Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Arup Deepfake Fraud 2024: How a Fake CFO…
Breach analysis Incident: 29 Jan 2024

Arup Deepfake Fraud 2024: How a Fake CFO on a Video Call Triggered HK$200 Million in Transfers

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 11 min read
On this page

In January 2024, a finance employee in the Hong Kong office of Arup, the London-based design and engineering firm, made 15 transfers totalling HK$200 million (about US$25.6 million) to five local bank accounts. The instructions came from what looked and sounded like the company's UK-based chief financial officer and other colleagues on a video conference. According to Hong Kong police, every other person on that call was fake. No system was hacked and no password was stolen. The attackers abused the one identity check that most payment processes still rely on: recognising a senior person's face and voice. That makes Arup a human identity breach, and a clear warning for any process, human or machine, that trusts a channel instead of verifying who is on the other end.

Key takeaways

  • A Hong Kong finance worker at Arup received a message purportedly from the UK-based CFO about a secret transaction. He first suspected phishing, then was reassured by a video call with people who looked and sounded like colleagues.
  • Hong Kong police said everyone else on the multi-person video conference was a deepfake, built from publicly available video and audio of the people being impersonated.
  • The worker made 15 transfers into five local bank accounts, a total of HK$200 million (about US$25.6 million), before checking with head office and finding the request was fraudulent.
  • Arup said fake voices and images were used, that its financial stability and business operations were not affected, and that none of its internal systems were compromised. Its CIO later called the attack "technology-enhanced social engineering".
  • The lesson is to verify identity and authority out of band for high-value actions. Seeing a face on a screen is not authentication, and the same applies to any request arriving over a trusted-looking machine channel.

At a glance

OrganisationArup (Hong Kong office)
WhenJanuary 2024; reported to Hong Kong police on 29 January 2024; made public by police in early February 2024; Arup named as the victim in May 2024
AttackerUnidentified fraudsters; no arrests reported for this case
Entry pointA message purportedly from the UK-based CFO, followed by a multi-person video conference populated with deepfakes
Identities abusedThe faces and voices of the CFO and other colleagues (impersonated human identities), used to manipulate a finance employee with authority to make payments
ImpactHK$200 million (about US$25.6 million) sent in 15 transfers to five bank accounts; Arup says operations and internal systems were not affected
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

The case first became public in early February 2024, when Hong Kong police described it without naming the company. According to CNN's report of the police briefing, a finance worker at the Hong Kong branch of a multinational received a message purportedly from the company's UK-based chief financial officer. The message talked of the need for a secret transaction, and the worker initially suspected it was a phishing email.

He was then drawn into a video conference. CNN reported that he put aside his early doubts because the other people in attendance looked and sounded just like colleagues he recognised. Senior Superintendent Baron Chan Shun-ching of the Hong Kong police told reporters: "(In the) multi-person video conference, it turns out that everyone [he saw] was fake."

Police said the fraudsters had not needed to break into anything to build the fakes. Hong Kong Free Press reported that, according to Acting Senior Superintendent Baron Chan, the scammers found publicly available video and audio of the people they were impersonating on YouTube and used deepfake technology to emulate their voices. Police also said the deepfake videos were pre-recorded and did not involve dialogue or interaction with the victim. The Register quoted Chan as saying: "I believe the fraudster downloaded videos in advance and then used artificial intelligence to add fake voices to use in the video conference." It also reported that the fraudsters used WhatsApp, email and one-to-one video calls to add credibility.

Following the instructions given, the worker made 15 transfers into five local bank accounts, a total of HK$200 million. The Register reported that he only discovered the truth after contacting the company's head office. Fortune reported that the ordeal lasted a week from when the employee was contacted to when the company began looking into the matter. The case was reported to police on 29 January 2024.

In May 2024, Arup was revealed as the victim. A spokesperson told CNN: "Unfortunately, we can't go into details at this stage as the incident is still the subject of an ongoing investigation. However, we can confirm that fake voices and images were used." The company added: "Our financial stability and business operations were not affected and none of our internal systems were compromised." Rob Greig, Arup's global chief information officer, said the company's operations were subject to regular attacks "including invoice fraud, phishing scams, WhatsApp voice spoofing, and deepfakes", and that "the number and sophistication of these attacks has been rising sharply in recent months."

In a February 2025 interview with the World Economic Forum, Greig said "none of our systems were compromised and there was no data affected", and described what happened as "technology-enhanced social engineering" rather than a cyberattack in the traditional sense: "People were deceived into believing they were carrying out genuine transactions that resulted in money leaving the organization." He also said he had created a deepfake video of himself using open-source software in about 45 minutes.

Timeline

DateEvent
January 2024Finance worker in Arup's Hong Kong office receives a message purportedly from the UK-based CFO about a secret transaction, then joins a video conference with deepfaked colleagues.
January 2024 (over about a week)Worker makes 15 transfers totalling HK$200 million to five local bank accounts, then contacts head office and the fraud is discovered.
29 January 2024Case reported to Hong Kong police.
4 to 5 February 2024Hong Kong police describe the case publicly without naming the company.
16 to 17 May 2024Arup is revealed as the victim and confirms that fake voices and images were used.
4 February 2025Arup CIO Rob Greig discusses the incident with the World Economic Forum.

