explainx.ainewsletter3.5k
TrendingNewsPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

learn

pathways — start freeworkshopsbootcampscoursescertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsagentsllmsdesignsdictionaryagi trackerranks

company

aboutvisionmissionteaminstructorscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

On this page

  • TL;DR
  • What actually happened
  • The attack that failed — and why the difference matters more than the technology
  • The pattern behind almost every successful deepfake fraud
  • Out-of-band verification: the one habit that keeps winning
  • Reducing your own deepfake exposure before an attack happens
  • The regulatory angle: disclosure over detection
  • Coming soon from explainx.ai: AI Ethics & Responsible Use
  • Related reading
← Back to blog

explainx / blog

Deepfake Fraud: Inside the $25.6 Million Video Call Scam

An engineering firm employee authorized 15 wire transfers on a video call where every participant, including the CFO, was an AI deepfake. Here's the fraud pattern — and the one habit that has repeatedly beaten it.

Aug 19, 2026·7 min read·Yash Thakker
AI EthicsAI SafetyDeepfakesFraud PreventionResponsible AIContent Provenance
go deep
Deepfake Fraud: Inside the $25.6 Million Video Call Scam

A video call window with a subtly glitching participant tile, symbolizing an AI deepfake impersonating a real person on a call

A finance employee joined what looked like a routine internal video call. Every other participant on it — including someone who appeared to be his company's chief financial officer — was an AI-generated deepfake. By the end of that call, he had authorized fifteen wire transfers totaling $25.6 million. Nobody caught it until internal verification, after the money was already gone.

This case study is part of an upcoming AI Ethics & Responsible Use course from explainx.ai — details on that below.

TL;DR

table · 2 cols
QuestionAnswer
What happened?An employee at an engineering firm's Hong Kong office authorized $25.6M across 15 transfers on a call where every participant was a deepfake
Did a similar attack ever fail?Yes — a near-identical attempt on an advertising-industry CEO's identity was caught before any money moved
What's the difference between the two?The failed attempt was verified through a separate channel before anyone acted
What's the fix?Out-of-band verification — confirm high-stakes requests through a channel the attacker doesn't control
Is there a regulatory angle?Yes — the EU AI Act requires disclosure and C2PA watermarking for AI-generated synthetic media
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

What actually happened

The case that changed how seriously companies take deepfake fraud involved a finance employee at an engineering firm's Hong Kong office. He received what looked like a routine internal communication, then joined a video call where every other participant — including someone who appeared to be the company's CFO — was AI-generated. Believing he was following legitimate executive instructions, he authorized fifteen separate transfers totaling $25.6 million in a single day. The fraud was only discovered during internal verification procedures, well after the money had already moved.

The attack that failed — and why the difference matters more than the technology

Not every attempt succeeds, and the failures are worth studying just as closely as the successes. In a separate case, attackers built a fake messaging account using a publicly available photo of a real advertising-industry CEO, then arranged a video call using a voice clone and synthetic video to impersonate him convincingly. Staff grew suspicious and escalated the situation before any money moved — no funds were lost.

The difference between that case and the $25.6 million one wasn't the sophistication of the deepfake. Both were technically convincing. The difference was that someone paused, got suspicious, and verified through a separate channel before acting. The MIT Sloan case study on the advertising-CEO incident treats exactly this — asking something the AI cannot know — as the clearest example of a low-tech countermeasure beating a technically advanced attack.

The pattern behind almost every successful deepfake fraud

This pattern extends well beyond corporate wire fraud. A deepfake video of a stock exchange's own CEO circulated widely, falsely promoting fraudulent investment tips. A scammer impersonating a sitting prime minister convinced a victim to transfer $3.8 million. Celebrity "endorsement" deepfakes — real public figures appearing to guarantee returns on cryptocurrency platforms they've never touched — have defrauded victims of millions more.

The mechanism is nearly identical across all of them:

  1. Urgency — the request demands action quickly, discouraging you from stepping back to double-check.
  2. Authority — it comes from someone who appears to have legitimate standing to make the request.
  3. A hard-to-verify channel — a video call or voice message that feels too real to doubt in the moment.

Remove any one of those three elements, and most of these scams fall apart.

Out-of-band verification: the one habit that keeps winning

The countermeasure that has repeatedly beaten even highly sophisticated deepfakes is simple to describe and easy to forget under pressure: out-of-band verification — confirming a request through a completely separate channel before you act on it. If a video call is asking you to move money or share sensitive data, hang up and call the person back on a phone number you already had on file, not one they just gave you on the call. Ask a question only the real person would know the answer to — something a deepfake, however good it looks, has no way to fabricate.

