The latest deepfake numbers give CISOs plenty to worry about
A finance employee at a Hong Kong firm was deceived into transferring over $25 million after participating in a video call featuring deepfake executives
- Incident date
- Jan 2024
- Target
- an unnamed multinational firm's Hong Kong branch employee
In 2024, a finance employee at the Hong Kong branch of a multinational firm was deceived by a sophisticated deepfake attack during a professional video call. The employee, believing they were communicating with the company's CFO and several other colleagues, ultimately transferred over $25 million to accounts controlled by the scammers.
What happened
The incident involved the use of deepfake technology to impersonate multiple company executives simultaneously during a single video meeting. By presenting a convincing, real-time simulation of leadership, the attackers successfully manipulated the finance employee into authorizing significant financial transfers. This case is frequently cited as a primary example of how AI-powered fraud can bypass traditional human verification methods by leveraging the perceived legitimacy of colleagues and superiors in a video conference environment. Experts note that as generative models continue to improve, detecting such attacks through visual or auditory analysis alone is becoming increasingly difficult, necessitating a shift toward rigorous, multi-channel verification protocols for all high-risk financial transactions.