Back to the blog
Cybersecurity

Deepfakes: when the call from the boss is a fake

Imagine you are in a video conference. Your finance chief is on the call, two colleagues as well. You recognize the faces, the voices, the way they speak. The CFO asks you to urgently carry out a series of transfers, strictly …

Justin Shabani

Managing Director & Founder

3 min read
Deepfakes: when the call from the boss is a fake, cover image

Imagine you are in a video conference. Your finance chief is on the call, two colleagues as well. You recognize the faces, the voices, the way they speak. The CFO asks you to urgently carry out a series of transfers, strictly confidential, it is about an acquisition. You hesitate briefly, but everything looks real. So you do it.

That is exactly what happened to an employee of the engineering group Arup. In the end, around 25 million US dollars were gone. The insidious part: apart from him, nobody in that conference was real. Every person on the call, including the CFO, was an AI-generated deepfake1. Welcome to the new reality of fraud.

Why deepfakes break the rules of the game

How a faked video call turns into millions in damage.

For decades a simple rule of thumb applied: if I can see and hear someone, they are real. That is exactly the rule deepfakes cancel out. Modern AI can recreate a real person's face, voice and expressions so convincingly that they can appear live in a video call.

That changes everything. The classic safeguard, to quickly call back and check in case of doubt, no longer works when the voice at the other end is itself faked. The attack does not target your firewall but your employees' basic trust in what they see with their own eyes.

Not an isolated case, but a wave

Generative-AI-enabled fraud is forecast to grow rapidly.

The Arup case is spectacular, but it is not an outlier. The number of deepfake fraud attempts is rising rapidly, and the damage grows with it. The consulting firm Deloitte estimates that generative-AI-enabled fraud in the US alone could grow to around 40 billion US dollars by 2027, up from about 12 billion in 20232.

The pattern is almost always the same: a faked authority figure, artificial urgency, absolute confidentiality, a request for payment or data. The technology is new, the psychological trick is ancient. That is exactly what makes it so dangerous, because it hits people at their most vulnerable point: the wish to be helpful and fast.

Why technology alone does not protect

Of course, detection software is being developed, and it helps. But it is a race in which the fakes keep getting better. Relying solely on a technical filter that will surely catch the next deepfake is a dangerous promise.

The most effective protection sits between your employees' ears. A team that knows the trick, that knows a video call is no longer proof of authenticity, and that has clear rules for critical processes, is far harder to fool. Here, awareness is not a soft add-on but the hardest line of defence you have.

Rehearsing the emergency before it happens

Knowledge alone, however, is not enough. In the rush of daily work, under the pressure of a seemingly urgent instruction from the boss, people fall back on reflexes, not on leaflets they once read. Reflexes only form through practice.

This is exactly where AI-THINK.'s AI-VI Cybersecurity Coach comes in. In a safe simulation, employees live through realistic incidents, including such social engineering and deepfake scenarios. They experience the pressure, make decisions and learn from the outcome, without real money being at stake. Abstract knowledge becomes a trained reflex. And because the content rests on the validated AI-VI Core Technology, every explanation in the training is reviewed and provable, not invented half-knowledge.

In very practical terms, a simple rule also helps: critical payments or data releases need a second, independent channel for confirmation that an attacker cannot also fake. No video call in the world replaces this callback via a previously agreed route.

Conclusion

Deepfakes turn seeing and hearing into an unreliable witness. The Arup case with 25 million US dollars in damage is the warning nobody should ignore, and it will not be the last.

Protection lies not in better software alone, but in vigilant, trained employees and clear rules for the emergency. Anyone who lets their people experience the attack once, safely, makes them resilient in the real moment.

What you can do now

  1. Define a second channel for payment approvals that does not run through the caller.

  2. Remove „I saw and heard the person“ from your approval criteria.

  3. Rehearse the case once instead of only describing it.

And if you need a reviewed basis for that: Get to know AI-VI

Sources

  1. [1]World Economic Forum: Deepfake fraud: lessons from a $25m attack (2025) sowie CFO Dive und Trend Micro zum Fall Arup, bei dem ein Mitarbeiter nach einem Deepfake-Videocall rund 25 Mio. US-Dollar überwieshttps://www.weforum.org/stories/2025/02/deepfake-ai-cybercrime-arup/
  2. [2]Deloitte Center for Financial Services, zitiert in VentureBeat: Deepfakes will cost $40 billion by 2027, durch generative KI ermöglichter Betrug in den USA könnte von rund 12,3 Mrd. (2023) auf ca. 40 Mrd. US-Dollar (2027) steigenhttps://venturebeat.com/security/deepfakes-will-cost-40-billion-by-2027-as-adversarial-ai-gains-momentum
Back to the blog

14 May 2026 · 3 min read

AI-VI, your AI avatar

With your consent we load three Google services: product videos from YouTube, audience measurement with Google Analytics and ad measurement from Google Ads. Data is transferred to Google in the process. Without your consent none of it loads, and videos show a preview image served from our own server. The website works fully either way. You can decide service by service under Settings, and change it at any time. Privacy policy