This is the same logic behind the Verify step in the responsible-AI framework: treat anything specific enough to be wrong — including a person's identity on a video call — as something that needs independent confirmation before it goes anywhere consequential.

Reducing your own deepfake exposure before an attack happens

Out-of-band verification is what stops a deepfake attack in the moment. There's also a slower, upstream habit worth building: reducing how much raw material — clear face shots, consistent backgrounds, recognizable voice samples — you leave publicly scattered across social posts and video content for attackers to train a clone on in the first place. The advertising-CEO impersonation above started with nothing more than a single publicly available photo.

For executives, public-facing employees, or anyone posting video content professionally, a privacy-first habit worth adopting is blurring or removing identifying background details before footage goes public — the same instinct behind blurring license plates and faces in shared video. BGBlur, a sister tool in the explainx.ai family, is built for exactly this: AI-powered face and background blurring that reduces the identifying detail available in your own published content, without needing a video editing background.

The regulatory angle: disclosure over detection

As synthetic media has gotten harder to detect visually, the global regulatory response has shifted toward requiring transparency at the point of creation rather than relying on detection after the fact. The EU AI Act requires clear disclosure when people are interacting with an AI chatbot or viewing AI-generated synthetic media, and requires machine-readable watermarking — often through the C2PA standard — to be embedded in generated audio, image, and video content. Several major AI image and video generators already implement this; not all of them do, which is itself worth knowing when you're evaluating which tools your organization trusts for content generation, and it's a reminder of why stripping that provenance metadata later carries real weight even outside a fraud context.

Coming soon from explainx.ai: AI Ethics & Responsible Use

This case is one module in an upcoming course from explainx.ai, AI Ethics & Responsible Use, taught by Yash Thakker — a practical look at where AI goes wrong in real workplaces and courtrooms, and what to actually do about it, built around a simple four-step framework (Verify, Protect, Disclose, Own). No release date yet — subscribe to explainx.ai's newsletter to hear when it drops.

Related reading

  • Top 10 AI Ethics Rules for Responsible AI Use — the five-pillar framework this fraud pattern maps to (transparency and security).
  • AI Hallucination Legal Cases: Why Lawyers Keep Getting Sanctioned — a different accountability failure, where the deception was accidental rather than deliberate.
  • Shadow AI: The Silent Privacy Risk in Every Workplace — how AI-related risk also fails quietly, without any fraud involved.
  • LinkedIn Adds Content Credentials (C2PA) to AI Images — how platform-level provenance labeling works in practice.
  • Is Removing an AI Watermark Illegal? — the legal weight of provenance metadata, relevant to synthetic-media disclosure generally.
  • Why AI Watermarks Are Good: The Case for Provenance — why C2PA-style disclosure exists as a countermeasure to exactly this kind of fraud.

Source: MIT Sloan case study on deepfake corporate fraud; public reporting on the engineering-firm Hong Kong incident and related deepfake fraud cases, as referenced above.

This article is for general education, not legal or security advice. Verify current fraud-prevention guidance with your organization's security team; case details reflect public reporting as of August 19, 2026.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

Related posts

Aug 19, 2026

AI Hallucination Legal Cases: Why Lawyers Keep Getting Sanctioned

Mata v. Avianca made headlines in 2023 as the first AI hallucination sanction. It was the opening act, not the exception. A public case tracker now documents well over 1,500 court filings worldwide where fabricated AI citations reached a judge — and the pattern behind who gets sanctioned hardest has almost nothing to do with the original mistake.

Aug 19, 2026

Shadow AI: The Silent Privacy Risk in Every Workplace

Roughly two in three employees already use AI tools at work, but fewer than one in five organizations have a formal AI usage policy. That gap has a name — shadow AI — and it's the quietest, most expensive way responsible AI use breaks down. We cover the mechanism, a widely reported real-world leak, and what actually reduces the risk without banning tools.

Aug 19, 2026

Top 10 AI Ethics Rules for Responsible AI Use in 2026

"Use AI responsibly" is not a rule, it's a slogan. These 10 rules are built from documented court cases, regulatory settlements, and a four-step framework — Verify, Protect, Disclose, Own — you can actually run through in your head before using AI for something that matters.