The fraud against Arup, the British engineering firm behind the Sydney Opera House and Beijing's Bird's Nest stadium, began the way most social-engineering attacks begin: with a phishing email. A finance employee at the firm's Hong Kong office received a message purporting to be from Arup's UK-based CFO, requesting a confidential transaction. The employee was suspicious, which is exactly the right instinct — and exactly the instinct the attackers had planned for.
The follow-up was a video call. On it, the employee saw and heard the CFO and several other senior colleagues he recognised, discussing the same confidential transaction the email had raised. Reassured by the live presence of familiar faces and voices, he proceeded to make fifteen separate wire transfers, totalling roughly $25.6 million, to five Hong Kong bank accounts the attackers had set up in advance. Every participant on that call besides the employee himself was an AI-generated deepfake, built from publicly available video and audio of Arup's real executives — footage scraped from webinars, press interviews, and recorded conference appearances, the kind of material any company routinely puts online.
The fraud was only discovered when the employee later followed up directly with Arup's head office about the 'secret transaction' and learned no such request had been made. By then, the funds were gone and unrecoverable. Arup's Chief Information Officer described the incident afterward in a phrase worth sitting with: 'technology-enhanced social engineering.' No company systems were breached. No credentials were stolen. No network was infiltrated. The only thing compromised was the employee's confidence in what he was seeing and hearing.
That framing matters for how organisations should actually respond. This was not an IT security failure in any conventional sense — it was the failure of an authorisation control built on an assumption that has quietly stopped holding: that seeing a colleague's face and hearing their voice on a call is a reliable form of verification. For any organisation whose payment authorisation still ultimately rests on 'I saw them, I heard them, it must be them,' the Arup case is the clearest evidence available that this control has already expired.