AI SafetyApplications 🇷🇺 31.07.2026 07:03

Video Call Is No Longer Proof: How Deepfakes Breach Corporate Trust

A Hong Kong employee of British engineering firm Arup was deceived into transferring $25.6 million after a video call with deepfake replicas of colleagues. The incident highlights that familiar faces and voices are no longer sufficient identity verification, prompting experts to recommend multi-step procedures and independent channels for large transactions.
In January 2024, an Arup employee in Hong Kong received a phishing email purportedly from the CFO, then was invited to a video call where the director and colleagues appeared and sounded authentic. He transferred about $25.6 million in 15 payments; none of the people on the call were real. Arup's CIO Rob Greig later created a real-time deepfake of himself in 45 minutes, demonstrating low technical barriers. The employee acted correctly by trying to verify the request, but he switched channels while the attackers controlled both email and video conference. Experts from Garda and RTU MIREA predict attacks will shift from pre-edited videos to real-time voice and face substitution. Effective countermeasures include treating secrecy requests as red flags, verifying unusual orders through pre-established independent procedures with a second authorized person, using multi-factor procedures rather than code words, writing down decisions that can never be made by one call or video, applying the same logic in personal life with relatives, and treating video and voice as just one source of evidence. Network security like NGFW cannot detect deepfakes in encrypted video streams, so financial regulations must preclude transfers based solely on face, voice, email, or video call.
Сокращения
CFO = Chief Financial Officer — финансовый директор
CIO = Chief Information Officer — ИТ-директор
NGFW = Next-Generation Firewall — межсетевой экран нового поколения
Source: Habr — хаб ИИ — original
Our earlier posts on this topic ↓
Fresh news