In January 2024, a finance employee at Arup, the London-headquartered engineering firm behind the Sydney Opera House and Beijing’s Bird’s Nest stadium, joined a video call with the company’s UK-based chief financial officer and several colleagues to discuss what he was told was a confidential transaction. He recognised their faces. He recognised their voices. Over the following days, acting on their instructions, he authorised fifteen transfers totalling $25 million to five Hong Kong bank accounts. Every person on that call was a fabrication, generated from publicly available footage and voice samples of real Arup executives. The employee only discovered the fraud when he called head office directly to check in.
What makes the Arup case worth revisiting, eighteen months on, is not the number, striking as it is. It is what the fraud actually attacked. This was not a phishing email that slipped past a spam filter, or a forged signature that a tired auditor failed to catch. It was the single verification mechanism every organisation has relied on since long before email existed: the assumption that a familiar face and voice, encountered in something resembling real time, constitute proof of identity. Generative AI has quietly made that assumption false, and most companies are still operating as though it holds.
An old trust, a new attack surface
The pattern is no longer exotic. In July 2024, an executive at Ferrari received a call from someone who sounded exactly like CEO Benedetto Vigna, complete with his Southern Italian accent, discussing a confidential acquisition and pressing for urgent financial assistance. The executive grew suspicious, not because the voice was imperfect, but because something about the request felt off, and asked a question only the real Vigna could answer: the title of a book he had recommended days earlier. The line went dead. Around the same period, WPP’s chief executive Mark Read was impersonated in a scam that combined a fake WhatsApp account with a Microsoft Teams call built from YouTube footage of Read himself, an attempt to extract money and confidential information from senior colleagues before it was caught.

These are not edge cases surfacing in security conference keynotes. Sumsub’s Identity Fraud Report puts the global rise in deepfake-related fraud attempts at 2,100% between 2022 and 2023. Regula’s 2024 industry survey found that 49% of businesses had absorbed direct financial losses from synthetic media fraud that year, up from 37% the year before, with the average incident in financial services costing over $600,000. Deloitte’s Center for Financial Services projects generative-AI-enabled fraud losses in the United States alone climbing from $12.3 billion in 2023 toward $40 billion by 2027. The FBI’s Internet Crime Complaint Center recorded well over $20 billion in cybercrime losses in its most recent annual report, with business email compromise and its AI-augmented successors among the largest single categories.
The economics explain the trajectory. Producing a convincing deepfake of a named executive now costs a fraction of what it did three years ago and requires no specialised access, only publicly available earnings calls, keynote appearances, and interview footage, all material that companies actively produce and promote because visible, communicative leadership is supposed to build trust with investors, employees, and customers. That same footage is now the raw material for impersonating them. The more accessible and telegenic a chief executive is, the more exploitable they become in exactly the moments requiring speed and discretion, such as a live acquisition, a restructuring, a crisis call at 11 p.m. It’s a quiet inversion of a governance virtue that boards have spent a decade encouraging.
Why the fix is harder than it looks
The obvious response, better biometric verification, is already being overtaken by the problem it is meant to solve. Gartner predicts that by 2026, 30% of enterprises will regard biometric identity verification as unreliable when used in isolation, precisely because injection and presentation attacks using synthetic faces and voices have grown too sophisticated to reliably distinguish from the real thing. Gartner analyst Akif Khan’s framing is blunt: organisations will increasingly be unable to tell whether the face being verified belongs to a live person or a deepfake. The technology sold as the solution to identity fraud is becoming part of the attack surface.
What actually stopped the Ferrari scam was not better software. It was a shared secret, a low-tech, deliberately human verification step that has nothing to do with facial recognition and everything to do with reintroducing friction at the exact point where organisations have spent years engineering friction out. That is the harder problem sitting underneath this one. Corporate hierarchies are built to move quickly when someone senior says something is urgent. A chief financial officer’s live, agitated request on a video call is designed to be acted on, not interrogated. Asking a caller who sounds exactly like your CFO to prove it via a codeword or callback protocol carries a real social cost inside most organisations: it can read as insubordination, or as an accusation, at precisely the moment hierarchy is telling the employee to comply. Building that friction back in, and making it psychologically safe for a junior employee to impose it on a senior executive, is a cultural and governance problem, not a procurement decision, and it belongs on the same agenda as signing authority and delegated financial limits, not buried in an IT security briefing that never reaches the board.
India’s exposure is structurally different, not just larger
The scale of the problem in India deserves separate attention rather than a token mention. A 2025 industry analysis found that 47% of Indian adults reported being a victim of, or knowing a victim of, AI voice-cloning or deepfake fraud, against a global average closer to 25%, with 83% of Indian victims of AI voice scams suffering direct monetary loss. Related “digital arrest” scams, in which fraudsters impersonate law enforcement or officials using synthetic audio and video, have cost Indian citizens an estimated $5.52 billion over six years, a figure serious enough that in July 2026 a Supreme Court bench led by Chief Justice Surya Kant pressed Parliament to criminalise digital arrest as a standalone offence and asked the Reserve Bank of India to standardise procedures for freezing suspected money-mule accounts across the banking system, precisely because no existing statute addresses synthetic impersonation directly.
The exposure is structural, not incidental. India’s real-time payments infrastructure, built for speed and near-universal reach through UPI, means funds can move and be laundered across mule accounts before a victim organisation has finished its first internal call to verify what happened. And in a business landscape still shaped by promoter-led conglomerates and family-controlled groups, verbal instruction from a founder or chairman often carries an informal authority that no compliance manual can easily override, exactly the channel a synthetic voice is built to exploit. Where the West’s initial response has run largely through insurers, security vendors, and corporate policy, India’s is running, for now, through the courts pressing a reluctant legislature to catch up. Neither has produced a durable answer yet.
The question boards are not yet asking
None of this means chief executives should retreat from public visibility, or that every video call now warrants suspicion. It means the question of how anyone inside an organisation proves they are who they claim to be, at the moment that matters most, needs an owner senior enough to make the answer stick against hierarchical pressure. Most companies have detailed rules about who can authorise a wire transfer above a given threshold. Very few have an equally clear, board-endorsed protocol for what happens when the person requesting it looks and sounds exactly right, in real time, and something still feels wrong. That gap, not the sophistication of the fraud itself, is what the next Arup will exploit.


