The Wire Transfer That Started With a Familiar Face


The call looked routine. The CFO’s face was on screen. The background matched the office the finance manager recognized. The request made sense given the acquisition supposed to close that week.

What happened next is in public legal records. The finance employee at Arup, a global engineering firm, approved 15 wire transfers totaling HK$200 million. The CFO on that call was a deepfake. So were the three colleagues seated alongside him. No credentials were stolen, no systems were breached, and no fraud alert fired. The only real person on the call was the one who signed off on the transfers.

This is not an isolated case. It is a template, and finance teams are its primary target.


Why Finance Teams Are the Primary Target

Social engineering attacks follow the money, and the money follows the people authorized to move it. Treasury managers, accounts payable teams, and CFOs share a combination that attackers find uniquely valuable: they have the authority to approve significant transfers, they are accustomed to receiving urgent and confidential instructions, and they regularly work with counterparties they have never met in person.

The FBI’s Internet Crime Complaint Center reported $2.99 billion in business email compromise losses in 2025 alone. That figure has grown every year for a decade. What changed in the past two years is the addition of voice and video to the attack chain. Email compromise required a target to act on text. Now the attacker can put a face and a voice behind the request, and both can belong to someone the target already trusts.

Voice cloning requires only a few seconds of reference audio. Earnings calls, conference recordings, and LinkedIn videos provide it freely. A real-time video deepfake grafts a synthetic face onto a live camera feed, which means the fake is not a pre-recorded clip that someone might scrutinize later. It is a person on a call, answering questions and adjusting in real time.

Deloitte’s Center for Financial Services projects that generative AI-enabled fraud losses in the US will climb from $12.3 billion in 2023 to $40 billion by 2027, at a compound annual growth rate of 32%. Finance teams sit at the center of that risk curve.


How the Attack Unfolds

The pattern for financial deepfake fraud is consistent enough that security teams have begun mapping it as a repeatable sequence: authority, urgency, and isolation.

The attacker establishes authority first, by impersonating a known executive, a legal representative, or a financial counterparty. The impersonation uses a spoofed email address, a cloned voice, or a synthetic face on video, depending on the channel.

Urgency follows immediately. The request is time-sensitive: a deal that closes today, a regulatory deadline, or a wire that must clear before the markets close. Urgency compresses the time the target has to verify.

Isolation completes the setup. The request is marked confidential. The target is instructed not to discuss it with colleagues until after the transfer clears. This removes the most reliable check a finance team has, which is asking someone else in the room.

A commercial bank manager lost $35 million in 2024 following exactly this sequence. He received a cloned-voice call from someone who sounded like a director he had spoken with before. The voice was right. The urgency was credible. The transfer was approved. Forensic analysis confirmed the call was synthetic after the money was already gone.


The Signals Worth Watching

Finance teams do not need to become deepfake experts. They need to recognize the conversational patterns that precede the ask.

A synthetic voice tends to flatten the natural rise and fall of unscripted speech. It omits breath sounds and the self-corrections of someone thinking aloud. A caller who never talks over you, never hesitates, and steers consistently toward urgency is worth pausing on.

On video, watch for movement that is too smooth around the eyes and mouth. Real faces carry micro-expressions that current synthetic faces still struggle to replicate consistently, especially under lighting changes or unexpected subject shifts.

The clearest behavioral signal is resistance to verification. A legitimate CFO will not object to you calling back on the number stored in your system. An attacker running a live deepfake cannot afford to let you do that.


What Finance Teams Can Do

The most effective control against this attack is also the most straightforward: verify the request through a channel the attacker does not control.

Any wire transfer, payment instruction change, or vendor banking update that arrives over a call or video should be confirmed through a second, pre-agreed channel before approval. A callback to a number stored in your system, not one provided by the caller, breaks the attack at its most critical point. This step should be formalized as policy so that pausing on an unusual request from a senior executive is a process step, not insubordination.

For recorded authorizations, finance teams are increasingly running the file through a deepfake detector before approving the transfer. Diopter’s deepfake detector analyzes audio and video for synthetic media signatures across multiple signal families, including temporal artifacts, spectral anomalies, and generator-specific fingerprints from tools that attackers are actively deploying. The verdict returns in under 60 seconds, before the transfer window closes.

For live calls where the authorization happens in real time, enterprise-grade detection tools can run continuous scoring throughout the conversation rather than checking a single clip after the fact.


Three Policy Steps Worth Taking Now

Finance leaders do not need a complete technology overhaul to close the most dangerous gap. Three policy decisions make an immediate difference.

First, establish a threshold above which every wire requires out-of-band verification, regardless of who is asking. The threshold should be defined in advance, not evaluated case by case under pressure.

Second, add a verification step for recorded authorizations. If a wire is approved based on a voicemail, a voice note, or a recorded call, the recording should be checked before the transfer clears. The check takes less time than the approval process already requires.

Third, remove the social pressure that makes this attack work. Finance teams need explicit permission to slow down and verify a request even when it comes from the CEO. The culture around approval processes matters as much as the technology that supports them.

The Arup incident did not happen because the finance team was careless. It happened because the attack was designed to look exactly like a legitimate process. The defense has to be equally deliberate.