Case study · Police case and company confirmation
Arup: deepfake fraud on a video call
An employee transferred about HK$200 million after a video call with fake versions of senior colleagues.
Principles involved
When and where
January 2024
Hong Kong
What happened
In January 2024, an employee at the Hong Kong office of a multinational received an email that appeared to come from the UK head office’s finance chief. It led to a group video call in which the finance chief and other colleagues appeared to take part. Following the instructions given, the employee transferred about HK$200 million, around US$25 million, to five bank accounts.
The people on the call were fakes. Hong Kong’s government told the Legislative Council that police believe the video was pre-recorded from public clips, so nobody on it interacted live. In May 2024 the engineering firm Arup confirmed it was the company involved. It said fake voices and images had been used, and that its internal systems were not compromised.
What the sources establish
The government’s reply to the Legislative Council describes the case without naming the company. Arup’s confirmation comes from its statements to the press, including the South China Morning Post. Early press reports described a live deepfake call, while the police account points to pre-recorded video.
Implications
No system was hacked. The fraud worked because a familiar face and voice felt like proof, and the request came with urgency and secrecy. AI made the faces cheap. The defense is a process that doesn’t depend on recognizing anyone.
Recommended practice
- 01Treat unusual requests for money, credentials or confidential data as unverified until you confirm them through a channel you start yourself.
- 02Call back on a number you already have, never one given in the message.
- 03Keep payments in the normal approval process, with more than one approver for large amounts, as Spain’s national cybersecurity institute recommends.
- 04Report attempts, including the ones that failed.
Sources
What each source establishes, and its limits. The practices and recommendations on this page are ours, and the facts come from the sources. See every source we use.
- LCQ9: Combating frauds involving deepfake Government of the Hong Kong SAR (reply to the Legislative Council) · June 26, 2024 · Government statement Describes the case: a phishing email posing as the UK head office’s finance chief led to a group video call, and the employee transferred about HK$200 million to five bank accounts. Police believe the video was pre-recorded from public clips. Limits: Doesn’t name the company.
- UK multinational Arup confirmed as victim of HK$200 million deepfake scam that used digital version of CFO to dupe Hong Kong employee South China Morning Post · May 17, 2024 · News report Reports Arup’s confirmation that it was the company in the Hong Kong deepfake case, and police figures on the transfers. Limits: A news report. Early reports described a live deepfake call, while the police account points to pre-recorded video.
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (I-120324-PSA) FBI Internet Crime Complaint Center · December 3, 2024 · Public service announcement Warns that criminals use AI-generated voice, images and video to impersonate people, and advises hanging up and calling back on a number you look up yourself. Limits: Aimed at US consumers.
- Suplantación del CEO utilizando la técnica de inteligencia artificial deepvoice INCIBE, Spain’s national cybersecurity institute · January 9, 2024 · Official case note (in Spanish) Describes a company that paid a fraudster after an AI-cloned voice of its chief executive called; advises confirming through a channel where you know who you’re talking to, never authorizing payments by phone and requiring more than one approver for large payments. Limits: An anonymized helpline case.
Cite this page
Founderz (2026). Arup: deepfake fraud on a video call. The RUAI Standard, 2026 edition. Developed by Founderz in collaboration with Microsoft. https://responsibleai.founderz.com/toolkit/case-studies/arup-deepfake-video-call-fraud
Licensed under CC BY 4.0: share and adapt with attribution.