top of page

Video Call Deepfake Fraud: Why Seeing Your Team On Screen No Longer Proves Anything

A finance employee gets an email asking for a large, confidential transfer. Something about it feels off, so he does exactly what he was trained to do. He picks up the phone and asks to see the person making the request on a video call.


The call happens. The CFO is there. Several colleagues he already knows are there too, faces and voices he recognized immediately. His doubts fade, and he authorizes the transfer. None of the people on that call were real.






The Meeting That Wasn't Real


That is what happened to Arup, the British engineering firm behind the Sydney Opera House. As CNN reported, a Hong Kong employee was pulled into a video conference populated entirely by deepfake recreations of his own colleagues, and the company later confirmed it lost $25.6 million across 15 separate wire transfers before anyone realized the meeting itself had been fabricated.


The employee did nothing wrong. He noticed the initial email was unusual. He escalated it. He asked for verification through the exact channel security training tells people to use: a live video call with the people supposedly making the request.


For years, that would have been the right answer. A voice on the phone can be faked with a few seconds of audio. A face on a screen, moving and speaking in real time alongside other familiar faces, felt like proof no phishing email could fabricate. Gartner had already flagged where this was heading, predicting that by 2026 nearly a third of enterprises will no longer consider face-biometric identity verification reliable on its own.


Praxis Hub infographic  showing a video meeting grid on a monitor and the text When the whole meeting is fake in teal and white.

That assumption is what the fraud was built to exploit. Every person on that call was generated from public video and audio of Arup's actual executives, the kind of footage sitting in earnings calls, conference panels, and company videos. The employee did not fail to verify. He verified against a standard that no longer holds.


What Voice Fraud Already Taught Your Team


Growing businesses have already absorbed one hard lesson about impersonation fraud, covered in our earlier post on the operational gap behind deepfake fraud: a familiar voice on a phone call is not proof of identity. A single voice impersonating a CEO or a finance lead has cost companies well over a million dollars in a single incident, even inside businesses with dual authorization and payment thresholds already in place.


Video call deepfake fraud is the next stage of the same pattern, and it is a harder one to catch. A phone call gives you one channel to fake. A video conference with multiple participants gives an attacker the chance to build social proof. When three or four familiar faces confirm the same request in the same meeting, the instinct to trust overrides the instinct to verify.


Teal Praxis Hub poster with a close-up eye behind torn paper and the slogan Seeing is no longer verifying.

What Actually Broke


It was not a systems failure. Arup confirmed that no internal technology was compromised. Nothing was hacked. The company's financial stability and operations were never at risk from a security standpoint.


What broke was an assumption sitting quietly inside the approval process: that a video call with recognizable people was sufficient confirmation to release a large sum of money. The technology did the convincing. The process did the authorizing.


Businesses that avoid this outcome tend to share a few quiet operational habits, not because they predicted deepfakes specifically, but because their approval structure never depended on any single moment of recognition in the first place.


  • A verification step that runs through a channel the original request never mentioned

  • A rule that no video call, however convincing, authorizes a transfer above a set threshold on its own

  • A named second approver who was not present on the call making the request

  • A built-in pause on large or unusual transfers, regardless of who appears to be asking

  • A habit of confirming urgent financial requests through a number or contact already on file, not one supplied in the message


None of this requires new software. It requires an approval process that was never built to trust a screen in the first place, the kind of gap a Business Process Improvement review is built to find before it gets tested.


Video Call Deepfake Fraud: The Control That Stops It


The uncomfortable truth in the Arup case is that better deepfake detection technology would not have been the fix. Detection tools are already losing ground to generation tools, and Gartner's own research points to the same conclusion: identity verification that leans on a face or a voice alone is becoming unreliable in isolation.


The fix that actually holds is procedural, not technical. A transfer request has to clear a channel the fraud never touched. That is a structural decision about how money moves inside a business, not a decision about which software to buy.


Praxis Hub infographic titled From One Voice to a Whole Meeting, showing phone call fraud, video call fraud, and verification steps.

Why Outside Perspective Helps


None of this reflects poorly on the employee who authorized the Arup transfer, and it would not reflect poorly on any team facing the same setup. You cannot see the gap in an approval process you built and use every day, especially one that has worked without incident for years. That is not a failure of judgment. It is a structural limitation that applies to anyone standing too close to the system they operate inside.


AI documents what you describe. It cannot see what you left out. A business can ask an AI tool to write a wire transfer policy and receive something clean, organized, and complete on paper, while the actual control gap, the one that only shows up when a video call feels real enough, stays invisible until it is tested by someone counting on exactly that blind spot.


Free Resource: AI Readiness Assessment


Before adding any new tool or vendor to solve a problem like this, it helps to know where a business actually stands. The AI Readiness Assessment gives owners and leadership teams a clear picture of where AI already touches financial and operational decisions, and where the habits around verification and approval need attention before automation makes the gap harder to see.


Get the AI Readiness Assessment - See where your business stands


Teal PRAXIS HUB book cover titled AI READINESS ASSESSMENT, a free download,, with AI chip brain, gears, and rising bar chart.

Frequently Asked Questions


What is video call deepfake fraud?


Video call deepfake fraud is a scam in which an attacker uses AI-generated video and audio to impersonate real people, often multiple people at once, during a live video conference. The goal is usually to convince an employee that a financial request is coming from executives or colleagues they already trust, when in fact no one on the call is real.


How is this different from voice cloning fraud?


Voice cloning fraud typically relies on a single fabricated voice during a phone call. This newer version adds fabricated faces and often multiple fake participants in the same meeting, which creates a stronger sense of social proof and makes the request feel more credible than a phone call alone.


Can dual authorization controls stop this type of fraud?


Dual authorization helps, but only if the second approver is verified through a separate channel from the original request. If both approvers rely on the same video call or the same compromised communication thread, the control does not close the gap that deepfake technology is built to exploit.


What is the fastest way to close this gap without new technology?


The fastest fix is procedural: require that any large or unusual transfer be confirmed through a phone number or contact already on file, never one supplied inside the request itself, regardless of how convincing the video call or email appears.


Why can't AI tools alone protect a business from this kind of fraud?


AI detection tools are working against AI generation tools that are improving just as fast, which means detection alone is not a stable defense. The more reliable protection sits in the approval process itself: a structural rule that no single video call can authorize money to move, no matter who appears to be on it.



Ready to Close the Gap Before Someone Tests It?


A business does not need to predict the next fraud technique to protect itself from one. It needs an approval process that never depended on a single point of recognition to begin with. If that structure is not in place yet, a Process Health Check identifies exactly where the gap sits and what it would take to close it.


The Back Office Brief


Get a weekly insight connecting back office operations to profit. Delivered every week, free.

The Back Office Brief

A weekly insight connecting back office operations to profit. For business owners running companies with 10 or more people who want to stop leaving money in broken systems.

Praxis Hub needs the contact information you provide to send you The Back Office Brief and to contact you about our services. You may unsubscribe at any time.

Comments


bottom of page