TL;DR: Deepfake fraud is shifting impersonation from crude phishing to real-time identity emulation, with Arup’s reported $25 million loss showing how synthetic voices and video can defeat human trust checks, according to SlashID. Mutual verification, not perception alone, becomes the control boundary when executives can be convincingly cloned in live meetings.
At a glance
What this is: This article explains how real-time deepfakes turn executive impersonation into a practical fraud vector, with Arup’s reported $25 million loss used as the clearest example.
Why it matters: It matters because identity teams must now account for synthetic voice and video as part of human trust workflows, not just password or MFA compromise.
By the numbers:
- In 2024, Arup confirmed that an employee in Hong Kong transferred approximately $25 million after joining a fake executive video call.
- Industry forecasts estimate that deepfake-enabled fraud losses could reach $40 billion annually by 2027.
- The attack ultimately drove 15 transfers to attacker-controlled accounts during a single staged meeting.
👉 Read SlashID's analysis of deepfake impersonation attacks and identity fraud
Context
Deepfake impersonation is a human identity problem disguised as a fraud problem. When attackers can clone a voice or face in real time, existing verification habits that rely on recognition, tone, or live video cues stop being dependable primary signals for approval.
In the Arup case, the initial email request was only the first stage. The decisive failure came when a convincing synthetic meeting was allowed to substitute for stronger identity proof, which is atypical in scale but increasingly typical in method.
For identity teams, the lesson is not that all video is untrustworthy. The lesson is that trust signals in finance, help desk, and executive workflows need cryptographic verification or tightly bounded out-of-band validation, especially where there is transaction authority.
Key questions
Q: How should security teams defend against deepfake fraud in executive approval workflows?
A: They should require out-of-band verification, role separation, and documented approval steps for any high-risk request. Deepfake fraud succeeds when a familiar voice or face can trigger action without a second trust check, so the control objective is to make impersonation insufficient on its own.
Q: Why do deepfakes matter to IAM teams?
A: Deepfakes matter to IAM teams because identity governance is only as strong as the assurance behind an approval. If a fake executive can trigger a reset, a transfer, or a privilege change, then IAM controls need stronger confirmation steps, evidence trails, and channel separation.
Q: What breaks when organisations trust live video for approval decisions?
A: The approval process starts using appearance as proof of identity, which is exactly what deepfake attackers exploit. Once the meeting itself becomes the validation step, there is no independent control left to challenge the request. Organisations need separate verification channels for urgent or high-value actions so the meeting cannot function as the only gate.
Q: Who is accountable when a deepfake bypasses identity controls?
A: Accountability usually sits with the team that owns identity assurance, fraud controls, and recovery design together, because the failure spans multiple governance boundaries. If the programme allowed weak proofing, weak liveness, or weak recovery paths, the control owner must treat that as an identity governance gap, not an isolated incident.
Technical breakdown
How real-time deepfake fraud is assembled
Modern deepfake fraud is a pipeline, not a single model output. Attackers gather public audio and video to build a target identity profile, then train voice or face synthesis models to mimic that person in live interaction. The output is often injected into meeting software through a virtual camera or audio path so the victim experiences a continuous, believable presence. This matters because the deception is not limited to static content. The attack can preserve timing, tone, and turn-taking well enough to defeat human suspicion during high-pressure requests.
Practical implication: treat live meeting identity as a verification problem, not a perception problem.
Why liveness checks and visual trust signals fail
Traditional liveness controls assume a human presence can be distinguished from synthetic media by eye motion, lip synchronisation, or challenge-response prompts. That assumption weakens when generation systems can align audio, facial movement, and physiological cues in real time. The problem is not only realism, but synchrony across channels. Once the attacker can coordinate voice, image, and conversational context, the user’s brain fills in the rest and authorisation follows the illusion rather than the identity.
Practical implication: do not treat visual confirmation alone as sufficient evidence for high-risk approvals.
Mutual verification in identity workflows
Mutual verification means both sides of a communication prove identity using cryptographic or out-of-band methods rather than relying on a caller’s displayed name or appearance. In financial and privileged workflows, this can include challenge codes, verified callbacks, signed requests, or identity-aware collaboration controls. The architectural shift is important because the identity proof must travel with the transaction or meeting, not sit outside it. That reduces the chance that a spoofed executive can use social context to override process controls.
Practical implication: bind approval and transaction steps to verifiable identity evidence.
NHI Mgmt Group analysis
Deepfake fraud is now an identity assurance failure, not a media authenticity edge case. The Arup incident shows that the attack surface is the trust layer around executive decisions, payments, and urgent exceptions. Once a synthetic voice or face is accepted as sufficient proof, the organisation has already lost the identity control boundary. Practitioners should treat this as a human IAM and fraud governance issue, not a narrow awareness problem.
