If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.

An employee did the careful thing. Unsure about an unusual payment request, they asked to confirm it on a video call with senior colleagues, including the chief financial officer. The call went ahead, the people on it looked and sounded right, and the payment, around $25 million, was approved. Every person on that call was an AI-generated deepfake.

The case, disclosed by the global engineering firm Arup, is one of the clearest illustrations yet of a simple, unsettling shift: seeing and hearing someone is no longer proof that they are real.

What happened

In early 2024, a finance employee at Arup’s Hong Kong office received a message about a confidential transaction. Suspicious at first, they joined a video call to verify it. On the call were what appeared to be the company’s UK-based CFO and several other colleagues. Reassured, the employee went on to make a series of transfers, 15 in total, amounting to roughly $25 million. Only later, on checking with head office, did it emerge that everyone on the call except the employee had been digitally fabricated. Arup and Hong Kong police have confirmed the incident publicly.

Why it worked

The attack did not break any system. No network was breached and no malware was involved. It targeted the one control the employee had been taught to rely on: confirm an unusual request with a person you recognise. Video and voice have always carried that weight because, until recently, faking them convincingly in real time was hard. That is no longer true. Available tools can now generate a live likeness of a named individual convincing enough to survive a video call, which turns the act of checking into part of the deception.

Why existing controls did not catch it

Payment controls and identity systems are built around accounts, credentials and approvals. None of those were obviously misused here, because the employee had legitimate access and used it. Multi-factor authentication protects a login, not a conversation. The weak point was not a system at all. It was that the human verification step, look at the person and confirm it is them, no longer proves what it used to, and there was no independent way to test whether the people on the call were genuine.

Why it matters for organisations

The Arup case is memorable because of its size, but the mechanism is what should concern security teams. Any moment where a person is trusted on the strength of a call, a payment authorisation, a change to bank details, a privileged instruction from a senior figure, is now a moment that can be attacked with a convincing fake. These are exactly the interactions attackers care about, because they move money or grant access, and they are the ones least protected by conventional tooling.

How to reduce the risk

The general advice is sound but incomplete: slow down high-value requests, confirm through a separate known channel, and do not treat a video call as proof of identity on its own. The gap in that advice is the separate known channel. It works only if there is a channel the attacker cannot also fake, and a phone number or email can be spoofed or compromised as readily as a video call can be fabricated.

How Loxada addresses this

Loxada Verify is built for exactly these moments. It uses the Loxada router already issued to a person as a hardware-anchored presence factor, giving a high-risk request a check tied to a physical device the attacker does not hold, rather than resting on a face or a voice that can be cloned. The lead use cases are the ones this case sits inside: high-value payment and authorisation moments, executive instructions given by call, and IT help desk identity checks.

Verify does not replace your identity provider or payment controls, and it does not address email-based fraud such as business email compromise. What it adds is a hardware-grounded way to confirm the person at the point where, as Arup found, simply seeing and hearing them is no longer enough. Loxada Verify launches in Q3 2026.

Common questions

What is a deepfake? Synthetic audio or video generated by AI to imitate a real person’s appearance and voice, now realistic enough in some cases to sustain a live call.

Was Arup hacked? No system was breached. The attack was social, using a fabricated video call to convince an employee to authorise legitimate transfers.

Would asking for a video call have helped? In this case the employee did ask for one, and the call itself was the fake. That is what makes the case significant.

Would multi-factor authentication have stopped it? MFA protects access to accounts. Here the employee had legitimate access; the deception was about who they believed they were speaking to, which MFA does not address.

Sources: Arup public statements and Hong Kong Police, 2024, as reported by CNN and others.

If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.