Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

The email-then-call sequence behind most deepfake…

The Arup deepfake incident highlights how attackers combine spoofed emails with real-time video call impersonation to bypass traditional verification

Incident date
Aug 2026
Target
Arup
Updated Aug 25, 2026 · 2 min read

In August 2026, the vulnerability of corporate communication channels was underscored by an incident involving the engineering firm Arup. A finance employee was targeted by a sophisticated scheme that successfully bypassed standard verification instincts by utilizing real-time synthetic media. This event serves as a critical case study on why traditional security measures—specifically the reliance on video calls for identity confirmation—are no longer sufficient against modern generative AI tools.

What happened

The attack followed a calculated sequence that leveraged the psychological impact of multi-channel communication. It began with an email, typically sent from a lookalike domain, which introduced an administrative request that initially sparked suspicion in the employee. However, the attackers escalated the request by initiating a video conference call.

During this call, the employee was presented with video and audio of individuals they recognized as company executives, including the CFO. Because the call successfully mimicked the authority and urgency of these figures, the employee’s prior skepticism regarding the email was resolved. In reality, every other participant on the video call was a deepfake. The attackers utilized real-time face swapping and voice cloning, which can now be generated from as little as 10 seconds of public audio.

This incident demonstrates that the cost and technical barriers to executing these scams have dropped significantly. Because the software integrates directly into standard conferencing platforms like Zoom or Teams, the visual and auditory output appears seamless to the victim. Following the call, the employee, believing they were acting under the direction of legitimate leadership, authorized approximately US$25 million in transfers. The incident highlights that seeing a face or hearing a familiar voice on a live call is no longer proof of identity. Effective defense now requires cross-channel verification, such as confirming requests received via email through a phone number found in an internal directory, or validating phone instructions through a secondary, secure written system that the caller does not control.

Sources