Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Deepfake video calls and identity verification: what breaks in finance workflows?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: Arup’s US$25.6 million loss shows that face recognition, voice familiarity, and normal approval checks can all be satisfied while identity is still unverified, according to Idemia’s analysis of the deepfake scam. The case shows why high-risk transactions now need independent proof of presence, not just human recognition.

NHIMG editorial — based on content published by Idemia: Anatomy of the $25.6 Million Arup Scam: Everyone Recognized the Faces. No One Verified Them

By the numbers:

Questions worth separating out

Q: What breaks when a deepfake video call is used to authorize a payment?

A: The approval chain breaks because the request appears to come from a trusted person even though the identity behind it has not been independently verified.

Q: Why do familiar faces and voices no longer provide enough assurance for high-risk approvals?

A: Because generative AI can reproduce public speech and appearance well enough to satisfy human recognition without proving the person is real, present, or authorised.

Q: How should organisations design fraud controls for executive impersonation?

A: Build controls around decision points, not just logins.

Practitioner guidance

  • Separate request and approval channels Require high-risk transactions to be initiated in one medium and approved in another controlled workflow so a single deepfake call cannot carry both persuasion and authorization.
  • Add independent identity verification for executives Use trusted callback numbers, pre-registered verification steps, or secondary approvers who were not exposed to the original call before releasing funds or sensitive access.
  • Train finance and IAM teams on synthetic-media fraud Update awareness training to include executive impersonation, deepfake meetings, and urgent confidential transfer scenarios, not just phishing links and suspicious attachments.

What's in the full article

Idemia's full article covers the incident detail this post intentionally leaves for the source:

  • The step-by-step narrative of how the deepfake call was staged and how the employee was persuaded.
  • The article's discussion of cryptographic identity verification and liveness detection in the context of high-risk approvals.
  • The specific examples of how organizations can separate conversation from authorization in practice.
  • The source's own framing of IDEMIA Public Security's Identity Proofing Platform and its role in identity assurance.

👉 Read Idemia's analysis of the Arup deepfake scam and identity verification failure →

Deepfake video calls and identity verification: what breaks in finance workflows?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Recognition is not identity verification: This case shows a control failure at the point where organizations assume a familiar face or voice is sufficient evidence. That assumption was designed for a world where live media was difficult to counterfeit at scale. Once deepfakes can reproduce executives convincingly, the control boundary shifts from human perception to independent proof. The practitioner conclusion is straightforward: identity assurance must stand apart from the conversational channel.

A few things that frame the scale:

  • The employee authorized 15 wire transfers totaling HK$200 million, or about US$25.6 million, after joining the deepfake call, according to The State of Secrets in AppSec.
  • Deepfake-enabled impersonation now scales from social engineering into direct financial loss when verification depends on human recognition alone.

A question worth separating out:

Q: What is the difference between recognising someone on video and verifying their identity?

A: Recognition is a human judgment based on appearance, voice, or familiarity. Verification is evidence-based proof that the person is real, present, and authorised for the action being requested. In deepfake scenarios, recognition can be manipulated while verification still needs an independent proof path.

👉 Read our full editorial: Deepfake fraud exposed the limits of face-based identity proof



   
ReplyQuote
Share: