The $25 Million Zoom Call
A finance employee at a global engineering firm wired $25 million after a video call where every other participant, including the CFO, was a deepfake. This is what payment fraud looks like now, and it hasn't slowed down in 2026.
A finance employee at Arup's Hong Kong office got an email from the UK-based CFO asking for a confidential transaction. He was skeptical, so a video call got set up to confirm it. Every other person on that call, the CFO included, was a deepfake, built from publicly available footage of real executives. The employee authorized 15 transfers totaling $25.6 million in a single day. The fraud only surfaced when he later called Arup's actual headquarters to follow up.
That was January 2024. The pattern hasn't slowed since. In March 2025, a finance director at a multinational in Singapore approved a $499,000 transfer on a Zoom call where every face and every voice was synthetic, fabricated from public footage of the real executives it impersonated. By April 2025, Hong Kong police had intercepted a fraud network using financial-services deepfakes to open bank accounts, with losses exceeding $193 million. Voice-only versions of the same attack go back further still: in 2019, a UK energy firm's CEO wired €220,000 after a phone call he believed was his German parent company's chief executive, cloned from public recordings of the real man's voice.
2026 hasn't broken the pattern, it's scaled it. Early in the year, a Fortune 500 financial services firm lost $28 million through a single deepfake video call impersonating its CFO on a supposed acquisition transfer. In May, Singapore police disclosed a scam in which fabricated footage showed Prime Minister Lawrence Wong, the president, a cabinet minister, and MAS officials discussing the Strait of Hormuz on a fake video conference, complete with deepfaked representatives from BlackRock and DIFC. One victim wired at least S$4.9 million (roughly US$3.8 million) before realizing the entire meeting, and everyone in it, was synthetic. The FBI now tracks deepfake-layered business email compromise as one of the fastest-growing, highest-value fraud categories targeting US enterprises, with average losses per incident now exceeding $500,000.
What connects all these cases is the same failure. Each targeted the one verification step everyone still trusts by default: seeing a colleague's face, hearing a colleague's voice, on a call that looks and sounds exactly like every other call that person has been on. That's precisely why it works. The entire model of trust in payment authorization assumes a synthetic executive convincing enough to survive a live video call isn't something an attacker can produce cheaply. It is now.
Deloitte's Center for Financial Services projects generative-AI-driven fraud could cost the US $40 billion by 2027. Payment and transaction fraud broadly is estimated at $66 to 117 billion by 2030, the largest single component of that figure. The volume that matters here isn't the size of any one transfer. It's that authentication built around human judgment on a call doesn't scale against an attacker who can generate a convincing executive on demand, for the cost of some public conference footage and a few hours of compute.
Passive liveness detection and identity matching applied at the point of authorization, not the point of after-the-fact investigation, is what closes that gap. That requires a detector trained against synthetic identities realistic enough to have actually fooled someone, at demographic breadth no single company's fraud log could ever provide on its own.
TessLabs' discriminator was hardened over eight years against real fraud inside a live identity-verification business, at population scale, the same scale payment networks operate at.
Read the white paper or place your order to see the detection data.
FAQ
Is deepfake payment fraud actually common, or are these isolated incidents?
No. Deepfake-layered fraud is one of the fastest-growing categories the FBI tracks for US enterprises, with average losses now exceeding $500,000 per incident. The pattern has repeated across Hong Kong, Singapore, the UK, and the US since 2019, each time using the same tactic: a synthetic executive convincing enough to survive a live call.
Can voice or face verification alone stop a deepfake payment scam?
Not reliably. Every case above defeated a human's judgment on a call, which is the same trust assumption most voice and video verification still relies on. Stopping it requires passive liveness detection trained against realistic synthetic identities, applied at the point of authorization rather than after the transfer clears.
Who is targeted by deepfake CEO or government-impersonation fraud?
Finance staff with wire authority are the most common target, but the May 2026 Singapore case shows the tactic extending to business professionals with any prior contact with government officials, impersonating heads of state and central bank officials rather than just corporate executives.
Case studies: Arup $25.6M scam via CNN; Singapore and Hong Kong 2025 cases, and the 2019 UK voice-fraud case, via Biometric Update and Sophos; the 2026 Fortune 500 case via SecurityToday; the May 2026 Singapore PM Wong deepfake scam via the Singapore Police Force and South China Morning Post.
Measuring this on your own model
The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.