Deepfake Detection Failure | Inside the Arup $25M Executive Scam (EP75)

August 06, 2026 00:27:57
Deepfake Detection Failure | Inside the Arup $25M Executive Scam (EP75)
Behind the Scams | Cryptocurrency & Romance Scam Stories
Deepfake Detection Failure | Inside the Arup $25M Executive Scam (EP75)

Aug 06 2026 | 00:27:57

/

Show Notes

In a shocking case of corporate fraud, Arup's Hong Kong office fell victim to a deepfake video call scam that siphoned off $25 million. This episode of *Behind the Scams* reveals how criminals used urgency, secrecy, and a convincing digital performance to manipulate a finance employee into believing they were in a legitimate meeting with the CFO. With synthetic faces and cloned voices, the fraudsters created an illusion of consensus that was hard to resist. Discover the psychology behind this alarming scam and learn how companies can protect themselves from such sophisticated threats. Don't miss this eye-opening exploration!

Chapters

View Full Transcript

Episode Transcript

[00:00:00] Speaker A: Welcome back to behind the Scams. I'm Nick Henley, a retired federal agent who spent 25 years investigating financial crimes and money laundering. With me, as always, is Sue. Today, a $25 million deepfake video call heist involving Arup's Hong Kong office and a fake meeting that looked real enough to move real money. Imagine you're sitting at your desk in Hong Kong. It's a normal workday. Emails, spreadsheets, approvals, deadlines. Then a message comes in from the company's chief financial officer. It's confidential, it's urgent, and it involves a major transaction. [00:00:40] Speaker B: You pause because something about it feels off. Maybe the wording, maybe the secrecy. Maybe the fact that when money and urgency appear in the same sentence, your internal fraud alarm starts tapping the glass. [00:00:58] Speaker A: Then comes the video call. You click in. There's the cfo. There are familiar senior colleagues, faces you recognize, voices you recognize. They look present. They speak naturally. They reinforce the same instruction. Move the funds. [00:01:17] Speaker B: And suddenly the thing that was supposed to protect you, the face to face verification, becomes the weapon. [00:01:25] Speaker A: Fifteen transfers, five bank accounts. Roughly $25 million gone. And here's the nightmare twist. The employee was the only real human being in that digital room. I spent 25 years as a federal special agent working financial crimes, wire fraud and money laundering cases. I've seen fake invoices, spoofed emails, compromised vendors, mule accounts, shell companies, the whole playbook. But this case, this is the old corporate wire fraud machine wearing a new face, literally. Before we go any further, let's put the case on the table. The company at the center of this story is Arup, the British engineering and design firm known for work on major global landmarks and infrastructure projects. The crime took place in January 2024 inside Arup's Hong Kong operation. A finance employee received what appeared to be a message from the company's UK based chief financial officer about an urgent confidential transaction. At first, the employee was suspicious, which is exactly the reaction we want people to have when secrecy, urgency and money show up together. [00:02:40] Speaker B: But then the scammers moved the employee into what appeared to be a live video conference. On screen were the CFO and several senior colleagues, people who appeared to look and sound like real ARUP executives. That fake meeting reportedly reassured the employee enough to authorize 15 separate transfers totaling about 200 million Hong dollars, roughly 25.6 million US dollars into five Hong Kong bank accounts. The fraud was discovered only later, after the employee followed up with Aroup's headquarters and learned there had been no such meeting. No such instruction. And no real executives on that call. Hong Kong police publicly described the case in February 2024, and Arup later confirmed in May 2024 that it had been the victim of what its leadership called technology enhanced social engineering. [00:03:40] Speaker A: One employee walked into a meeting. The executives were fake. The money was real. And by the time anyone understood the difference, $25 million was gone. [00:03:51] Speaker B: And before we move on, listeners should understand where the public record appears to stop. Reporting has documented the loss, the discovery, the police disclosure, and arup's later confirmation. But it has not clearly established that anyone was prosecuted or. Or that the stolen funds were fully recovered. [00:04:14] Speaker A: That matters, because in a fraud like this, the visible crime is the fake meeting. The ending often sits elsewhere in bank records, mule accounts, frozen funds, cross border requests, and investigative files the public never sees. The public record does not tell us who built the deepfake meeting, who controlled the receiving accounts, how much money was frozen, or whether prosecutors charged anyone. So we can reconstruct the heist, but not a courtroom ending. [00:04:45] Speaker B: So let's slow this down, because the sequence is what makes the case so chilling. Act one is the message. Act two is the doubt. Act three is the meeting. Act four is the money leaving. And the final act is the discovery that the room had never been real. [00:05:08] Speaker A: And the employee does one important thing right. He hesitates. Something feels wrong. The secrecy, the urgency, the money. It all triggers the warning signs. At that point, the first layer of the scam is not fully working. [00:05:23] Speaker B: Then the criminals change the stage. They don't just send another email. They move him into a video meeting. Now he is no longer staring at a suspicious instruction on a screen. He is looking at what appears to be leadership. The CFO is there. Other senior colleagues are there. Familiar faces, familiar voices. A digital room that seems to answer the very doubt the first message created. The call does not just reassure him, it surrounds him. [00:05:56] Speaker A: That is the turn. The fraud moves from instruction to performance. Once the meeting feels real, the instruction feels real. [00:06:05] Speaker B: Then come the transfers. Not one 15 money moving out in pieces into 5 Hong Kong bank accounts. To the employee, each transfer may have felt like part of one confidential corporate instruction. To investigators, each account became a separate trailhead, and each payment was another chance for the money to be drained, split, or moved farther from recovery. And for a little while, nothing explodes. The task is done. The urgent thing is handled. The meeting, as far as the employee knows, was real. [00:06:47] Speaker A: And then the final act. Later, the employee follows up with headquarters, probably expecting routine confirmation. Instead, the floor drops out. Headquarters says, in effect, what meeting? What Transaction what? Approval. [00:07:05] Speaker B: No real cfo, no real colleagues, no real authorization. [00:07:11] Speaker A: Just one real employee, one counterfeit boardroom, and $25 million already out the door, moving faster than the truth could catch it. That's the shape of the heist. Now, the real question is why it worked and what it tells us about verification in an age when a meeting itself can be counterfeit. [00:07:31] Speaker B: And that's the uncomfortable question sitting underneath this whole episode. If a video call can be staged, if familiar faces can be manufactured, and if the person giving the order may not be a person at all, what does verification mean now? [00:07:52] Speaker A: That's right, Sue. For years, the cybersecurity advice was simple. Don't trust the email, don't trust the text, don't trust the caller id Verify through a separate channel. But this case complicates the advice because it shows that a familiar face on a screen is not, by itself, verification. [00:08:11] Speaker B: That is not comforting, Nick. That's the security equivalent of locking the front door and discovering the burglar can impersonate your house. [00:08:21] Speaker A: When I worked federal wire fraud and money laundering cases, the older version was usually an email pretending to be the CEO or cfo. Sometimes the criminals compromised a mailbox. Sometimes they spoofed a domain. The target was a finance employee under deadline pressure. What changed here is speed and believability. The fraudsters didn't just write as the executive. They performed as the executive. [00:08:48] Speaker B: So this is business email compromise with theater production values. [00:08:55] Speaker A: And when I started working money laundering cases, the criminals were not exactly winning Oscars. Some fake emails looked like they had been assembled by someone at war with punctuation. But they still worked because they landed at the right time, in the right inbox, under the right pressure. Sophistication helps criminals, but timing, trust, and pressure have always done most of the work. AI just adds a custom mask to an old robbery. From an investigative standpoint, this case has four moving parts. Executive impersonation, social proof, payment, execution, and laundering. The structure is old. What changed is that the criminals could now perform the approval chain instead of merely writing it. [00:09:42] Speaker B: That's the part that makes this feel different. It's not one fake boss barking orders. It's a room full of familiar faces creating the illusion of consensus. [00:09:55] Speaker A: Stage two is the synthetic meeting. Public reporting does not tell us exactly how the fakes were built. But in general, these tools can rely on available video, audio and images. Conference appearances, interviews, company clips, social media, or compromised internal material. The criminals do not need a flawless Hollywood production. They need a short, believable performance that Survives long enough to defeat the employee's warning system. [00:10:24] Speaker B: So when people hear deepfake, they picture a perfect fake person. But operationally, the scammers don't need perfect. They need believable, brief and contextually convincing. [00:10:38] Speaker A: Exactly. And the context does a lot of the work. If you already believe you're in a confidential finance meeting, your brain fills gaps. Maybe the lighting is odd. Maybe there's a slight audio delay. Maybe someone doesn't speak much. But we've all sat through bad video calls. Freezing, lagging, weird compression, people talking over each other. That normalizes imperfections. [00:11:03] Speaker B: Which means years of terrible video conferencing accidentally trained us to accept suspense. Suspicious video conferencing? [00:11:11] Speaker A: Unfortunately, yes. But the serious point is recognition. The scammers use the strongest shortcut humans have. I know that