It began, as most modern frauds do, with an email. A finance employee in the Hong Kong office of Arup — the British engineering firm behind the Sydney Opera House and Beijing's "Bird's Nest" stadium — received a message purporting to come from the company's UK-based chief financial officer. It spoke of a confidential transaction. The employee was suspicious; the note had the faint smell of phishing.

So the fraudsters did something a simple phishing email could never do. They invited the worker to a video call.

On screen sat the CFO. Around him sat other familiar colleagues, faces the employee recognised, voices that sounded right. The meeting looked ordinary in every respect but one: none of the other participants were real. Every figure on that call was a real-time, AI-generated deepfake, assembled from publicly available footage and audio of genuine Arup staff. The employee was the only human present.

Reassured by the faces of people he believed he knew, the worker set aside his doubts and followed instructions. Over a period that followed, he executed 15 separate transfers totalling HK$200 million — roughly US$25.6 million — into five Hong Kong bank accounts controlled by the criminals.

The deception held until the employee, later, checked in with Arup's actual head office. Only then did the architecture of the fraud collapse into view: the confidential deal did not exist, the CFO had issued no such instruction, and the money was already gone. Hong Kong police confirmed the case in February 2024, describing a scam in which the victim was lured onto a video conference populated entirely by digitally recreated people. No arrests recovered the funds.

What makes the Arup case a landmark is not its size — corporate wire fraud has cost more — but its mechanism. For years, the standard defence against "CEO fraud" was human verification: if an email seems suspicious, pick up the phone, get on a call, look the person in the eye. The Hong Kong operation weaponised exactly that instinct. The verification step the employee performed was real; the people he verified against were not. The safeguard became the attack surface.

Arup confirmed it was the target and that no client data was compromised and its finances were unaffected beyond the stolen sum, but the firm's global CIO later spoke publicly about the volume and sophistication of attacks now aimed at the company, warning that the technology to fabricate convincing voices and images had moved from theoretical threat to operational tool.

The criminals needed no zero-day exploit and no insider. They needed only footage that any large public company inevitably leaves online — conference talks, interviews, internal videos — and software capable of animating it convincingly in real time. The rest was social engineering as old as commerce itself: authority, urgency, secrecy.