Executive Answer
In January 2024, an Arup employee wired $25.6M after a deepfake video call - she verified with the right people, followed the process, and lost the money anyway. Voice cloning requires just 3 seconds of source audio. The FBI recorded $893M in AI-related fraud losses in 2025 alone, representing fewer than 5% of actual incidents. The controls that protect against this are process-based: out-of-band verification for financial transactions, pre-shared code words between executives and finance, and strict dual-authorization for large transfers.
- $25.6M - wired by a finance employee at Arup after a deepfake video call impersonating the CFO and senior executives. January 2024. The most documented large-scale deepfake fraud case on record.
- $893M - AI-related fraud losses reported to the FBI in 2025. First year AI appeared as a formal crime category in the IC3 annual report (released April 2026).
- 3 seconds - the amount of source audio required to generate a convincing voice clone using current commercial tools. A 30-second earnings call clip provides 10x that.
- 54% - click rate for AI-generated phishing campaigns, compared to 12% for traditional campaigns, according to 2025 research published by Brightside AI.
- 5% - estimated share of AI fraud victims who actually report the crime to authorities, meaning the $893M figure represents a small fraction of actual losses.
AI has not changed what attackers want. It changed the cost of impersonation. Voice cloning, deepfake video, and AI-generated phishing have collapsed the economics of identity fraud: what once required a nation-state budget and a team now requires a laptop and three seconds of audio. The controls that protected organizations in 2022 were designed for a different threat. This article covers what breaks, what still works, and the specific steps CISOs and their finance and operations teams need to take before the next incident.
In January 2024, a finance employee at Arup joined a video conference. On the call were the CFO, three senior executives, and the CEO. She recognized them. She had worked with some of them for years. She followed the instructions they gave her and wired $25.6 million.
None of those people were real. Every person on that call was an AI-generated deepfake. The faces, the voices, the corporate context - all synthesized. The employee did exactly what she had been trained to do: she verified the request with the right people. The problem was that "the right people" were fabrications.
This is not a story about a failure of security awareness training. The employee was not careless. The controls that existed were followed. The threat had simply moved past them.
And Then There Was Ferrari
Six months later, in July 2024, a Ferrari executive received communications that appeared to come from CEO Benedetto Vigna. The scenario was similar: an urgent request, a voice that matched, pressure to act quickly.
This time, the attack failed. The executive noticed something slightly off about the vocal tone. Not dramatically wrong - just not quite right. He asked a personal question, something rooted in a shared experience that only the real CEO would know. The caller could not answer it. The attempt collapsed.
Two incidents, same technology, opposite outcomes. The difference was not the sophistication of the attack. It was whether the target had a verification mechanism that existed outside the synthetic environment the attacker had created.
The Ferrari executive had that mechanism. The Arup employee did not - not because she was less capable, but because the organization had not built one.
The Numbers Behind the Trend
The FBI's 2025 Internet Crime Report, released in April 2026, added "AI-related" as a formal crime descriptor for the first time in the agency's history. The reported losses: $893,346,472 across 22,364 complaints. Those are the cases people actually reported. Researchers consistently estimate that fewer than 5% of AI fraud victims file a report.
AI-generated phishing is part of the same picture. Research published by Brightside AI in 2025 found that AI-crafted phishing campaigns achieve click rates of 54%, compared to 12% for traditional campaigns. The gap is not marginal - it reflects a qualitative shift in how these messages are written. AI-generated phishing is personalized, contextually aware, and grammatically clean. The signals that trained employees to spot phishing - generic language, odd phrasing, spelling errors - are gone.
What this adds up to: the attack surface for identity-based fraud has expanded dramatically, the cost of executing sophisticated attacks has collapsed, and the detection signals organizations relied on are no longer reliable.
Three Verification Assumptions That No Longer Hold
Most organizational identity verification is built on assumptions that made sense before AI voice cloning and deepfake video existed. Those assumptions are now liabilities.