face. I know that voice. I know that person. [00:11:23] Speaker B: And once the employee is in that meeting, the scam moves from Should I trust this email? To Am I really going to challenge a room full of senior people? [00:11:35] Speaker A: Exactly. Stage three is execution. Reports describe 15 separate transfers totaling about $25 million into five different bank accounts. That's not a single impulsive click. That's a sequence. And the sequence matters because every payment creates both another fraud loss and another trail for investigators to chase. [00:11:57] Speaker B: And the employee probably wasn't thinking, I'm sending $25 million to criminals. He was thinking, I'm following instructions from leadership On a confidential corporate matter. [00:12:09] Speaker A: That distinction is everything. The victim is not careless in the cartoon sense. They are operating inside pressure, authority, uncertainty, and a deception engineered around the company's own hierarchy. Psychologically, the scam worked because it pulled four levers at urgency, secrecy, authority, and consensus. [00:12:31] Speaker B: Let's talk about what was happening inside the employee's head, because this is the part I think people underestimate. We love to believe we'd spot the scam, but this wasn't just a technical trick. It was psychological compression. [00:12:47] Speaker A: That's exactly right. In investigations, I learned early that fraud is rarely just about the lie. It's about the environment the lie creates. The criminals build a room, sometimes literally, in this case, where the victim feels there is only one acceptable path forward. [00:13:04] Speaker B: The first lever is urgency. Not panic, necessarily, but pressure, the feeling that if you slow things down, you're the problem. [00:13:14] Speaker A: Urgency is one of the oldest tools in wire fraud. In federal cases involving business email compromise, fake vendor payments, and executive impersonation, the victim was almost always placed under a clock. This must go out today. The deal closes in an hour. The CEO is waiting. The point is to make normal verification feel like obstruction. The second lever is secrecy. The phrase confidential project can sound legitimate in corporate life. Mergers, acquisitions, litigation, restructuring, strategic investments. Companies do handle sensitive matters. The fraudsters strategy is to turn legitimate confidentiality into isolation. I saw that over and over. Fraudsters didn't just impersonate authority. They created conditions where the victim felt that verifying the request would violate loyalty or confidentiality. Once you make the employee feel alone with the decision, the criminals have gained leverage. [00:14:15] Speaker B: Then comes authority bias. If the CFO or someone who appears to be the CFO is in the room, the employee is not processing this as a normal request from a stranger. They're processing it as an instruction from leadership. [00:14:32] Speaker A: Right. Corporations run on hierarchy. That hierarchy is useful. It creates order, accountability, and speed. But criminals abuse that strategy structure. In traditional wire fraud, the fake email says, I need this done now. In this case, the fake face adds, you can see it's really me. That's a major escalation. [00:14:53] Speaker B: And the fourth lever is group consensus. The other fake colleagues aren't just decoration. They're there to make the employee think, everyone else knows about this. Everyone else agrees. I'm the only one catching up. [00:15:07] Speaker A: That's the genius. And the cruelty of this scam. A single impersonator can be questioned. A group creates momentum in federal investigations. We looked closely at how conspirators reinforced one another. One person introduces the scheme, another validates it, another applies pressure. The deepfake meeting compresses that conspiracy into one polished performance. And I want to be very careful here. It's easy for outsiders to say, how could anyone fall for that? But when I sat across from victims in wire fraud and money laundering investigations, shame was often the first thing they felt. Shame helps criminals because it delays reporting. The right response is not blame. The right response is containment, investigation, and stronger controls. [00:15:58] Speaker B: That's important because if your workplace culture punishes people for raising concerns or admitting mistakes, fraudsters benefit. A scared employee waits. A supported employee reports immediately. [00:16:13] Speaker A: Discovery is a race against the money. Once a suspicious transfer is identified, companies need banks, law enforcement, legal cyber teams, and insurers moving immediately. Days later, the laundering machinery may already be several moves ahead. [00:16:31] Speaker B: Which brings us to the next question. Once that money leaves the company, where does it go? [00:16:36] Speaker A: Great question, Sue. I love how you always tee me up to either tell a war story or tap into my law enforcement experience. I do love reliving it, because it was not only an exciting career, it was actually pretty fun. Anyways, in the federal world, the moment a wire fraud loss is discovered, the Clock starts. Investigators want wire details, beneficiary accounts, timestamps, correspondent banks, IP logs, email headers, and device evidence. Anything that shows where the money went and how the fraud was staged. [00:17:11] Speaker B: When