McAfee found that a convincing voice clone can be built from as little as three seconds of audio, easily lifted from an earnings call, a conference keynote, a podcast interview, or a video posted to the company’s own website. In their tests, three seconds of sample audio was enough to produce an 85% voice match to the original speaker, and accuracy climbed further with just a little more source material.
The tools to do this are no longer specialist software. Dozens of voice cloning applications are freely available online, and many of the more capable versions cost less than a $20-a-month streaming subscription. Some are legitimate products, built for dubbing and content creation, that are simply repurposed by criminals. Others circulate on underground forums as ready-made fraud kits, packaged with scripts for exactly this kind of attack. Either way, the economics have flipped: what once required a nation-state-level budget can now be done by a small criminal crew for the price of a coffee subscription.
That shift shows up in the numbers. The FBI’s 2025 Internet Crime Report logged more than 22,000 AI-related fraud complaints with losses exceeding $893 million, and Industry researchers have reported dramatic increases in AI-enabled voice fraud and deepfake-assisted social engineering attacks over the last two years. An increasing number of organizations report financial losses linked to deepfake and AI-enabled fraud. with average losses topping $280,000 per incident. Analysts at Deloitte project AI-enabled fraud could cost businesses as much as $40 billion annually by 2027.

Why CFO Impersonation Attacks Work So Well
A CFO impersonation attack succeeds for the same reason the original Arup scam did: it exploits trust and urgency at once. Finance and treasury staff are trained to move quickly when a senior executive requests a time-sensitive, confidential transaction, and a familiar voice or face on a live call short-circuits the skepticism that a suspicious email might otherwise trigger.
A few factors make this attack style especially dangerous right now:
Executives are the easiest people to clone. CEOs and CFOs regularly appear in earnings calls, media interviews, webinars, and conference keynotes, all of which are public, high-quality audio and video sources that give attackers exactly the raw material they need.
Live interaction defeats static red flags. Traditional awareness training tells employees to look for typos, mismatched domains, and odd phrasing. None of that applies on a live video call where the “executive” can answer questions in real time.
Urgency and confidentiality are built into the pretext. Nearly every deepfake CEO fraud case follows the same script: a time-sensitive, confidential deal that discourages the target from checking with anyone else before acting.
Multi-person calls add false credibility. In the Arup case, several deepfaked “colleagues” appeared alongside the fake CFO, which made the situation feel more legitimate than a single suspicious caller ever could.

How to Protect Your Organization
Defending against deepfake CEO fraud requires updating both technology controls and human habits. A few practical steps make a meaningful difference:
Verify out-of-band, every time. Any request involving a wire transfer, a change to payment details, or a “confidential” financial decision should be confirmed through a second, independently initiated channel, such as a phone call to a known number, not a callback number provided in the suspicious message or call itself.
Put dual authorization on high-value transfers. No single employee, regardless of who appears to be asking, should be able to approve or execute a large wire transfer alone. Require a second, in-person or independently verified sign-off above a defined threshold.
Establish a verbal or code-word verification protocol. Some organizations now use a pre-agreed passphrase for sensitive financial requests made by phone or video, similar to the “family code word” approach recommended for consumer voice-cloning scams.
Limit public exposure of executive voice and video. Consider how much unscripted audio and video of senior leaders is publicly available, and whether earnings calls, internal town halls, or interviews need to remain so easily accessible.
Train employees to be suspicious of urgency, not just of poor quality. Today’s deepfakes rarely look or sound “off.” The reliable warning signs are behavioral: pressure to act fast, insistence on secrecy, and a request to bypass normal approval processes.
Report and rehearse. Employees need a clear, fast way to flag a suspicious call or request, and finance and executive teams should run tabletop exercises so that when a real attempt happens, the response is second nature rather than improvised.
Awareness Training Is the Control That Scales
Firewalls and email filters were never built to catch a live video call with a synthetic CFO on it. The Arup case demonstrates that even sophisticated organizations can be compromised when trusted identities are convincingly impersonated, and established verification procedures are bypassed. That is precisely the gap that ongoing cybersecurity awareness training is designed to close.
CyberClan’s Cybersecurity Awareness, Education, and Training program is built around exactly this kind of evolving threat. Rather than a one-time compliance video, the program follows a continuous Evaluate-Communicate-Fortify-Measure cycle: assessing how employees actually respond to social engineering, delivering targeted training (including scenarios that reflect deepfake and voice-cloning tactics), closing the specific gaps that testing reveals, and tracking measurable improvement over time. It’s paired with phishing simulations, executive-focused tabletop exercises that rehearse exactly the kind of high-pressure wire-transfer scenario Arup faced, and threat intelligence to help your team recognize new fraud tactics as they emerge.
Deepfake CEO fraud isn’t a future risk. It’s already cost real companies tens of millions of dollars, and the tools behind it get cheaper and more convincing every quarter. The organizations that hold up aren’t the ones that expect their people to spot a perfect fake; they’re the ones that have built verification habits and response protocols that don’t depend on ever spotting it at all.
Ready to test how your team would respond to a deepfake CFO call?
Talk to CyberClan about building an awareness training program designed for today’s AI-powered fraud tactics.
Sources: Financial Times / CFO Dive, McAfee “Artificial Imposters” research, FBI 2025 Internet Crime Report via CybelAngel, Deloitte AI fraud projections.


