"Fake CEO" deepfake fraud: the $25 million scam that stunned corporate security teams
Read: 7 minutes

Deepfake "Fake CEO" Fraud: The $25 Million Scam That Stunned Corporate Security Teams
In early 2024, an employee in the finance department of a Hong Kong-based multinational transferred $25 million to scammers after participating in a video conference with people who appeared to be his company's Chief Financial Officer and several colleagues. Every participant on the call — except for the victim — was a "deepfake" generated by artificial intelligence in real time. This case marked a turning point in the field of corporate fraud and social engineering.
How the Attack Was Carried Out
The attack followed a now-familiar pattern, significantly amplified by "deepfake" technology:
First Contact — The victim received a phishing email seemingly originating from the UK headquarters, requesting a confidential wire transfer.
Trust Validation — Suspicious, the employee agreed to a video call to verify the request.
The Deepfake Call — Attackers used real-time deepfake technology to animate public images of the real CFO and his colleagues, responding to questions using pre-recorded audio clips.
Authorized Transfer — Reassured by the apparent video confirmation, the employee executed 15 transactions totaling $25.6 million.
The fraud was only discovered several days later, when the employee directly contacted the headquarters.
The Technology Behind the Attack
Real-time "deepfake" video generation has progressed significantly. Tools that once required specialized technical expertise and substantial rendering time can now run in near real-time using off-the-shelf hardware. Key capabilities include:
Face swapping in live video streams
Voice cloning from just 3 seconds of audio
Lip-syncing to align the cloned voice with facial movements
Background replacement to simulate typical office environments.
Sources of training data are disturbingly accessible — LinkedIn profile photos, YouTube interviews, and earnings call recordings are all that attackers need.
The Scale of the Problem
This is not an isolated case. According to the Deloitte Center for Financial Services, AI-driven fraud losses are expected to reach $40 billion in the United States by 2027. The FBI's Internet Crime Complaint Center (IC3) reported a 300% increase in complaints involving deepfakes between 2023 and 2024.
How to Protect Your Organization
Implement a system of verbal codewords: pre-agreed phrases, mandatory for any sensitive financial request, regardless of the communication channel.
Require out-of-band verification: systematically confirm major wire transfers using a separate, pre-defined phone number.
Train finance teams on deepfake fraud scenarios.
Use liveness detection tools on video conferencing platforms.
Establish a dual-authorization procedure for all wire transfers exceeding a certain threshold.
The era of "seeing is believing" is over. In 2025, organizations must implement verification processes that assume visual and audio evidence can be faked. The human factor remains the final line of defense, and it must be reinforced accordingly.
Don't wait for a security breach.
The average cost of a data breach is $4.88 million.
