Everyone on the Call Was Fake but Him: The $25 Million Arup Deepfake Meeting

by Warrier | Jun 24, 2026 | Case Files

A cautious employee suspected the email — so he asked for a video call to be sure. The CFO was there. So were his colleagues. Every one of them was a deepfake, and $25 million was gone within the week. Inside the Arup case: how a fake meeting beat a trained professional's correct instinct, and the simple, non-technical controls that would have stopped it cold. Members only.

Case Summary

In January 2024, a finance employee at the Hong Kong office of Arup — the London-based engineering firm behind the Sydney Opera House and Beijing's "Bird's Nest" stadium — was tricked into making 15 transfers totalling roughly HK$200 million (about US$25.6 million) to five bank accounts controlled by fraudsters. He did so after a video conference call with the company's chief financial officer and several colleagues. Every participant on that call except him was an AI-generated deepfake. Arup later publicly confirmed the incident, with a spokesperson stating that fake voices and images had been used and that no internal systems were compromised.

It remains one of the largest and most fully documented AI-enabled frauds on record — and the case that turned "deepfake video call" into shorthand for a new category of corporate risk.

Why This Case Matters

For the entire history of business, "I spoke to them — I saw their face" has been the gold standard of confirmation. The Arup case is where that standard publicly broke. The employee was not reckless; he was cautious, suspected the initial email, and did exactly what security training advises — he asked for a video call to verify.

The verification step was the trap. When the threat can fake the very channel you use to check, every instinct that once protected you becomes the mechanism of the loss.

Source Notes

The facts are drawn from the victim organisation's own confirmations to CNN, the Financial Times and Fortune (May 2024) — including the spokesperson's confirmation that fake voices and images were used and that internal systems were not compromised, and CIO Rob Greig's statements on rising attack sophistication and his own open-source deepfake test relayed to the World Economic Forum. The incident mechanics, transaction count, the HK$200 million / US$25.6 million figure, the five recipient accounts, the discovery via head-office follow-up, and the February-to-May 2024 disclosure sequence are corroborated across CNN, Fortune, CFO Dive and the OECD/AI Incident Database (Incident 634). Statements by Hong Kong police regarding broader, similar deepfake scams are attributed to that wider crackdown and not presented as the Arup perpetrators. Defensive guidance is synthesised from the same reporting and standard finance-control practice.

MEMBERS ONLY — THE FULL CASE FILE CONTINUES BELOW

🔒 This analysis is for warrier.ai Intelligence members only. → Become a Member

Already a member? Log in here

"

advertising

Buy the world How hungry are you? Which country do you want to buy? Become a part of net art history.