Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

Arup AI media incident — Oct 2026

A finance employee at Arup was deceived by a video call featuring AI-generated executives, resulting in $25.6 million in fraudulent transfers.

Reported date
Oct 9, 2026
Target
Arup

The exact incident date was not established. This entry is dated by its source report.

Updated Oct 10, 2026 · 1 min read

In 2024, a finance employee at Arup’s Hong Kong office was targeted in a sophisticated social engineering attack that leveraged generative AI to facilitate a massive financial fraud. The incident serves as a primary example of how synthetic media can be used to bypass traditional security protocols by impersonating trusted leadership.

What happened

The attack began with a phishing email that impersonated the company's CFO. This initial contact was followed by a video conference call, which the employee joined under the impression that they were meeting with several company executives to discuss a confidential transaction. During the call, the employee recognized the faces and voices of the participants, leading them to believe the request was legitimate.

In reality, every other participant on the video call was a deepfake. The attackers utilized a combination of face reenactment and voice cloning to create a convincing, interactive simulation of the executives. By framing the request as a confidential matter, the attackers discouraged the employee from verifying the instructions through other communication channels. Consequently, the employee executed 15 separate transfers, resulting in a total loss of $25.6 million in a single day.

Sources