← Back to blog

The Deepfake That Signed Off on $25 Million: A Teardown of the Arup CFO Video-Call Heist (February 2024)

In January 2024 an Arup employee in Hong Kong made 15 transfers totalling HK$200 million after a video call on which every other participant was a pre-recorded deepfake. The rules of wire transfers decided in 1989 that recognizing a signature is not by itself a security procedure, and the one check that exposed the fraud came after the money had moved.

Published 9 October 2026 · 10 min read · fraud / deepfakes / payment controls

In January 2024, an employee in the finance department of Arup's Hong Kong office joined a video conference. The engineering firm's chief financial officer, who works from the United Kingdom, appeared on the call, and so did other colleagues the employee recognized. Over the following week the employee made 15 transfers totalling HK$200 million, about US$25.6 million, to five bank accounts.

"(In the) multi-person video conference, it turns out that everyone [he saw] was fake," Acting Senior Superintendent Baron Chan Shun-ching of the Hong Kong police told the public broadcaster RTHK when the force described the case. Every face and every voice on the call was synthetic except the victim's own.

The date in the headline is when the world heard about it. The money moved in January. The police made the case public at a briefing on Friday, February 2, without naming the company, and Arup confirmed it was the victim on May 17, after the Financial Times reported it. Arup is a large and sophisticated firm, with 18,500 employees in 34 offices, and it worked on the Sydney Opera House and designed Beijing's Bird's Nest stadium. That is part of why the case is worth taking apart slowly.

The artifact, in order

The public record for this incident is thin, and nearly all of it comes from two places: the Hong Kong police, who described the case in February 2024, and Arup, which confirmed it in May 2024 and talked about it in 2025. Read in order, their accounts give a sequence of five steps.

First, a message. In mid-January the employee received what the South China Morning Post, citing police, called "a phishing message ... that appeared to be from the company's CFO based in the United Kingdom saying a secret transaction had to be carried out." The employee's first read of it was correct. According to Chan, the worker initially "suspected it was a phishing email, as it talked of the need for a secret transaction to be carried out."

Second, the meeting. The fraudsters answered that doubt with a video conference. Police told AFP that the employee received "video conference calls from someone posing as senior officers of the company requesting to transfer money to designated bank accounts." Chan said the call had several participants and that all of them except the victim were impersonated, and he said where the material came from: "Scammers found publicly available video and audio of the impersonation targets via YouTube, then used deepfake technology to emulate their voices." Then he added the detail that most later retellings drop. As AFP reported it, "the deepfake videos were pre-recorded and did not involve dialogue or interaction with the victim." The meeting was a playback. Nobody on it had to answer a question.

It worked anyway. Chan said the worker "put aside his early doubts after the video call because other people in attendance had looked and sounded just like colleagues he recognized." That sentence is the whole attack. A person's judgment had caught the phishing message. The meeting existed to overrule that judgment, and it did.

Third, the payments: "15 transfers totalling HK$200 million to five bank accounts over a week in January," as the Post summarized the police account in May.

Fourth, the discovery. CNN's February report gives it one line: "The scam involving the fake CFO was only discovered when the employee later checked with the corporation's head office." Police received the report on January 29, AFP said, "at which point some HK$200 million (US$26 million) had already been lost via 15 transfers."

Fifth, what was not touched. Arup's statement in May: "Our financial stability and business operations were not affected and none of our internal systems were compromised." Its global chief information officer, Rob Greig, later called the incident "technology-enhanced social engineering" and said: "It wasn't even a cyberattack in the purest sense. None of our systems were compromised and there was no data affected."

What the record does not say

None of these sources says anything about Arup's payment controls. It does not say who else, if anyone, approved the 15 transfers, what limits applied, whether payments to new accounts were held, or whether a callback rule existed and was skipped. Arup's spokesperson told CNN in May that the company could not "go into details at this stage as the incident is still the subject of an ongoing investigation." When police briefed AFP in February they said "no arrest has been made so far," and I found no later report of an arrest or of the money being recovered.

The retellings have filled the gap anyway. The AI Incident Database notes in its entry that the case "has become a recurring reference for reports on AI-powered scams," and that "its emergence as a shorthand in journalism is worthy of note in and of itself." Shorthand collects detail as it travels. A 2026 VentureBeat retrospective puts the call on Zoom, says the first wire transfer "took minutes," and states that there was "No second approver, no out-of-band confirmation, no system-enforced hold." None of those details appears in the police statements or in Arup's. The database's editors observe that it is cited "particularly when discussing the dangers of deepfake technology in real-time video conferencing," while the police described clips that were recorded in advance.

So a teardown has to work the way an engineer works an incident that left no logs: from the outcome back to the controls that would have stopped it, saying at each step which part is inference.

A rule written in 1989

Money movement stopped trusting recognition a long time ago, and the rule is written down. Article 4A of the Uniform Commercial Code, the American law of wire transfers, was approved in 1989. Its definition of a "security procedure" lists what can count as one: "algorithms or other codes, identifying words or numbers, encryption, callback procedures, or similar security devices." Then it adds a sentence that reads, thirty-five years on, as if it were written about Arup: "Comparison of a signature on a payment order or communication with an authorized specimen signature of the customer is not by itself a security procedure."

