Arup Deepfake Scam: How a Fake Video Call Led to $25.6 Million in Losses

Arup Deepfake Scam: How a Fake Video Call Led to $25.6 Million in Losses

A finance employee at engineering firm Arup's Hong Kong office received a message that appeared to come from the company's chief financial officer in the United Kingdom.

The request involved a confidential transaction. Then came something more convincing than an email.

The employee joined a group video conference.

The CFO appeared on screen with other familiar colleagues. Their faces looked right. Their voices sounded familiar. The meeting appeared to confirm that the request was legitimate.

There was one problem.

Nobody else on the call was real.

Fraudsters had created digital versions of the executives and employees using publicly available video and voice material. Hong Kong authorities later said the conference had been pre-recorded.

After the meeting, payment instructions continued through instant messaging. The employee eventually authorized 15 transfers to five Hong Kong bank accounts totaling HK$200 million, about US$25.6 million. Arup later confirmed that it was the company targeted.

The case is striking because the fraud did not depend on an unknown caller or an obviously suspicious message.

The employee saw familiar people.

That is what made the request convincing.

Traditional deepfake advice often tells employees to watch for unusual blinking, distorted facial movements, or unnatural speech. Those checks can still help, but the Arup case raises a harder question:

What happens when the fake looks good enough?

Higher-risk transactions cannot depend entirely on someone's ability to spot manipulated media. Businesses need independent identity and authorization checks that do not rely on the same video, voice, email, or message that initiated the request.

The Arup Deepfake Case Exposed an Identity Verification Gap

Calling the incident a deepfake scam describes the technology. It does not fully explain why the transaction succeeded.

Several signals appeared legitimate at once: a senior executive's request, familiar faces, familiar voices, apparent colleagues, and instructions tied to a confidential transaction.

The weakness was that all those signals came through channels the fraudsters controlled.

A stronger process introduces information from somewhere else. That might mean calling an executive through a number already stored in the company directory, requiring another approval through an established system, or comparing submitted identity information with existing records.

The goal is not simply to prove that a video is fake. It is to determine whether enough independent information supports the identity and request before the business acts.

Why Deepfake Fraud Is Becoming a Business Risk

An April 2026 Surfshark analysis reviewed publicly reported deepfake fraud incidents from January 2019 through March 2026.

It identified $2.19 billion in documented global losses, including $1.65 billion during 2025. The United States accounted for $712 million, while corporate attacks represented 43% of reported U.S. losses in the dataset.

Those figures have limits. Surfshark compiled publicly reported incidents with documented financial losses using several databases and published reports. The total is not an official government count, and unreported cases would not appear.

Still, the findings show why deepfake fraud is more than an employee-awareness issue. It affects any workflow where a business must decide whether the person requesting money, access, employment, or approval is really who they claim to be.

How Deepfake Identity Fraud Affects Different Industries

Financial services: A customer requests a large transfer or changes payment details after a video conversation. The team can still verify through established contact information, account history, or another approval channel.

Insurance:
A claimant provides complete information, but the submitted address or phone history conflicts with existing policy records. Another identity check may be appropriate before a higher-risk payment or account change.

Lead generation: A lead contains a name, phone number, email, and address, but some fields appear associated with different people. The record may be outdated, incorrect, or fraudulent. The team may correct it, verify it through another source, or hold it for review.

HR and remote hiring: A candidate may perform well during a video interview without being the person represented in the application.

On April 15, 2026, the U.S. Department of Justice announced sentences for two U.S. nationals who helped North Korean IT workers pose as U.S.-based employees. The operation used at least 80 stolen U.S. identities, reached more than 100 companies, and generated over $5 million.

Related risks can also appear with synthetic identity fraud, where real and fabricated information may be combined into an identity that appears legitimate.

4 Identity Checks Before Acting on a Higher-Risk Request

Deepfake detection can remain part of employee training, but it should not be the only safeguard. The following checks can help when a video or voice call appears convincing and nothing on screen looks obviously wrong.

1. Verify Through a Trusted Channel

Use contact information established before the unusual request arrived.

A finance employee can call an executive through a number already stored in the company directory instead of one supplied in the current message. The second check should come from a channel the requester does not control.

2. Cross-Check Several Identity Details

Compare available information such as names, aliases, addresses, phone numbers, emails, and existing customer or employee records.

Consistent information may support normal processing. Conflicting information may justify another review.

Neither result proves fraud or identity ownership.

3. Use Stronger Identifiers When Appropriate

A large transaction, new account, payroll setup, or sensitive account change may justify stronger identity checks when the business has a lawful purpose and appropriate access.

Checking whether a submitted Social Security number matches the claimed name, for example, can add another signal.

A match does not prove that the person submitting the information owns the SSN. Stolen identity information may also match legitimate records.

4. Decide What a Mismatch Triggers

Teams should know what happens when information does not align.

Possible actions include requesting another document, contacting the person through a known channel, correcting data, running another check, temporarily holding the transaction, or escalating the record for manual review.

A discrepancy should support proportionate review rather than automatic rejection.

How Searchbug Tools Help Verify Identity Behind a Request

Searchbug does not determine whether a video is AI-generated. Instead, its tools help organizations verify whether the identity behind a transaction, application, or request aligns with available records.

Build a Broader Identity and Contact Picture

Searchbug's People Search API can return names and aliases, current and historical addresses, phone numbers with line type, relatives, and available public-record indicators.

Teams can compare those results with submitted information. A different address history or phone association may justify correction or another verification step.

The result does not establish that the person communicating with the business owns that identity.

Check Whether an SSN and Name Align

For permitted business uses, SSN and Name Match can check whether a submitted Social Security number matches the submitted name.

The result can add another identity signal when an application, employment record, or fraud review needs stronger verification.

A match shows that the supplied information aligns according to available records. It does not prove that the person submitting it is the rightful owner of the identity.

Review Deeper Public-Record Context

A Background Check can provide additional context when earlier checks identify a reason for deeper review.

Available records may include address and phone history, emails, relatives, corporate filings, professional licenses, liens, judgments, bankruptcies, criminal records, and other public information.

These records can support a broader identity review. They do not prove fraud, intent, or who is behind a video call. Organizations should also confirm that the data and intended use are appropriate for employment or other regulated decisions.

TL;DR

An Arup employee authorized $25.6 million in transfers after joining a deepfake video conference that appeared completely legitimate. The case shows why businesses should rely on independent identity verification, not just familiar faces or voices, before approving higher-risk requests.

Searchbug's People Search API, SSN and Name Match, and Background Check can provide supporting identity signals to help verify identity across financial services, insurance, HR, and other high-risk workflows. No individual result proves fraud or confirms identity ownership.

Create a free Searchbug API Test Account with $10 in credits to test the relevant identity tools with your workflow. Teams reviewing larger files or working without an API can also use Bulk Processing.

Data Verification

Arup Deepfake Scam: How a Fake Video Call Led to $25.6 Million in Losses