Deepfake Fraud — How Companies Lose Money to Fake CEOs, and How to Defend Against It
RETURN_TO_BLOG
AI & Security 14 min

Deepfake Fraud — How Companies Lose Money to Fake CEOs, and How to Defend Against It

Paweł Wiszniewski
Paweł Wiszniewski
SEO & GEO Specialist · AI Engineer

In January 2024, a finance employee at the Hong Kong office of engineering firm Arup joined a video conference with the "CFO" and several "colleagues" from headquarters. Everyone looked and sounded exactly as they should — because the attackers had already harvested publicly available recordings from webinars, interviews, and conferences to train deepfake models on. After the call, the employee executed 15 wire transfers totaling $25.6 million before anyone realized there hadn't been a single real person in that video room besides him. This isn't an isolated case from a faraway country — it's a template that fraudsters worldwide, Poland included, have been copying throughout 2025 and 2026.

Poland's NASK checked: 66% of Poles can't tell a cloned CEO voice from the real one. In 2025 the FBI broke out AI as a standalone fraud category for the first time ever — 22,364 complaints and $893 million in losses. The single biggest case: $25.6 million wired after one video call with a deepfake fake CFO. This isn't conference-talk science fiction anymore — it's a real risk for any company with a finance department and a phone. Here's the anatomy of the attack, the procedures that stop it, and why “spotting the fake” alone is a losing strategy.

This post closes the security cluster from the external-threat side. Prompt injection and LLM application security describes attacks ON the AI systems you build or deploy yourself. This post describes the opposite: AI attacks ON your company, aimed not at code, but at the people with access to a bank account.

The scale of the problem — from Hong Kong to Poland

/// THE SCALE OF AI FRAUD — FROM HONG KONG TO POLAND

$893M
22,364 AI-related fraud complaints — the first such category in IC3’s 25-year history
FBI IC3, 2025
$25.6M
15 wire transfers executed in a single day after one video call with a deepfake CFO
Arup, Hong Kong
$3.5B
lost to impersonation scams, including ~$1B tied to business impersonation specifically
FTC, 2025
66%
of Poles can’t tell a cloned AI voice from a real one; 13,200+ deepfake ads detected
NASK

In 2025 the FBI, for the first time in the Internet Crime Complaint Center's (IC3) 25-year history, broke out artificial intelligence as a standalone fraud category: 22,364 complaints and $893 million in losses, the largest share of which — $632 million — was investment fraud featuring deepfakes of well-known people endorsing fake platforms. The FBI openly states the real scale is significantly higher, since most victims never realize AI was involved in the attack against them. In parallel, the FTC recorded $3.5 billion in losses from impersonation scams in 2025 — including nearly a billion dollars in losses tied to business impersonation specifically.

Closer to home: according to NASK, Poland's national research institute, 66% of Poles cannot tell a cloned AI voice from a real one, and the institute detected more than 13,200 ads using deepfakes, including the likenesses of public figures and bank CEOs, directing people to fake investment platforms. This shows the infrastructure for producing convincing voice and video fakes is now widely accessible — the problem isn't technological, it's organizational: does your company have a procedure that works even when the voice on the phone sounds identical to the CEO's?

The anatomy of an attack — how it actually happens, step by step

/// THE ANATOMY OF A DEEPFAKE CEO FRAUD ATTACK

A repeatable structure, seen from Hong Kong down to smaller, less publicized cases

01
RECONNAISSANCE
Harvesting public voice and face recordings from webinars, interviews, LinkedIn — seconds are enough
02
PRETEXT
Time pressure plus a request for secrecy — together these block normal verification
03
EXECUTION
Number spoofing, a real-time deepfake video call, sometimes an email from a compromised account as "confirmation"
04
CASH-OUT
Accounts prepared in advance, instant transfer, and immediate dispersal of funds

A deepfake CEO fraud attack isn't random — it has a repeatable structure, visible both in the Arup case and in smaller, less publicized incidents:

  1. 1.Reconnaissance. Attackers gather publicly available voice and face recordings of the target — webinars, press interviews, conference footage, even short LinkedIn or YouTube clips. Cloning a voice today takes as little as ten to a few dozen seconds of clean audio and a free or cheap tool.
  2. 2.Pretext. The scenario always contains two elements: time pressure ("the transfer has to go through by end of day") and confidentiality ("don't mention this to anyone, it's a sensitive deal/acquisition"). Together these two elements prevent the victim from verifying through normal channels.
  3. 3.Execution. Contact happens over a spoofed phone number, a real-time deepfake video call, or a combination of both — sometimes backed by an email from a forged or compromised account to "confirm in writing."
  4. 4.Cash-out. The money lands in accounts prepared in advance — in Arup's case, the attackers had five Hong Kong bank accounts ready before making first contact with the employee. Funds are dispersed and withdrawn immediately, before the bank or the victim can react.