A signature check is recognition. You hold the thing in front of you against what you know the real one looks like. The drafters did not call that useless. They said it could not stand alone, and the reason is not hard to see: a good enough forgery passes a comparison by definition. A face on a video call is a signature that moves.

Article 4A is American law and did not govern transfers out of Hong Kong. I cite it for what the people who wrote the rules of wire transfers decided about recognition, and the same thinking runs through the checklists bank examiners work from. The examiner's guide of the National Credit Union Administration, the US regulator for credit unions, tells examiners to "ensure credit union controls address adequate separation of duties between initiators, approvers, and reconcilers," to check funds-transfer agreements for "telephone call-back requirements," and to look for "dual-control verification." The first of the FBI's prevention tips for business email compromise is one line: "Use secondary channels and/or two-factor authentication to verify requests for changes in account information."

That family is not small. The FBI's Internet Crime Complaint Center counted 305,033 business email compromise incidents, domestic and international, between October 2013 and December 2023, with $55,499,915,582 in exposed losses. In its 2023 data, "international banks located in the United Kingdom and Hong Kong often acted as an intermediary stop for funds." The Arup case is the video-call version of a fraud the payments world has been fighting for a decade, in one of the places where that fraud's money habitually passes through.

What these controls share is that they do not care how convincing the request was. A callback goes to a number the firm already had on file, so it reaches the real chief financial officer however good the fake one looked. A second approver who has to confirm through a separate channel adds a person the fraudsters must also fool, on a line they do not control. The control's strength does not depend on the attack's weakness. That is the design principle, and it is why the quality of the deepfake, which is where most of the coverage looked, is the least important variable in the case.

The gates, reverse-engineered

With that template, the outcome narrows down which gates were missing or ineffective, even though the record never names them. What follows is inference, and I will say where.

An out-of-band confirmation before the first transfer. This is the gate we can be surest about, because the case contains its test. When the employee checked with head office, the fraud collapsed on contact. The confirmation that would have stopped all 15 transfers did take place. It took place after them. Either no rule required that check before money moved, or the rule could be satisfied through a channel the fraudsters controlled, such as a reply to their own message or another call they set up. The record does not say which.

An independent second approver. The record does not say whether anyone else signed off. If someone did, they signed off on the same evidence, the call, which means the second approval was not independent. What makes dual control work is the second channel as much as the second person. Two people who watched the same video are one control.

A hold on new payees and a limit on velocity. Five accounts received 15 transfers in about a week. The examiner's guide tells examiners to review "typical daily transaction volume," because "unusual transaction amounts or volumes may reflect fraudulent/erroneous activity or weak controls." Whether Arup's systems had holds or limits of that kind, and what they were set to, is not public.

And the one gate that clearly did fire was the human one. The employee spotted the first message as phishing. Everything after that was the attackers' answer to a control that worked.

Why the fake was cheap

The attackers did not need anything Arup protected. Chan said they built the participants from "publicly available video and audio of the impersonation targets via YouTube." A firm whose leaders speak at conferences and appear in the media has, without meaning to, published the training data for its own impersonation. The more visible its people are, the cheaper they are to copy, and that exposure grows with the communications budget, not the IT budget.

Nor did they need the newest technology. Pre-recorded clips were enough. Greig, interviewed by the World Economic Forum a year later, put it plainly: "It's freely available to someone with very little technical skill to copy a voice, image or even a video." Then he tried the harder version himself. "After the incident, I was curious so I attempted to make a deepfake video of myself in real time. It took me, with some open source software, about 45 minutes." He was candid about the result: "It wasn't particularly convincing." The attack on his firm never had to be convincing in real time. It only had to hold up through a meeting in which nobody asked it anything.

Recognition by machine had fared no better. At the same February briefing, police described a separate scheme from the previous July to September, in which eight stolen identity cards had been used for 90 loan applications and 54 bank account registrations, and in which, on at least 20 occasions, "AI deepfakes had been used to trick facial recognition programs by imitating the people pictured on the identity cards." Human eyes and automated face matching fell to the same trick in the same city, a few months apart.

Move the last line to the top

The February account turns on one late moment: the employee checks with head office, and the fraud falls apart. That check is the control. It costs almost nothing and depends on nobody's eyes, and when it was finally used it worked at once. In the Arup sequence it came last, once the message had been read, the meeting held and all 15 transfers made.

The practical version is short enough to fit on a card. Wherever a person can approve an irreversible action because they recognize who is asking, by face, by voice or by writing style, put a confirmation in front of it that runs through a channel set up before the request arrived. A number already on file will do. So will a second approver who must reach the requester independently, or a code agreed in advance. Then have the system enforce the order, so the check comes before the money moves. None of this requires detecting the deepfake. It is built so that it never has to.

In the sentence of CNN's February report that describes the fraud being caught, the word to change is "later."


Sources:

Confirm through a channel the request did not arrive on.

The control that would have stopped this fraud did not have to detect the deepfake. It only had to happen before the money moved, through a channel set up in advance. The same rule applies when software agents can initiate payments or other actions that cannot be undone: the order of request, confirmation and execution should be enforced, and afterwards it should be checkable. Chain of Consciousness keeps a tamper-evident record of an agent's actions, so that order can be verified later by someone who was not there.

pip install chain-of-consciousness
npm install chain-of-consciousness

Or start without installing anything: Hosted Chain of Consciousness.