people hear trace the money, they picture someone opening a laptop, typing dramatically, and watching a red dot move across a map. How does it actually work? [00:17:24] Speaker A: Less red dot, more subpoenas, bank records, emergency requests and coordination. Investigators look at the outgoing wire instructions, the receiving bank, the account holder, the timing, and whether the receiving account immediately pushed the funds somewhere else. If the money is still sitting there, banks and law enforcement may be able to freeze it. If it moves, investigators follow the next hop. [00:17:50] Speaker B: And in a case like this, with 15 transactions into five accounts, that means five starting points for the chase. [00:17:59] Speaker A: Correct. Each account becomes a trailhead. Criminals want layers, shell companies, mule accounts, fake invoices, cryptocurrency conversion, foreign exchange, prepaid instruments, or transfers through multiple jurisdictions. The goal is simple. Move the money far enough, fast enough, that recovery becomes difficult. [00:18:22] Speaker B: Let's define a mule account, because that term comes up a lot. And some listeners may not realize those account holders aren't always criminal masterminds. [00:18:32] Speaker A: A money mule is a person or entity used to receive, receive, and move criminal proceeds. Some know exactly what they're doing. Others are recruited through job scams, romance scams, investment schemes, or payment processing pitches. During my federal career, we saw mules who thought they were helping an employer, helping a romantic partner, or earning a commission. But once fraud proceeds touch their account, they become part of the laundering chain. [00:19:01] Speaker B: So the fraud doesn't end with the video call. There may be a whole human network downstream, some complicit, some manipulated, moving pieces of that money as fast as possible. [00:19:14] Speaker A: Exactly. Borders make recovery harder. If the victim, company banks, and suspect accounts sit in different jurisdictions, every step can require coordination across legal systems. While criminals move at the speed of [00:19:28] Speaker B: online banking, what stands stands out to me is that this case also raises corporate liability questions. Not just who clicked, but what systems allowed one employee to act on a video meeting and move that much money? [00:19:44] Speaker A: Absolutely. Investigators and insurers will look at internal controls, approval thresholds, dual authorization, callback procedures, vendor verification, bank token controls, segregation of duties, escalation channels, and whether the company's policies match the actual risk environment. A sophisticated scam can still expose ordinary control gaps. [00:20:08] Speaker B: And then there's the emotional toll. The employee is likely replaying that call over and over, wondering what they missed. [00:20:17] Speaker A: That toll is real. Corporate victims can lose sleep, Sleep, confidence, and even careers. Even when the attack was engineered by professionals using Advanced tools Companies need to investigate firmly and support employees who report quickly and cooperate honestly. [00:20:35] Speaker B: Employee burnout matters here too. Overloaded finance teams, non stop approvals, global time zones and constant pressure create a perfect environment for manipulation. [00:20:49] Speaker A: Exactly. Fraud controls are not just software settings. They're human safety rails. If your finance employees are exhausted, understaffed and afraid to challenge executives, your fraud defenses are already weaker. Criminals study procedures, but they also study pressure. [00:21:07] Speaker B: So if the bad guys can fake the meeting, fake the voice, fake the authority, and move the money fast, what can organizations actually do? [00:21:16] Speaker A: High tech scams often require low tech interruption. You don't beat a deepfake by staring harder at the screen. You beat it by forcing the request outside the fake environment. [00:21:27] Speaker B: So not does the video look real, but can I verify this through a channel the scammers don't control? [00:21:36] Speaker A: Exactly. For any high risk transfer, a scroll, especially anything over a designated threshold, the rules should be simple. No money moves based solely on email, chat or video meeting instructions. There must be an out of band verification step. [00:21:51] Speaker B: Out of band means a separate communication path. If the request comes by email, you verify by phone. If it comes by video call, you verify using a known company directory number, not a number provided inside the suspicious message. [00:22:09] Speaker A: In my federal wire fraud cases, callback failures were a recurring theme. Someone would call the number in the fraudulent email instead of the number already on file. That's like asking the burglar to confirm whether he's the homeowner. The callback has to use a trusted source that existed before the transaction. [00:22:28] Speaker B: What about passphrases? Because that sounds almost old fashioned, but also very doable. [00:22:34] Speaker A: I like verbal authenticator words for high risk situations. Some organizations call them duress words, challenge words, or transaction passphrases. The idea is that certain finance approvals require a short verbal exchange that is never written an email and never improvised on a call. For example, what is today's authorization word? If the person on the call can't answer, the transaction stops. [00:23:01] Speaker B: And the passphrase cannot be something obvious like the company mascot, the CEO's dog, or password. 