The voice on the phone is who they say they are. For decades, callback verification worked: you receive a suspicious request, you call the number on file, you hear the right voice, you proceed. Voice cloning breaks this completely. The voice on the other end of that callback can be synthesized from three seconds of audio taken from any public recording. An earnings call, a conference presentation, a LinkedIn video - all of it is training data. The executive does not need to have been compromised for their voice to be weaponized.
The face on the video call is the person you know. The Arup case showed that deepfake video in a multi-person conference call is not a theoretical risk - it is an operational capability that attackers are already using. Real-time deepfake tools can synthesize a convincing video of a known executive, with lip sync and plausible background. The face matches the LinkedIn photo. The voice matches. The contextual details about recent business events match because the attacker researched them.
Familiarity is a reliable detector. "I've worked with her for eight years - I would know." This is the most dangerous phrase in corporate security right now. The Ferrari executive caught the attack because he had a specific personal reference point that went beyond surface familiarity. Most people, in most professional relationships, do not have that. They know what someone looks like on screen and how their voice sounds in meetings. That is exactly what deepfake technology replicates.
What Still Works - and What the Ferrari Case Actually Teaches
The Ferrari outcome is instructive, but not because personal familiarity is a scalable defense. It is not. The reason the attack failed was more specific: the executive used a verification mechanism that existed outside the attacker's synthetic environment. A personal reference the AI could not have been trained on, and could not plausibly guess.
That principle scales. The question is whether organizations build it deliberately, before they need it.
Process-based controls are the answer here. Technology helps at the margin - there are tools that analyze video for artifacts of AI generation, and they catch some attacks. But a motivated attacker with access to current commercial deepfake tools will produce output that defeats real-time detection in most enterprise environments. The reliable control is not detection - it is a verification step that cannot be replicated by the synthetic identity.
Five Controls That Actually Address AI Identity Fraud
1. Out-of-band verification for financial transactions above threshold. Define a dollar amount above which any wire transfer requires a second confirmation through a separate channel that was not used to initiate the request. If the request came by email, verification happens by phone to a pre-registered number. If it came by phone, verification happens through a messaging channel. If it came by video call, verification requires a follow-up through a different medium. The key word is pre-registered: the contact details cannot be provided by the person making the request. They were established in advance and stored somewhere the attacker cannot influence.
2. Pre-shared code words for high-sensitivity authorization. A set of rotating code words, known only to specific executives and their finance counterparts, that are required to authorize verbal or video transactions above a defined sensitivity level. Simple to implement. Almost impossible for an attacker to replicate without prior compromise of internal systems. Ferrari's executive improvised a version of this. Organizations should formalize it.
3. Strict no-single-person authorization policy for large transfers. No individual should be able to authorize a wire transfer above a set threshold, regardless of seniority or urgency. This is not new - dual authorization for large transactions is standard practice in financial services. It is not standard practice in most other sectors. AI-powered social engineering creates exactly the scenario dual authorization is designed to prevent: pressure on one person to act quickly on behalf of a trusted authority figure. Remove the single point of failure.
4. Deepfake scenario training for finance and operations teams. General security awareness training does not adequately prepare people for deepfake attacks because the scenario is not intuitive. Run tabletop exercises where finance staff experience a simulated deepfake call. Let them feel what it is like to be 80% certain they are talking to the right person and still have to follow the verification protocol. That experience changes behavior more reliably than any policy document.
5. Explicit executive digital footprint awareness. Executives should know that every public recording of their voice and video is potential training data for an attacker. This does not mean stopping public appearances - that is not realistic or desirable. It means being conscious of what exists, ensuring internal communications channels have appropriate access controls, and understanding that a convincing impersonation of them is technically feasible and increasingly common. Executives who understand this participate differently in verification policy discussions.
The Board Conversation This Requires
AI identity fraud is a financial risk, a reputational risk, and an operational continuity risk. It is not exclusively a security team problem. The Arup case resulted in a $25.6 million loss that became public. The reputational dimension of that disclosure is separate from the financial one, and in some organizations the reputational damage outlasts the financial recovery.
