Unnamed Hong Kong engineering firm AI media incident
An employee at a Hong Kong engineering firm was deceived into transferring $25 million after participating in a video conference featuring AI-generated.
- Reported date
- Sep 30, 2026
- Target
- Unnamed Hong Kong engineering firm
The exact incident date was not established. This entry is dated by its source report.
An employee at a Hong Kong engineering firm was targeted in a sophisticated fraud scheme that resulted in the loss of $25 million. The incident highlights the growing risks posed by AI-generated content in corporate environments, where traditional security measures may fail to detect social engineering tactics that leverage fabricated identities.
What happened
The attack began when an employee received a message appearing to originate from the company’s chief financial officer, requesting a series of financial transfers. Although the employee initially felt suspicious regarding the request, they were persuaded to proceed after participating in a video conference. During this call, the employee interacted with individuals they believed to be the CFO and other trusted colleagues. In reality, every participant on the call—with the exception of the employee—was an AI-generated deepfake.
The fraudsters did not need to penetrate the company's internal network to execute the theft. Instead, they utilized deepfake technology to create convincing audio and visual representations of executives, successfully manipulating an honest employee into initiating the transfers. Because the employee was authorized to perform such transactions, the payment orders satisfied standard account-level security measures, despite the underlying decision being induced by a fabricated identity. This incident underscores a critical gap in current payment security frameworks, which typically verify the identity of the person initiating a transaction rather than the legitimacy of the instructions provided to them.