FrançaisEnglishEspañolالعربيةहिन्दीবাংলা中文

← Back to the blog

Published on 2026-07-25

Your boss asks for a transfer on a video call. Is it really them?


An employee joined a video call with a dozen familiar colleagues and sent 25.6 million dollars. Every face on that call turned out to be fake.

An employee at the Hong Kong office of the engineering firm Arup joined a video call that looked entirely routine. A dozen or so familiar faces, including the company's UK based chief financial officer, sat in their usual boxes on screen, discussing a confidential transaction. He had been hesitant about the request when it first arrived by email. The call put that hesitation to rest. Over the following week he authorized 15 transfers totaling 25.6 million dollars. Every single person on that call, it turned out, was generated.

Built from footage that was already public

None of the executives impersonated that day had done anything careless. The material scammers needed already existed: interviews, conference talks, company videos, all the ordinary footage a senior employee accumulates just by doing their job in public. Feed enough of it into the right software and you get a face that moves like the real one and a voice that sounds like the real one, live, responding to what is said in the room. Arup's chief information officer Rob Greig later called it 'an industry, business and social issue', and said he hoped the company's experience would help others grasp how far the technique had come.

The camera stopped being proof

For most of our lives, seeing a colleague's face and hearing their voice on a call was close enough to certainty. UNESCO's own account of the deepfake problem puts the shift bluntly: detection tools now lag behind the tools that create the fakes, in what amounts to a race nobody fully wins. Waiting for software that reliably flags a synthetic face is waiting for a finish line that keeps moving. The Arup case did not get caught by anyone spotting a glitch on screen. It got caught a week later, when the employee finally checked with headquarters through a completely different channel.

A face that moves and a voice that answers back are no longer proof that a person is actually on the other end of the call.

Small live tests, and their limits

There are a few things you can still try in the moment, on a call that feels off. None of them are guarantees, but a real-time deepfake has to work harder to fake them convincingly:

Try any of these and you might catch a clumsy fake outright. You should not, however, build your entire defense on them, because whatever trick works today gets patched into tomorrow's version. That is exactly the point UNESCO is making when it says the response cannot stay purely technical.

The step that actually held the line

Every documented near miss involving a deepfake video call shares one detail: somewhere in the story, a second, independent channel would have caught it, and in most cases it eventually did. A phone call to a number saved long before the meeting. An email to an address you already had, not one supplied during the call. A private code word agreed with your finance team well in advance, for exactly this situation. None of that depends on spotting a pixel out of place. It depends on refusing to let the request and its verification travel through the same pipe.

If your job ever puts you one video call away from moving real money, that habit is worth building before you need it: any request of that size gets confirmed somewhere other than the screen where it was made. The Hong Kong employee eventually did exactly that. He just did it a week and 25.6 million dollars too late.

You do not need to run a finance department for any of this to matter. A video call asking you to approve a payment, share a password, or rush a decision can target a small business just as easily as a multinational firm, and the fake does not need to be perfect: it only needs to be convincing enough to stop you from picking up a second phone. The habit that would have saved 25.6 million dollars costs nothing to practise on a much smaller request. Confirm first, transfer second, every single time real money changes hands based on what a screen showed you.

Topics : deepfakes video calls fraud

Sources

Keyboard shortcuts

?Open this help
EscClose the panel or this help
1-3Pick an answer during the quiz
EnterNext case, once you've read the answer
TabMove from link to link: the whole site works by keyboard