The governance gap is transactional verification, not user education. People can be trained to be cautious, but training does not create a cryptographic identity signal when a synthetic executive is on the call. The control failure is allowing high-value requests to be authorised through perception-based validation alone. That means finance, procurement, and help desk workflows need identity proof that is stronger than a familiar voice.
Mutual verification is becoming a baseline requirement for executive and payment workflows. When deepfakes can sustain a believable live interaction, the organisation needs confirmation methods that do not depend on what the user hears or sees. This is where identity governance, PAM, and collaboration security converge. Teams should assume that executive privilege can be impersonated in the communication channel even if the account itself is not compromised.
Deepfake-enabled fraud will increasingly chain across human and non-human identity processes. A fake executive can trigger a payment, a help desk reset, or a privileged exception, and each downstream action can create new access or new trust. That makes lifecycle controls, approval boundaries, and escalation paths part of the fraud control plane. The practitioner takeaway is clear: if identity proof is weak at the start, every downstream control inherits that weakness.
From our research:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, showing that behaviour gaps can outlast policy intent even when teams believe controls are mature.
- For a broader governance lens, see The 52 NHI breaches Report for patterns where access and identity assumptions failed at runtime.
What this signals
Deepfake fraud will push identity programmes toward channel-level verification. If voice and video can be forged convincingly, then approval workflows need proof that is independent of the communication medium. The next control frontier is not just authentication of users, but verification of requests before money, resets, or privileged exceptions move.
Identity teams should expect executive impersonation to intersect with NHI and access workflows. A synthetic executive can trigger downstream actions that involve service accounts, admin privileges, or temporary access grants, so the fraud control plane and the identity control plane are now coupled. Teams should review where human trust can trigger machine access without a second proof of identity.
With 43% of security professionals concerned about AI systems learning and reproducing sensitive information patterns from codebases, per The State of Secrets in AppSec, attackers have both technical and social paths to exploitation. That combination means identity verification must be designed for deception at scale, not just compromise at login.
For practitioners
- Implement high-risk transaction verification Require out-of-band confirmation for payments, account resets, and privileged exceptions above defined thresholds, with verification tied to a pre-registered channel rather than the live call.
- Separate identity proof from meeting presence Use cryptographic or callback-based verification before approving requests that arrive through video or voice, especially when the request is urgent or unusual.
- Harden executive approval workflows Add policy checkpoints for finance and executive assistants so a familiar voice cannot bypass dual approval, call-back rules, or transaction hold periods.
- Train for synthetic-media fraud scenarios Run tabletop exercises that include deepfake calls, cloned voices, and staged urgency so staff can practice pausing the transaction and escalating through verified channels.
Key takeaways
- Real-time deepfakes turn trusted voices and faces into a practical fraud channel that can bypass human judgement during urgent approvals.
- The Arup case shows how a synthetic executive meeting can drive multi-million-dollar loss without any account takeover or malware footprint.
- Mutual verification and out-of-band validation are the controls that change the outcome when identity can be impersonated in the conversation itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63C | Federation and assertion trust matter when voice or video is used as identity evidence. |
| NIST CSF 2.0 | PR.AC-1 | Identity proof and access control both fail when approvals rely on perception alone. |
| NIST SP 800-53 Rev 5 | IA-2 | Identity verification for privileged requests aligns with stronger authentication controls. |
| GDPR | Art.32 | Deepfake-enabled impersonation can expose personal and financial data through weak operational safeguards. |
Review operational safeguards where identity verification protects personal data or payment activity.
Key terms
- Deepfake: Synthetic or altered media created with AI or machine learning so that a person appears to say or do something they never did. In security terms, deepfakes are trust attacks that can distort identity verification, approval workflows, and fraud detection.
- Mutual Verification: A two-way identity check in which both parties prove who they are before a sensitive interaction continues. In practice, this means the requestor and the approver both rely on cryptographic or out-of-band proof rather than visual or auditory cues alone.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
What's in the full article
SlashID's full article covers the technical detail this post intentionally leaves for the source:
- The reconstructed Arup attack sequence, including reconnaissance, phishing, and deepfake meeting execution.
- The voice-cloning notebook and model choices used to demonstrate how synthetic speech can be produced quickly.
- The deepfake detection limits discussed for liveness checks, lip synchronisation, and challenge-response prompts.
- The mutual TOTP concept introduced as a defence pattern for live voice and video identity verification.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building identity controls across human, machine, and autonomous systems, it is worth exploring.
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org