A phishing email used to be the whole attack. Now it is often just the opening move. Attackers increasingly combine a suspicious email or message with a follow-up phone call or video meeting in which the “executive” on the other end looks and sounds exactly like the real person, generated in real time by AI. That combination, deepfake plus phishing plus social engineering, is what makes deepfake video call scams so effective, and so difficult for even experienced employees to catch.
This article breaks down how the attack chain actually works, walks through 10 of the most widely reported, independently verified real-world cases from 2019 to 2024, and pulls out the common patterns that link them all.
Key Executive Takeaway
Modern deepfake fraud relies on a multi-stage process. The deepfake video or audio call is almost never the first touchpoint. It is the vocal or visual verification step designed to dissolve employee doubt after an initial phishing setup.
Quick Answers
What is a deepfake video call scam?
A deepfake video call scam is a fraud attempt in which attackers use AI-generated video or voice cloning to impersonate a trusted executive or colleague on a live video meeting or phone call, typically to authorize a fraudulent payment or extract sensitive information.
How do deepfake video call scams usually start?
Almost always with a phishing message. An email, a WhatsApp text, or a fake meeting invite sets up the pretext. The deepfake call is the follow-up that removes the target’s remaining doubt.
Are deepfake video call scams actually working?
Yes. Documented cases confirmed by law enforcement and published in major financial outlets describe successful and attempted scams against Arup, Ferrari, WPP, LastPass, Wiz, and Binance between 2019 and 2024, with verified losses ranging from hundreds of thousands to $46 million.
What is the single most effective defense?
Independent verification through a channel the caller could not have set up. Ask a personal question only the real person would know, or hang up and call back on a known internal number. This has repeatedly stopped deepfake scams even when the visuals looked convincing.
How the Attack Chain Actually Works
A deepfake video call scam is rarely just a deepfake. It is a coordinated attack combining three distinct techniques, each doing part of the job:
1. Phishing sets the pretext
The scam usually opens with an email or a text message referencing a plausible business scenario: a confidential acquisition, an urgent regulator request, or a quiet wire transfer that gives the eventual call a reason to happen.
2. Reconnaissance and impersonation prep
Attackers collect publicly available audio and video of the target executive: earnings calls, conference talks, YouTube videos, LinkedIn clips, and media interviews to train the voice and face model. Everything they need is typically already public.
3. The deepfake call closes the deal
Once the target agrees to a call or joins a meeting, the deepfake takes over: an AI-generated voice with the executive’s exact accent and cadence, an AI-generated video showing them on camera, and often other AI-generated participants added to create false consensus.
The reason this combination works, even against employees who might recognize a standalone phishing email, is that each element addresses the weakness of the last. The email creates a plausible business reason. The reconnaissance makes the impersonation convincing. The video call gives the target visual and auditory confirmation that the request is real. Our guide on social engineering vs deepfake scams vs phishing covers how these categories overlap and where they differ.
10 Real-World Deepfake Video Call Scams
1. The UK Energy Firm: $243,000 (2019)
One of the earliest widely reported cases of AI voice cloning being used in corporate fraud happened in March 2019, when the CEO of a UK-based energy firm received a call he believed was from the German CEO of the firm’s parent company. The caller, using an AI-generated version of the parent CEO’s voice complete with his subtle German accent and speech rhythm, asked for an urgent transfer of $243,000 to a Hungarian supplier within the hour. The UK CEO complied. The funds were moved through Hungary to Mexico and then dispersed.
According to Forbes reporting on the case, based on details shared by insurer Euler Hermes, the fraudster called back twice more: once to claim the transfer had been reimbursed, and once to request a follow-up payment. Suspicion was only raised when the reimbursement did not appear and the caller ID showed an Austrian number. This case proved that AI voice cloning had crossed from theoretical risk into active commercial exploitation.
2. UAE Bank Heist: $35 Million (2020)
In January 2020, a bank manager in the United Arab Emirates received a call from someone whose voice he recognized as a corporate director he had spoken with several times before. The call was reinforced by emails from a lawyer named Martin Zelner confirming the details of a supposed acquisition. Believing the request was legitimate, the bank manager authorized $35 million in transfers across multiple international bank accounts.
As Unite.AI documented, based on court records filed by Emirati authorities, Court documents cited by investigators stated that ‘deep voice’ technology was used to imitate the executive’s voice. to imitate the director’s voice. At least 17 individuals were involved in the operation. Two smaller transfers totaling roughly $415,000 were traced to US bank accounts, but the bulk of the funds moved through multiple foreign jurisdictions. This case remains one of the largest documented losses to a voice-cloned deepfake alone.
3. Binance: Zoom Hologram of the CCO (2022)
In August 2022, Binance Chief Communications Officer Patrick Hillmann disclosed on the company’s blog that a sophisticated hacking team had created what he called an AI hologram of himself, using prior TV interviews and public appearances as source material, and used it to run Zoom meetings with cryptocurrency project representatives. The fake Hillmann told them Binance was considering their tokens for exchange listing, a highly valuable prospect that could raise millions of dollars for targeted projects.
According to The Register’s coverage, the scam was uncovered when several project representatives contacted the real Hillmann to thank him for meetings he had no knowledge of, as he is not involved in exchange listing processes. This case marked one of the first known uses of a live video deepfake in a corporate meeting setting.
4. Arup: $25.6 Million Multi-Person Video Conference (2024)
In January 2024, a finance employee in the Hong Kong office of British engineering firm Arup authorized 15 wire transfers totaling around $25.6 million to five Hong Kong bank accounts. According to Hong Kong police, every other participant appearing on the video call was generated using deepfake technology.
