An employee joins a video meeting, recognises senior colleagues and follows instructions to transfer company funds. But the people on screen are digital impersonations. This happened at engineering consultancy Arup in 2024, when a deepfake fraud in Hong Kong resulted in losses of HK$200 million — approximately US$25.6 million.
Familiar faces, fraudulent instructions
The employee believed they were attending a conference with the company’s chief financial officer and other representatives. According to reporting citing Hong Kong police, the deception led to 15 transfers into five bank accounts over a week in January.
Arup confirmed in May 2024 that it was the company involved. The case demonstrated how convincing impersonations could turn an apparently routine business interaction into a major financial loss.
When recognition becomes a vulnerability
The threat lay in the apparent credibility of the meeting. A suspicious written request might prompt an employee to seek confirmation. Seeing familiar faces and hearing apparently familiar voices can create the impression that confirmation has already been obtained.
In this case, the supposed participants were part of the deception. The incident illustrates how AI-generated media can exploit workplace trust and the authority attached to senior positions.
The technology gave fraudsters another way to make instructions appear legitimate, with consequences extending beyond misleading content into actual financial transactions.
A challenge for everyday business
The implications reach beyond large multinational companies. Remote meetings and digital payment instructions are common features of business communication.
A convincing image or voice cannot, by itself, establish that a person is who they claim to be. The same principle applies when an apparent executive requests an urgent payment or a supposed supplier changes banking details.
Independent confirmation through an established contact channel, combined with separate payment approval, can help prevent one deceptive interaction from authorising a transfer.
The danger is already practical
Arup’s experience provides a concrete example of AI being used to facilitate financial crime. The victims were responding to what appeared to be human authority.
For organisations adopting increasingly digital workflows, the lesson is specific: identity and payment authority need verification beyond the face and voice presented on a screen.
Newshub Editorial in Asia – 1 October 2026
An employee joins a video meeting, recognises senior colleagues and follows instructions to transfer company funds. But the people on screen are digital impersonations. This happened at engineering consultancy Arup in 2024, when a deepfake fraud in Hong Kong resulted in losses of HK$200 million — approximately US$25.6 million.

Recent Comments