How it happened: the identity attack path

  1. Harvest public identity material. Police said the fraudsters collected publicly available video and audio of the people they planned to impersonate, including from YouTube.
  2. Build synthetic identities. The attackers used deepfake technology to produce pre-recorded video of the CFO and colleagues and to emulate their voices.
  3. Make first contact as the CFO. A message purportedly from the UK-based CFO asked for a secret transaction. The worker suspected phishing at this stage.
  4. Overcome doubt with a group call. A multi-person video conference, in which every other participant was fake according to police, made the request look collectively endorsed by recognised senior people.
  5. Reinforce across channels. WhatsApp, email and one-to-one video calls were used to add credibility, according to The Register.
  6. Use the victim's legitimate authority. The worker, acting within his own role, made 15 transfers to five bank accounts. No credentials were stolen and no systems were accessed.
  7. Detection only by out-of-band check. The fraud surfaced when the worker contacted head office directly.

Impact

  • HK$200 million (about US$25.6 million) transferred to fraudsters in 15 transactions to five bank accounts.
  • Arup said its financial stability and business operations were not affected, and that none of its internal systems were compromised.
  • The South China Morning Post described it as the first case of its kind in Hong Kong. Police said no arrests had been made at the time of their briefing.

What this means for identity security

Most identity controls protect the login. At Arup, the login was never the target. The attackers did not need the CFO's password or the finance worker's account. They impersonated the CFO's identity at the human layer, face and voice, and then used the worker's real, authorised access to move the money. The failure was in how authority was verified.

The worker's first instinct, that the message looked like phishing, was right. What overrode it was a richer channel. A group video call feels like strong evidence, and before generative AI it largely was. The Arup case shows that appearance and voice can no longer serve as authentication factors on their own. Verification needs to rely on something an impersonator cannot copy from a YouTube video: a callback to a known number, a second approver, or a request confirmed inside a system where the requester has had to authenticate properly.

There is a direct parallel with machine identities. Services and AI agents routinely act on requests because of where they appear to come from, a trusted network, a known webhook, a familiar integration, rather than because the caller has proved who it is. An attacker who can make traffic look like it comes from a trusted source gets the same result as the Arup fraudsters: a legitimate identity with real authority performing a harmful action. Our Human vs Non-Human Identity explainer covers where these two worlds meet, and the NHI Authentication Guide sets out how to make machine callers prove identity cryptographically instead of by context.

Recommendations

  • Verify high-value requests out of band. Confirm any unusual payment or secret-transaction request through a separate, pre-registered channel, such as a call back to a number held on file, never a number or link in the request. Our Workforce Identity Security Guide covers verification for help desks, resets and other high-risk interactions.
  • Do not treat video or voice as authentication. Update payment and approval policies so that recognising someone on a call is never sufficient on its own to authorise a transfer.
  • Enforce separation of duties on payments. Require a second, independent approver for large or unusual transfers and for payments to new beneficiaries. See IAM and IGA Basics.
  • Move approvals into authenticated systems. A payment request should originate in a workflow where the requester has signed in with phishing-resistant MFA, not in a chat, email or call.
  • Train staff on multi-channel impersonation. Make clear that secrecy and urgency from a senior executive are warning signs, and that checking with head office is expected and protected.
  • Apply the same rule to machines and agents. Services and AI agents that can move money or data should require authenticated, scoped requests rather than trusting the channel. The Privileged Access Management Guide explains human-in-the-loop and just-in-time controls for high-impact actions.

Frequently asked questions

How much did Arup lose in the deepfake scam?

The employee made 15 transfers totalling HK$200 million, about US$25.6 million, to five bank accounts in Hong Kong. Arup said its financial stability and business operations were not affected.

Was Arup hacked?

No. Arup said none of its internal systems were compromised, and its CIO described the incident as technology-enhanced social engineering. The fraudsters used deepfaked video and voices of the CFO and colleagues to persuade an authorised employee to make the payments.

Is the Arup deepfake fraud a non-human identity breach?

No, it is a human identity breach: people's faces and voices were impersonated to manipulate another person. We include it because the underlying weakness, trusting a request because of the channel it arrives on rather than verifying the requester, applies equally to service accounts, integrations and AI agents.

MGM Resorts breach 2023 · Uber breach · Workforce Identity Security Guide · Human vs Non-Human Identity · NHI breaches

How NHI Mgmt Group can help

Deepfakes make it easy to borrow a trusted identity, whether it belongs to a person or a machine. Our NHI Foundation Level Training Course shows teams how to authenticate and govern service accounts, API keys, tokens and AI agents so that high-impact actions depend on verified identity, not on appearances.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org