Three attack vectors — not every deepfake looks the same

VectorHow it worksWarning sign
Voice CEO fraud (vishing)A cloned CEO voice calls from a spoofed number, demanding an urgent transferTime pressure + a request for secrecy + an unusual contact method for that person
Video CEO fraudA real-time deepfake on a video call, as in the Arup caseThe call is suddenly initiated, participants don't react to unusual control questions
AI-generated invoices and documentsA fake invoice or payment instruction with realistic company details, generated by a language modelA changed bank account number in an email "from a regular vendor," small errors in registration details

The third vector is often overlooked, yet growing just as fast — a language model can now generate an invoice indistinguishable from the original based on a handful of examples found online or stolen from a compromised mailbox, which connects this threat to classic BEC (Business Email Compromise) covered in more depth in AI email automation — the same channel companies use to streamline correspondence is also the main entry vector for fraudsters.

Deepfake-resistant procedures — a defense that doesn't rely on "spotting" the fake

/// PROCEDURES THAT WORK REGARDLESS OF THE FAKE’S QUALITY

Don’t build your defense on someone spotting the deepfake

01
SECOND-CHANNEL VERIFICATION
Hang up and call back a known number — never the one the request came from
02
THRESHOLDS WITH DUAL AUTHORIZATION
Every transfer above a set amount needs approval from a second, independent person
03
A COMPANY OR FAMILY PASSPHRASE
Agreed offline in advance, unrelated to business context — a voice clone can’t guess it
04
URGENCY = A RED FLAG
Time pressure and a request for discretion are attack signals, not a measure of importance

The most important lesson from deepfake detection research is this: don't build your defense on someone recognizing the fake. Detection tools perform worse against newer models (diffusion models produce harder-to-catch artifacts than older GANs), audio and video compression on WhatsApp or a phone call destroys exactly the signals detection algorithms rely on, and an attack delivered over a private channel (SMS, WhatsApp, a direct phone call) never reaches any corporate detection system at all. Instead of relying on recognition, build a procedure that works regardless of how good the fake is:

  • Second-channel verification — always initiated by you. If you get a call or video request for a wire transfer, hang up and call back a number you already have on file — never the number that called you, and never a number given in that same message.
  • Amount thresholds with dual authorization. Every transfer above a set threshold requires approval from a second, independent person — no exceptions, even when "the CEO is personally pushing for it."
  • A company or family passphrase. Agree in advance, offline, on a codeword unrelated to any business context, one a real supervisor would know and an attacker — even with a perfect voice clone — has no way to guess.
  • The "urgency is a red flag" rule. Time pressure and a request for discretion aren't signs of how important something is — they're the single most recognizable pattern of a social-engineering attack, AI or not.

Detection tools — helpful, but not sufficient on their own

/// DETECTION TOOLS — THE LIMITS WORTH KNOWING

An extra layer, not your main line of defense

WHAT DETECTION GIVES YOU
  • An extra warning signal on a suspicious recording
  • Real-time video traffic scanning at larger organizations
  • After-the-fact verification of recordings, for investigation
  • A supplementary layer — never a replacement
WHAT IT DOESN’T DO
  • Doesn’t keep up with the newest diffusion models
  • Doesn’t survive audio/video compression (phone, WhatsApp)
  • Never sees an attack delivered over a private channel
  • Doesn’t assess context or the transaction’s business logic

Deepfake detection tools have genuine value as an additional layer — especially for verifying recordings after the fact or scanning real-time video traffic at larger organizations. But they have structural limitations worth knowing before you treat them as your main line of defense: effectiveness depends heavily on the generation method and compression level of the recording, detection by definition lags behind generation (a detection model learns from existing samples, while new generation techniques appear faster), and no tool assesses the context or intent of a conversation — it might flag a recording as suspicious, but it won't tell you whether the transaction makes business sense. Treat detection as an extra warning signal, never a substitute for a verification procedure.

