The $25 Million Phone Call: How AI Voice Cloning Is Powering CEO Fraud

The $25 Million Phone Call: How AI Voice Cloning Is Powering CEO Fraud

A finance employee at the Hong Kong office of engineering giant Arup joined what looked like a routine video call. On the screen were several familiar faces, including the company’s CFO, discussing a confidential transaction that required urgent action. Reassured by the people he could see and hear, the employee made 15 transfers totaling roughly $25 million (HK$200 million) to five Hong Kong bank accounts. 

None of the people on that call were real. Every face and every voice, including the CFO’s, had been synthesized using AI. The fraud only came to light when the employee later checked in with headquarters directly, by which point the money was gone. 

The Arup case, confirmed by the Financial Times in 2024, is now one of the most cited examples of deepfake CEO fraud in the world, and for good reason: it shows exactly how far this threat has moved beyond the crude “spoofed email from the boss” scams security teams have trained employees to spot for years. Attackers no longer need to fake a signature or an email domain. They can fake the person. 

From Phishing Email to Cloned Executive 

Business email compromise (BEC) has always relied on impersonation, tricking an employee into believing an instruction came from someone with authority. What has changed is the fidelity of the impersonation. AI voice cloning scam techniques and real-time deepfake video generation now let attackers reproduce not just the words a CEO or CFO might use, but their actual voice, cadence, and on-camera likeness. 

The technical barrier to entry has nearly disappeared. Researchers at McAfee found that a convincing voice clone can be built from as little as three seconds of audio, easily lifted from an earnings call, a conference keynote, a podcast interview, or a video posted to the company’s own website. In their tests, three seconds of sample audio was enough to produce an 85% voice match to the original speaker, and accuracy climbed further with just a little more source material. 

The tools to do this are no longer specialist software. Dozens of voice cloning applications are freely available online, and many of the more capable versions cost less than a $20-a-month streaming subscription. Some are legitimate products, built for dubbing and content creation, that are simply repurposed by criminals. Others circulate on underground forums as ready-made fraud kits, packaged with scripts for exactly this kind of attack. Either way, the economics have flipped: what once required a nation-state-level budget can now be done by a small criminal crew for the price of a coffee subscription. 

That shift shows up in the numbers. The FBI’s 2025 Internet Crime Report logged more than 22,000 AI-related fraud complaints with losses exceeding $893 million, and Industry researchers have reported dramatic increases in AI-enabled voice fraud and deepfake-assisted social engineering attacks over the last two years. An increasing number of organizations report financial losses linked to deepfake and AI-enabled fraud. with average losses topping $280,000 per incident. Analysts at Deloitte project AI-enabled fraud could cost businesses as much as $40 billion annually by 2027. 

AI Voice Cloning Statistics

Why CFO Impersonation Attacks Work So Well 

A CFO impersonation attack succeeds for the same reason the original Arup scam did: it exploits trust and urgency at once. Finance and treasury staff are trained to move quickly when a senior executive requests a time-sensitive, confidential transaction, and a familiar voice or face on a live call short-circuits the skepticism that a suspicious email might otherwise trigger. 

A few factors make this attack style especially dangerous right now: 

Executives are the easiest people to clone. CEOs and CFOs regularly appear in earnings calls, media interviews, webinars, and conference keynotes, all of which are public, high-quality audio and video sources that give attackers exactly the raw material they need. 

Live interaction defeats static red flags. Traditional awareness training tells employees to look for typos, mismatched domains, and odd phrasing. None of that applies on a live video call where the “executive” can answer questions in real time. 

Urgency and confidentiality are built into the pretext. Nearly every deepfake CEO fraud case follows the same script: a time-sensitive, confidential deal that discourages the target from checking with anyone else before acting. 

Multi-person calls add false credibility. In the Arup case, several deepfaked “colleagues” appeared alongside the fake CFO, which made the situation feel more legitimate than a single suspicious caller ever could. 

AI Voice Cloning graphic image

How to Protect Your Organization 

Defending against deepfake CEO fraud requires updating both technology controls and human habits. A few practical steps make a meaningful difference: 

Verify out-of-band, every time. Any request involving a wire transfer, a change to payment details, or a “confidential” financial decision should be confirmed through a second, independently initiated channel, such as a phone call to a known number, not a callback number provided in the suspicious message or call itself. 

Put dual authorization on high-value transfers. No single employee, regardless of who appears to be asking, should be able to approve or execute a large wire transfer alone. Require a second, in-person or independently verified sign-off above a defined threshold. 

Establish a verbal or code-word verification protocol. Some organizations now use a pre-agreed passphrase for sensitive financial requests made by phone or video, similar to the “family code word” approach recommended for consumer voice-cloning scams. 

Limit public exposure of executive voice and video. Consider how much unscripted audio and video of senior leaders is publicly available, and whether earnings calls, internal town halls, or interviews need to remain so easily accessible. 

Train employees to be suspicious of urgency, not just of poor quality. Today’s deepfakes rarely look or sound “off.” The reliable warning signs are behavioral: pressure to act fast, insistence on secrecy, and a request to bypass normal approval processes. 

Report and rehearse. Employees need a clear, fast way to flag a suspicious call or request, and finance and executive teams should run tabletop exercises so that when a real attempt happens, the response is second nature rather than improvised. 

Awareness Training Is the Control That Scales 

Firewalls and email filters were never built to catch a live video call with a synthetic CFO on it. The Arup case demonstrates that even sophisticated organizations can be compromised when trusted identities are convincingly impersonated, and established verification procedures are bypassed. That is precisely the gap that ongoing cybersecurity awareness training is designed to close. 

CyberClan’s Cybersecurity Awareness, Education, and Training program is built around exactly this kind of evolving threat. Rather than a one-time compliance video, the program follows a continuous Evaluate-Communicate-Fortify-Measure cycle: assessing how employees actually respond to social engineering, delivering targeted training (including scenarios that reflect deepfake and voice-cloning tactics), closing the specific gaps that testing reveals, and tracking measurable improvement over time. It’s paired with phishing simulations, executive-focused tabletop exercises that rehearse exactly the kind of high-pressure wire-transfer scenario Arup faced, and threat intelligence to help your team recognize new fraud tactics as they emerge. 

Deepfake CEO fraud isn’t a future risk. It’s already cost real companies tens of millions of dollars, and the tools behind it get cheaper and more convincing every quarter. The organizations that hold up aren’t the ones that expect their people to spot a perfect fake; they’re the ones that have built verification habits and response protocols that don’t depend on ever spotting it at all. 

Ready to test how your team would respond to a deepfake CFO call? 

Talk to CyberClan about building an awareness training program designed for today’s AI-powered fraud tactics. 

 

Sources: Financial Times / CFO Dive, McAfee “Artificial Imposters” research, FBI 2025 Internet Crime Report via CybelAngel, Deloitte AI fraud projections. 

 

Under Attack? Guaranteed 15 minute response time.

Please call our emergency hotline below or fill out the form with your name, email, and phone number.

US/CA

1 800 762 3290

UK

0800 368 8731

AU

61 1800 413 128

Email

response@cyberclan.com

The information you provide in this form is only used exclusively to assist you. We do not share your data.

Sugandha Sood

Executive Vice President, Finance

As a professional accountant Sugandha, CPA, CGA has over 15 years of progressive finance and accounting experience across multiple industries including healthcare, medical, nuclear waste, and transportation.

Prior to joining CyberClan she worked at Energy Solutions Canada and was responsible for various aspects of accounting, financial reporting, internal controls, process improvements and taxation. Sugandha is eager to leverage her professional skills and play a vital role in the growth of the company by providing information to make informed decisions.