Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

What controls would have stopped this nearly $1 million…

A Texas dealership lost nearly $1 million after scammers posing as bank employees convinced executives to initiate 12 unauthorized wire transfers within…

Incident date
Jul 2026
Target
Unidentified multinational company
Updated Jul 20, 2026 · 1 min read

In July 2026, a Texas-based dealership fell victim to a sophisticated business email compromise scam that resulted in the loss of nearly $1 million. Scammers impersonating employees from the company's long-term banking partner successfully manipulated executives into approving 12 separate wire transfers in just over 60 minutes.

What happened

The incident relied on social engineering and the abuse of trust rather than deepfake technology. The attackers presented themselves as credible representatives of the dealership’s bank, possessing sufficient internal knowledge to appear legitimate to the targeted executives. By maintaining a high-pressure environment, the scammers successfully bypassed standard verification protocols.

While the attackers did not utilize AI-generated voice or video synthesis in this specific instance, the case highlights the vulnerability of organizations when established communication channels are compromised. Industry experts suggest that the breach likely involved the acquisition of sensitive credentials, potentially through the sharing of codes from multi-factor authentication prompts that explicitly warn users against disclosure. The speed of the transfers suggests that the scammers gained direct access to the company's online banking portal. Financial security professionals note that this incident could have been prevented by adhering to standard internal controls, such as implementing dual-approval requirements for wire transfers and enforcing mandatory out-of-band verification. Specifically, the scam could have been thwarted if the executives had simply hung up and initiated a call to their official, known bank contact to verify the requests independently. Treasury departments are advised to never approve externally requested payments without rigorous internal validation, regardless of the perceived urgency or the familiarity of the caller.

Sources