Training the finance team — the single most important investment you can make

The finance and accounting team is the group most exposed to this type of attack — they're the ones with account access and the authority to execute a transfer. A generic "intro to AI" session isn't enough; what's needed is a scenario specific to this role: a simulated phone call under time pressure, drilling the second-channel procedure until it's automatic, and a clear message that refusing to execute a transfer until it's verified never carries professional consequences — even if the call turns out to have been genuine. How to design a program like this per role, and how it simultaneously satisfies the Article 4 AI literacy obligation, is covered in AI literacy and mandatory training.

The AI Act and deepfakes — a labeling obligation since August 2026

AI Act Article 50, which applies from August 2, 2026 (with a transitional period until December 2, 2026 for the technical marking of content generated by systems placed on the market earlier), requires providers and deployers to clearly label synthetic content — including deepfakes — as artificially generated or manipulated. This matters for the legitimate use of AI at your own company (marketing materials, for instance), but obviously has zero effect on criminals, who by definition have no intention of labeling their fakes. Labeling protects against accidental deception, not a deliberate attack — which is why the procedures above remain the only real line of defense.

A defensive checklist for the finance department

  1. 1.Implement second-channel verification for every transfer request initiated by phone or video — call back a known number, never the one the request came from.
  2. 2.Set amount thresholds with mandatory dual authorization, with no exceptions for "urgent" requests from leadership.
  3. 3.Agree on a company passphrase offline, outside any digital channel that could be intercepted.
  4. 4.Train the finance team on scenarios specific to their role, not a generic AI introduction.
  5. 5.Build a culture where refusing or delaying a transfer pending verification is never penalized.
  6. 6.Treat detection tools as an extra signal, not a substitute for procedure.
  7. 7.Monitor publicly available recordings of leadership — the less raw voice and video footage circulates publicly, the harder a high-quality clone is to make.

---

I help companies build resilience against AI-driven fraud — from auditing payment authorization procedures, through finance-team training tailored to real attack scenarios, to second-channel verification architecture. I do this as part of AI consulting and AI training for teams. Reach out — I'll start by reviewing what your company's transfer authorization process looks like today and where the biggest gap is.

Worth reading next:

/// RELATED_RECORDS

AI & Security

AI Literacy — Mandatory AI Training Under Article 4 of the AI Act: Who, What, and How

If anyone at your company uses ChatGPT to draft emails, you're a “deployer” under the AI Act — and since August 2, 2026, national market surveillance authorities can check whether you've given that person a “sufficient level of AI competence.” There's no single training template or required certificate — but there is a concrete methodology: who the obligation covers, how to design a role-based program (leadership, operations, IT), and how to document the result so it survives an inspection.

13 min
AI & Security

AI Policy at Your Company and ISO/IEC 42001 — Governance That Doesn't Kill Innovation

Six weeks ago, national market surveillance authorities across the EU got formal powers to check whether companies actually meet the Article 4 AI literacy obligation — and whether they have documents to prove it, not just good intentions. Most SMEs that have deployed AI are missing one thing: a written AI policy. Here's what such a policy must contain, how to build an AI systems register, when to reach for ISO/IEC 42001 instead of an internal document, and who at a small company should be the “AI owner” without a Chief AI Officer title.

14 min
AI & Security

GDPR and AI — Personal Data in Prompts, DPIA and LLM Vendor Agreements (Practically)

Pasted a customer's email into ChatGPT to speed up your reply? That's already personal data processing under GDPR — with the full weight of obligations most teams have never heard of. Six weeks ago Poland's data protection authority (UODO) published the first official self-assessment checklists for AI/GDPR compliance — proof the regulator is already watching, not just theorizing. When does a prompt trigger a DPIA, how does the “meaningful human involvement” test from Article 22 hold up against a lead-scoring chatbot, and how do OpenAI's, Anthropic's and Google Cloud's DPA agreements actually differ — a practical guide without the legal jargon.

15 min
/// AUTHOR
Paweł Wiszniewski – AI & Web Engineer

Paweł Wiszniewski

SEO & GEO Specialist & AI Engineer

SEO/GEO specialist (10 years) and AI engineer (3 years). I build search visibility, AI systems and automations that reduce costs and improve operational efficiency.

Signal received?

Terminate
Silence

Initiate protocol. Establish connection. Let's build something loud.

> WAITING_FOR_INPUT...