A finance employee at Arup received a video call. The person on screen looked like the group CFO. They sounded like the CFO. They gave wire transfer instructions. The employee authorized 15 transfers in a single day. US$25 million moved before anyone realized the CFO on the call was artificial. This attack—one video call, one fabricated executive, one devastating loss—represents a fundamental shift in how cyber crime works.
The Attack Looked Real Because It Was AI-Generated
The attacker didn’t hack the video conferencing system. They didn’t compromise Arup’s network. They generated a deepfake video of the CFO using AI tools. The audio was synthesized to match the CFO’s voice. When the finance employee answered the call, they saw what appeared to be their actual CFO authorizing wire transfers.
There was nothing obviously artificial about the call. The video quality was high. The audio was natural. The instructions were credible because they came from someone who looked and sounded like the person authorized to give them.
This is the first shift: deepfakes are now indistinguishable from reality. An employee can’t tell the difference between a real CFO and a fabricated one. The attacker doesn’t need to compromise systems. They just need a convincing video.
Multi-Participant Deepfakes Make The Attack More Convincing
Single deepfake calls are suspicious. One person on a video call authorizing unusual transactions might trigger questions. But what if the call included multiple executives? What if the CFO was joined by the COO and the board chairman, all deepfaked, all confirming the wire transfer?
Attackers are now creating multi-participant deepfake meetings where multiple fabricated executives appear on the same call, creating false consensus. An employee seeing three deepfaked executives all agreeing on a wire transfer is far less likely to question the request.
The attack escalates from “one suspicious call” to “multiple executives confirming the same instruction.” The psychology shifts from skepticism to compliance.
Before The Deepfake Call Comes Personalized Phishing
The deepfake video call didn’t happen in isolation. Before it occurred, the target received personalized phishing emails. These weren’t generic messages. They referenced the employee’s actual role, their actual manager, and actual company details.
An AI tool had already profiled the organization and identified the finance employee as the target. It generated phishing emails specifically designed to make that employee trust subsequent communications. By the time the deepfake call arrived, the employee had already been primed to expect contact about wire transfers.
Traditional phishing sends the same message to thousands of people. AI-generated phishing creates thousands of unique messages, each tailored to a specific person. The volume and personalization exceed what human awareness training can address.
The Attacker Already Knows Your Infrastructure
Before executing the attack, the attacker needs intelligence. Who is the CFO? What is their authority level? Who reports to them? What is the company’s wire transfer process? What are the approval thresholds? Which financial institutions does the company use?
This reconnaissance used to take weeks of manual work. AI reconnaissance tools now answer these questions in hours. They scan your website, LinkedIn profiles, org charts, SEC filings, and banking information. They build a complete picture of your company’s structure, decision-making authority, and financial flows.
The reconnaissance happens invisibly. There’s no alert when an AI tool profiles your infrastructure. By the time you’re aware of the threat, the attacker has already completed their homework and moved to execution.
Where Does This Loss Actually Land?
The Arup deepfake attack resulted in a $25 million voluntary wire transfer. It’s not a data breach. It’s not malware or ransomware. It’s not employee theft or embezzlement.
So which insurance policy responds?
That’s the question organizations need to answer before the next deepfake attack occurs. The answer isn’t straightforward. And that gap between the threat and the coverage is where organizations absorb losses they shouldn’t have to.
Before deepfakes hit your organization, review your policies and understand what’s actually covered. Continuum helps organizations map deepfake risk across their insurance portfolio.
Contact Continuum to understand your coverage when deepfakes occur.