Boards should be asking whether their finance authorization controls have been reviewed against the AI threat landscape in the past 12 months. Most have not been. The controls in place were designed for a world where callback verification and video recognition were reliable. Neither can be assumed to hold anymore.
The practical framing for that board conversation: what is our maximum financial exposure from a single successful deepfake authorization event, and what is our current control against it? If the answer to the second question is "we verify by calling back," the follow-up question is whether that process can be defeated by a voice clone. In most cases, the honest answer is yes.
Why Urgency Matters Here
The FBI categorized AI fraud for the first time in its 2025 report. That is not a signal that the problem is new. It is a signal that the problem has grown large enough that existing crime categories could no longer contain it.
The Arup attack happened in January 2024. The Ferrari attempt happened six months later. Since then, the tooling has gotten cheaper, faster, and more accessible. What required technical skill and significant resources in 2024 is now available in commercial form to anyone willing to pay for a subscription.
Organizations that update their identity verification controls before an incident are in a fundamentally different position from those that update them after. The cost of the controls described here is low. The cost of the incident they prevent is not.
The Arup case is important not because of the dollar amount but because of what the employee did right. She verified with the right people. She followed the process. And she still lost $25.6 million. That is what makes this threat genuinely difficult to communicate internally - the human performed correctly. The process was the problem. Most security incidents have a human failure at the root. This one did not, and that is why the controls conversation has to happen at the process and policy level, not just the training level. When I work with organizations on this, the most common gap is not awareness - it is the absence of a verification step that cannot be faked by the technology that just faked the CEO.
This is the fourth article in a series on AI and enterprise security. The series covers how AI is changing the threat landscape and what security leaders need to do about it - from deepfake attacks to shadow AI to governance and board accountability.
Related Expertise
Related Articles
AI Is Already Being Used Against You. Here's How to Fight Back.
Deepfakes, AI-cloned voices, autonomous phishing agents - the security framework every organization needs now.
Insider ThreatShadow AI: The Insider Threat Your Security Stack Can't See
Employees are pasting sensitive data into unapproved AI tools every day - and most organizations have no visibility into it.
Frequently Asked Questions
What is a deepfake BEC attack and how does it work?
A deepfake BEC attack uses AI-generated video, voice, or both to impersonate an executive in real-time communication. Unlike traditional BEC, which relies on spoofed emails, deepfake BEC places a convincing synthetic version of a known executive on a video call or phone line. The Arup incident in January 2024, where a finance employee wired $25.6 million after a deepfake video call, is the most documented large-scale example.
How much has AI-enabled fraud cost organizations in 2025?
The FBI's 2025 Internet Crime Report, released in April 2026, recorded $893,346,472 in losses from AI-related fraud - the first time the FBI formally categorized AI as a crime descriptor. Researchers estimate that fewer than 5% of AI fraud victims report the crime, suggesting actual losses are significantly higher. Total cybercrime losses in 2025 reached $20.8 billion according to the same report.
How much audio does an attacker need to clone an executive's voice?
Modern voice cloning tools can produce a convincing replica with as little as 3 seconds of source audio. Publicly available recordings - earnings calls, conference presentations, podcast appearances, LinkedIn video posts - provide more than enough material. The executive does not need to have been compromised. Their public voice is the attack surface.
What controls protect against deepfake identity fraud?
The most effective controls are process-based: out-of-band verification for financial transactions above a defined threshold, pre-shared code words between executives and finance teams, strict dual-authorization policies for large transfers, and deepfake scenario training for finance and operations staff. Technology-based deepfake detection exists but is not reliable enough to be the primary control against determined attackers.
How did Ferrari stop a deepfake CEO attack?
In July 2024, a Ferrari executive received communications appearing to be from CEO Benedetto Vigna. The executive noticed slight inconsistencies in vocal tone, then asked a personal verification question only the real CEO could answer. The attacker could not respond correctly and the attempt failed. The lesson: personal familiarity alone is not reliable, but a pre-established verification mechanism that exists outside the synthetic environment the attacker created can defeat the attack.