One fake video call cost a company $25.6 million. Here is how deepfakes work, why your eyes cannot always catch them, and the habit that stops this scam.
Deepfakes are AI-made videos that make it look and sound like someone is saying or doing something they never did. In 2024, a finance employee wired $25.6 million after a video call where every colleague, including the CFO, was a fake. Your eyes cannot reliably catch these, so the fix is to verify through a separate, trusted channel before acting.
In early 2024, a finance employee at the UK engineering firm Arup joined what looked like a routine video call. Several familiar colleagues were on screen, including the company's UK-based chief financial officer, who needed urgent approval for a confidential transaction.
The employee followed instructions and completed 15 separate transfers totaling $25.6 million. Weeks later, the truth came out. Every single person on that call, aside from the employee, had been an AI-generated deepfake. Arup publicly confirmed the incident, and it remains one of the largest deepfake fraud cases on record.
This was not a low-budget prank video. It was a coordinated, real-time performance built to fool a trained professional, and it worked.
Think of a deepfake as digital puppetry. AI takes real footage and audio of a person, usually pulled from interviews, social media, or company videos, and uses it to generate a synthetic version that can say or do things the real person never did. The best ones can hold a live conversation, react in real time, and mimic small mannerisms like blinking or head tilts.
This is not a rare, one-off event. It is a fast-growing category of fraud.
A global consumer study by the identity verification company Jumio, surveying more than 8,000 adults across the US, UK, Singapore, and Mexico, found that 60 percent of people had encountered a deepfake video within the past year. Only 15 percent said they had never come across one at all.
This is not just a consumer problem either. A Gartner survey of 302 security leaders, published in September 2025, found that 62 percent of organizations had faced a deepfake-enabled attack in the previous year. Within that group, 44 percent were hit by a deepfake voice call and 36 percent by a deepfake video call, which is the exact pattern behind the Arup case. And the money is climbing fast, with reported US deepfake fraud losses tripling to over $1 billion in 2025.
Sources: World Economic Forum reporting on the Arup incident; Gartner survey of 302 security leaders, September 2025; peer-reviewed meta-analysis of human deepfake detection
Here is the part worth sitting with. In that same research, about 60 percent of people believe they could spot a deepfake if they saw one. The confidence is there. The accuracy is not.
Business video calls. Scammers impersonate executives, vendors, or coworkers to authorize wire transfers or share sensitive information, exactly like the Arup case.
Fake celebrity endorsements. A video appears to show a famous person promoting an investment, a product, or a giveaway. It is fabricated, designed to get you to click, buy, or hand over money.
Romance scams. Some scammers now use AI-generated video "dates" with people who do not exist at all.
Political and social manipulation. Fabricated videos of public figures saying things they never said, designed to spread confusion or misinformation.
Some deepfakes still have flaws you can catch with a careful eye. Look for:
Odd blinking patterns or a face that seems slightly stiff
Audio that does not quite match the lip movements
Lighting or shadows that do not match the background
Skin that looks unnaturally smooth, almost filtered
Glitchy transitions around hair, clothing, or background edges
A flat, slightly robotic tone of voice
The technology is improving fast, and researchers who study deepfakes professionally now admit even they sometimes cannot reliably tell real from fake. Spotting the flaws is a helpful skill, not a safety net.
Since your eyes cannot be fully trusted, the fix has to happen outside the call itself.
Agree with your team or family: any video call requesting money, gift cards, or login credentials gets verified through a second channel before anyone acts. A standing rule removes the awkwardness of "checking up" on someone in the moment.
End the call. Do not follow any instructions involving money, passwords, or sensitive data. Contact the person through a number or app you already have saved, not anything provided during the call. If it involved work, notify your company's IT or security team immediately. Report it to the FTC at ReportFraud.ftc.gov and the FBI at ic3.gov.
Yes. The Arup case involved a live, real-time deepfake video call with multiple fabricated participants, not a pre-recorded clip. The fakes responded and answered questions in the moment.
Some security tools and browser extensions offer deepfake detection, but they are not perfect and should not replace verification habits like calling back on a known number.
Research shows human accuracy at spotting deepfakes sits around 55 percent, barely better than chance. Confidence in this skill is usually higher than actual ability, which is exactly what makes deepfakes dangerous.
Both. High-dollar cases like Arup hit businesses, but individuals are targeted too, especially through romance scams and fake celebrity investment videos.
Contact your bank immediately to ask about a wire recall or dispute, then report it to the FTC and FBI IC3. Acting within the first hour gives the best chance of recovering funds.
Know someone who needs this?

The SDS Shop
Simple guides for every situation
Family Safety Starter Pack
AI Safety Guide
Senior Safety Guide
Business Security Kit
and more....
Clear, friendly guides that walk you through it.
Starting at $19
SCAM ALERT CENTER

Fresh scams land here first. A quick look keeps you a step ahead.
Don't Get Hacked
Weekly tips, scam alerts, and plain-language security advice. One email. No spam.
© 2026 Simple Digital Safety. All rights reserved.
Privacy Policy | Terms | Disclaimer | Refund