Skip to Content

Every Person on That Video Call Was Fake: The $25.6M Meeting That Should Terrify Your CFO

July 20, 2026 by
Every Person on That Video Call Was Fake: The $25.6M Meeting That Should Terrify Your CFO
Administrator

The TL;DR: Deepfake CEO fraud now targets 400 companies every single day, with average enterprise losses of $680,000 per attack — and in controlled studies, only 0.1% of humans reliably spot a deepfake. Your finance team's eyes and ears are no longer a security control.

The Breakdown

In the now-infamous Arup case, an employee joined a video call with the CFO and several colleagues. Everyone looked right. Everyone sounded right. The employee wired $25.6 million across 15 transfers.

Every single person on that call was a deepfake. The entire meeting was fabricated.

That was the warning shot. Here's where we are now:

  • Deepfake vishing surged over 1,600% in a single quarter in the US.
  • US deepfake fraud losses hit $1.1 billion in 2025; Deloitte projects AI-enabled fraud could reach $40 billion annually by 2027.
  • The modern playbook is multimodal: a spoofed email creates the paper trail, a cloned voice call adds personal authority, and a brief deepfaked Teams appearance seals the deal. Each channel builds credibility for the next.

The uncomfortable truth: this attack doesn't exploit a server. It exploits organizational trust — the assumption that seeing and hearing an executive is verification.

The EC-Council Lens: How CHFI and CCISO Thinking Beats Synthetic Media

The CHFI (forensic) response — when the wire has already gone out:

  • Preserve everything immediately: call recordings, email headers, meeting metadata, gateway logs. Deepfake investigations live or die on artifact preservation in the first hours.
  • Follow the money and the metadata: spoofed domains, VoIP origin numbers, and re-encoded media artifacts leave forensic trails that fabricated faces don't erase.

The CCISO (governance) response — so the wire never goes out:

  • Out-of-band verification, no exceptions: any payment or credential request initiated over voice/video gets confirmed through a separate, pre-established channel. Even for the CEO. Especially for the CEO.
  • Dual authorization thresholds: no single employee — however senior the requester appears — can move six figures alone.
  • Train for the 0.1% problem: since humans can't reliably detect deepfakes, controls must assume the fake will be convincing. Process beats perception.

The Stack Takeaway

For twenty years, security awareness training taught people to spot the fake. That era is over — the fakes won. The organizations that survive AI-era fraud are the ones that redesign process so that detection doesn't matter.

That's a leadership skill and an investigative skill — exactly the ground covered by Bluu Kazi's CCISO and CHFI training tracks. Your CFO can't out-stare a deepfake. Your controls can.

Sources: CybelAngel — Deepfake CEO Fraud · Adaptive Security — Deepfake Statistics 2026 · Bright Defense — 150+ Deepfake Statistics · Brightside AI — The $50M Voice Cloning Threat · KnowBe4 — Deepfake Fraud Losses

Every Person on That Video Call Was Fake: The $25.6M Meeting That Should Terrify Your CFO
Administrator July 20, 2026
Share this post
Archive