1, 2, 3. Which I say with love and concern for everyone's IT department. [00:23:15] Speaker A: Please do not make the duress word duress. Fraudsters, thank you for your service. [00:23:22] Speaker B: What else should companies put in place immediately? [00:23:25] Speaker A: Number one. Multi person verbal verification for wires over set thresholds using trusted phone numbers. Number two. Segregation of duties so one employee cannot receive, approve and release the funds alone. Number three. Waiting periods for unusual payments, new payees, changed bank details, or transfers to high risk jurisdictions. [00:23:49] Speaker B: Number four, make it safe to slow down. Employees need permission. Actually, they need an obligation to pause a payment request if something feels unusual, even if the person requesting it appears to be senior. [00:24:05] Speaker A: That is huge. A healthy fraud control culture says no one is too senior to verify if the cfo, CEO, general counsel or board chair is legitimate. They should welcome strong controls. If someone gets angry because finance followed policy. That's not a finance problem. That's a governance problem. [00:24:27] Speaker B: And training needs to evolve too. We can't keep showing employees the same fake email with a misspelled domain and a suspicious attachment and call that enough. [00:24:37] Speaker A: Exactly. Training now has to include synthetic voice, fake video meetings, spoofed collaboration tools, cloned executives, and pressure based scenarios. The red flag is not only a bad link, the red flag is the demand to bypass normal process. [00:24:55] Speaker B: For individuals. The takeaway is simple. If money, urgency, secrecy and authority all show up together. Stop. That combination deserves verification, whether you're at work helping a family member or responding to a message from someone who sounds familiar. [00:25:13] Speaker A: And remember, verification is not disrespect, it is professional. It protects the company, the employee, the executive being impersonated and the customer. A good protocol removes shame from the process because everyone knows the rule before the emergency happens. [00:25:31] Speaker B: So the defense is not to distrust everyone. It's to stop trusting any single channel as proof. [00:25:39] Speaker A: Exactly. Trust people, verify channels, protect process. [00:25:44] Speaker B: What stays with me about this case is how familiar it all feels right up until the impossible part. An email, a meeting, a finance request, senior people on a call. These are ordinary business rituals. The scam worked because it hid inside normal. [00:26:06] Speaker A: That's exactly right. And from having worked many wire fraud and money laundering cases while a special agent, I can tell you criminals don't need to invent a new human weakness. They exploit the ones that already exist. Trust, urgency, hierarchy, and the desire to do your job well. AI just gives them a faster mask and a better microphone. [00:26:28] Speaker B: If you encounter suspicious activity, report it quickly to your bank, your company's security or legal team, and the appropriate law enforcement or cybercrime reporting channel in your jurisdiction. Speed matters. Silence helps scammers. [00:26:47] Speaker A: The ARUP deepfake heist is not just a strange headline, it is a warning shot. The next generation of fraud may look like your boss, sound like your colleague, and arrive inside a meeting. You think think you understand. [00:27:00] Speaker B: If this episode made you rethink a process at work. That's the point. The goal is not to make people paranoid. It's to make verification normal before the pressure arrives. [00:27:12] Speaker A: And if you found this useful, subscribe to behind the Scams, leave us a review and send this episode to someone whose job depends on trusting the right voice at the right moment. Then ask one simple question at work. What is our second path of verification? When the first one looks real, that's [00:27:30] Speaker B: what stays with me. One person tried to do the right thing in a room that was built to deceive them. If we can make it easier for the next person to pause, verify, and speak up, then we have to, as [00:27:47] Speaker A: we always say before we close, stay skeptical, stay kind to victims, and verify before you wire. Bye for now.

Other Episodes

Episode

February 21, 2026 00:22:13
Episode Cover

EP 45: Pig Butchering 2.0 - How Scammers Are Draining Home Equity (aka: HELOC Romance Scams)

In the latest episode of Behind the Scams, we uncover the alarming rise of "pig butchering" scams, now targeting unsuspecting homeowners. As scammers evolve...

Listen

Episode 0

May 08, 2026 00:41:03
Episode Cover

Cyber Slavery & Cryptocurrency Laundering | Inside Southeast Asia's $15B Scam Farms (EP58)

In this gripping continuation of our "Fortress of Fraud" series, Nick and Sue Henley unveil the harrowing reality of cyber slavery in Southeast Asia....

Listen

Episode 0

March 19, 2025 00:30:08
Episode Cover

EP 13: Fake Love, Real Loss: The $250K Wedding/Romance Scam in Ukraine!

In this gripping episode, we delve into the heart-wrenching world of romance scams, focusing on a shocking $250,000 wedding scheme that unfolded in Ukraine....

Listen