In early 2024, a finance employee at the engineering firm Arup joined a video call with colleagues he recognized, including the company’s CFO.
Every other person on that call was generated. He approved roughly $25.6 million across 15 separate transfers before anyone caught it.
The case gets cited so often it has started to feel like a curiosity, a strange one-off from Hong Kong. It isn’t.

The mechanism behind it, synthetic voice and video used to clear a human verification step, has gotten cheap enough to point at mid-sized manufacturers, regional distributors, and two-partner accounting practices.
Almost every control sitting between a payment request and an outgoing wire was designed around one assumption: that a person on the other end of a call can be identified by how they look and sound. That assumption no longer holds, and finance teams are the ones absorbing the consequences.
The attack stopped requiring a hacker
Voice cloning used to be a research demo. McAfee researchers demonstrated in 2023 that roughly three seconds of recorded audio produced an 85% voice match using publicly available tools.
Any executive who has spoken on a webinar, a podcast, or an earnings call has already published the raw material.
The economics collapsed alongside the technical barrier. Cloning services sold on criminal marketplaces now run under $20 for a usable voice model.
The person running the scheme doesn’t need to breach your network, escalate privileges, or move laterally through your file server. They need a LinkedIn org chart, a public recording, and a plausible reason for the CFO to be calling on a Friday afternoon.
The reported numbers reflect that shift. In 2025, the FBI added AI-related fraud as a formal crime descriptor for the first time in the 26-year history of its Internet Crime Complaint Center, logging more than 22,000 complaints and roughly $893 million in losses.
Business email compromise, increasingly assisted by synthetic media, accounted for another $3.05 billion across 24,768 complaints. Both figures undercount reality, since companies that wire money to a fraudster rarely volunteer the story.
Your approval workflow recognizes people, it doesn’t verify them
Look at how payment authority actually works inside most companies. There’s a dollar threshold, a second approver above it, and an unwritten rule that anything unusual gets a phone call. That last step was the real control. It worked because a familiar voice was hard to fake.
Microsoft’s 2025 Digital Defense Report put a number on how much damage this narrow attack category does: BEC made up 2% of observed threats but 21% of attack outcomes.
The Association for Financial Professionals reported that 76% of U.S. organizations experienced attempted or actual payments fraud in 2025, with about 74% affected by BEC specifically.
These are not exotic incidents happening to unlucky companies. They are the ordinary operating conditions of a finance department.
Dual approval doesn’t help as much as people assume, either. Two approvers who both received the same fabricated call from the same fabricated voice are not two independent checks. They are one check performed twice.
The control only does its job when the second person verifies through a different channel than the first, and almost no approval matrix specifies that.
Timing makes it worse. Attackers watch the calendar the same way your controller does. Quarter close, the week before a filing deadline, the stretch when your accountant is requesting documents and your AP inbox is full of legitimate unusual requests. That’s when a fabricated wire instruction stops looking fabricated.
The handoff to your accountant is the quiet part of the problem
Think about what leaves your company during a tax or audit cycle. Prior-year returns. Payroll registers with full Social Security numbers. Bank statements with routing and account numbers. Beneficial ownership details.
Entity EINs. It moves out of your systems, sits in somebody’s inbox, gets forwarded to a staff accountant, and lands on a laptop you have never seen.
Fraudsters know this window exists, and they know both sides of it are distracted. The most common play isn’t a dramatic deepfake video call. It’s a lookalike domain, a thread hijack on a real email chain, and a request for one more document.
The controls that close this gap are unglamorous. Protecting financial data during the accounting handoff comes down to encrypted portals instead of email attachments, multi-factor authentication on every login that touches tax records, and a verbal callback on any request that involves a payment or a change to one.
Tools like ShareFile and SafeSend exist for exactly this reason, and the friction they add is measured in seconds.
Ask your accounting firm which portal they use and whether their staff has been trained on thread hijacking.
If the answer is that they mostly work over email because clients find portals annoying, you have identified a real exposure in your own controls, not just theirs.

Detection is a losing race, so provenance becomes the control
The instinct in most security programs is to buy a detector. Feed the call audio through a model, flag the synthetic ones, move on.
Regula’s 2024 research put average deepfake-related losses at around $603,000 per affected financial-sector company, with fintechs closer to $637,000.
Firms in that bracket are not short on security tooling. They lost the money anyway, because the fraud arrived through a channel the tooling wasn’t watching.
Detection works until the generators improve, which they do on a faster cycle than detection vendors ship updates. Industry forecasts already anticipate meaningful gains in evasion rates over the next few years.
Building your fraud program on the premise that software will reliably tell you what’s fake puts you in a permanent catch-up position.
The more durable approach flips the question. Instead of asking whether an incoming message is fake, verify through a channel the attacker doesn’t control:
- Call back on a number from your own vendor master file, never the number in the email signature or the one read aloud on the call.
- Set a mandatory hold, 48 hours is common, on any change to vendor banking details, with confirmation from a second known contact at that vendor.
- Agree on a shared passphrase with your accountant and your top ten vendors for anything involving money movement. It sounds like spycraft. It costs nothing and it defeats a voice clone completely.
- Push provenance standards where you can. Content Credentials under the C2PA specification are starting to appear in enterprise video tools, and cryptographic signing of a recording is far more tractable than detecting a forgery after the fact.
What the next five years probably look like?
Deloitte’s base case projects U.S. generative-AI-enabled fraud losses reaching $40 billion by 2027, up from $12.3 billion in 2023, a compound annual growth rate around 32%. Forecasts like that age badly in either direction, but the direction of travel is not seriously contested.
Two secondary effects deserve attention from anyone doing longer-range planning. Insurers have started adding deepfake-specific exclusions and sublimits to commercial crime policies, which means the financial backstop companies assume they have may quietly shrink before the exposure peaks.
And verification is likely to migrate into the payment rail itself rather than staying a human step: confirmation-of-payee schemes, cryptographically bound vendor identities, holds triggered by anomalous instruction patterns.
Expect auditors to start asking about this in the same tone they now ask about segregation of duties. A company that cannot describe how it verifies a payment instruction is going to look, by 2030, the way a company without backups looked in 2015.
Where to start?
Pick the single workflow where a successful attack would hurt most. For most organizations that’s a change to vendor banking details, not a novel wire request.
Write down the verification step in one sentence, name the number you’ll call back on and where that number lives, and set the hold period.
Then test it by having someone outside your finance team attempt the request through normal channels and see how far they get.
You will probably find the control works fine on paper and dissolves under time pressure. Better to learn that from a drill than from a reconciliation three weeks later.
With many years of professional experience within transnational corporations in different industries, Richard Jaimes has had the opportunity to lead people and organizations, investigate future topics, create strategies and innovations, consult senior management and translate insights into business advantages. Richard is also a long time senior consultant with Quantumrun Foresight.