According to CNN Business reporting based on Hong Kong police statements, the attack opened with a phishing message purporting to come from the UK-based CFO, asking for a confidential transaction. The employee suspected the email at first. However, the follow-up video conference, populated with what appeared to be the CFO and multiple recognized senior colleagues generated using public footage, overcame his doubt. Law enforcement described this as the first known case of scammers using multi-person deepfakes to deceive a financial target.
5. LastPass: Deepfake Audio of the CEO (April 2024)
In April 2024, password management company LastPass disclosed that one of its employees had been targeted with an audio deepfake impersonating CEO Karim Toubba. According to BleepingComputer coverage of the incident, the attacker used WhatsApp to deliver voice calls, text messages, and at least one voicemail featuring deepfake audio.
The attempt failed because WhatsApp was not a normal business communication channel at LastPass, and the messages arrived outside standard working hours. Both factors raised suspicion, leading the employee to report the incident to the internal security team rather than responding. LastPass shared details publicly specifically to highlight voice impersonation risks.
6. WPP: Deepfake Microsoft Teams Meeting (May 2024)
In May 2024, the CEO of advertising group WPP disclosed in an internal email that attackers attempted an elaborate deepfake scam impersonating him against another WPP executive. As documented in the OECD AI Incidents Monitor, attackers created a WhatsApp account using a public image of CEO Mark Read, then set up a Microsoft Teams meeting that appeared to be organized by Read and another senior executive.
During the meeting, According to WPP CEO Mark Read, the attackers used publicly available material to impersonate senior executives during the attempted scam of the target executive along with YouTube video footage, while impersonating Read off-camera through the meeting chat window. The target agency leader was asked to set up a new business as a pretext for extracting money and credentials. The attempt was unsuccessful.
7. Elon Musk Deepfakes: Beauchamp Loses $690,000 (2024)
In 2024, deepfake investment scams featuring AI-generated Elon Musk videos endorsing fraudulent cryptocurrency platforms became a widespread category of consumer fraud. As CBS News documented citing analysis by Sensity, Musk has been reported as one of the most frequently impersonated public figures in AI-powered investment scams. in deepfake financial fraud.
In one documented case, 82-year-old Steve Beauchamp saw a deepfake video of Musk endorsing a high-yield platform, contacted the operators, and over several weeks drained more than $690,000 from his retirement account. This category demonstrates how the underlying video cloning tools used in public fraud mirror the tooling deployed against corporate targets.
8. Ferrari: Stopped by the Book Question (July 2024)
In July 2024, an executive at Italian automaker Ferrari received WhatsApp messages appearing to come from CEO Benedetto Vigna, referencing a confidential acquisition and requesting urgent assistance. The follow-up phone call used a voice clone convincing enough to reproduce Vigna’s subtle Southern Italian accent.
According to MIT Sloan Management Review’s analysis of original Bloomberg reporting, the Ferrari executive noticed minor tone inconsistencies and asked an unrehearsable question: the title of a book Vigna had personally recommended to him days earlier. The caller could not answer and hung up. This case demonstrates how a simple personal verification question can defeat even convincing AI voice-cloning attacks
9. Hong Kong Pig-Butchering Ring: $46 Million (October 2024)
In October 2024, Hong Kong law enforcement announced the arrest of 27 people connected to an organized fraud ring that defrauded victims of approximately $46 million using deepfake face-swap technology on live video calls to establish trust.
According to CNN coverage of police briefings, operators used AI face-swapping software during video calls to build long-term trust before directing targets to fake investment portals. This case demonstrated that real-time video deepfakes are operating at industrialized scale beyond isolated executive targeting.
10. Wiz: Deepfake Voice Sent to Dozens of Employees (October 2024)
In October 2024, Wiz co-founder and CEO Assaf Rappaport disclosed onstage at TechCrunch Disrupt that his employees had been targeted with a deepfake voice attack attempting to harvest credentials.
According to TechCrunch’s reporting on Rappaport’s disclosure, dozens of employees received voicemails asking for internal login credentials. The attack failed because the audio had been cloned from one of his conference presentations, where his speaking-anxiety voice sounded noticeably different from his day-to-day conversation.. Employees recognized the nuance and flagged the messages immediately.
Common Patterns Across All 10 Cases
Read together, these documented incidents reveal consistent structural operational trends:
- Every corporate scam opened with a phishing pretext: The video or voice call was consistently used as a confirmation step, never the cold entry point.
- Clones were generated from public collateral: Keynotes, media appearances, podcasts, and earnings calls provided ample training data.
- Deepfakes succeeded by overriding initial hesitation: In the Arup and UAE cases, employees who questioned the initial email had their concerns neutralized by visual or vocal confirmation.
- Defeated attempts relied on active verification: Unscheduled channels, out-of-band checks, and personal security questions broke the attack flow.
For further analysis on synthetic media risks, explore our overview of the top 10 deepfake phishing scams and review our collection of 50 real-life social engineering and phishing attack scenarios.
Why Executives and Their Teams Are the Priority Target
Every documented corporate incident has targeted either C-suite leadership directly or staff members possessing payment authorization authority, such as finance directors and executive assistants.
Executives represent an ideal target profile for three structural reasons: their vocal and visual data is abundantly available online, they possess authority to bypass standard operational friction, and requests originating from their office carry urgency. Our analysis on whaling attacks and executive security training details how high-target individuals require specialized awareness frameworks.
How Organizations Can Reduce Exposure
Effective defensive posture does not rely on training employees to visually spot digital artifacts on high-speed video calls. Instead, organizations must harden verification procedures:
- Mandate out-of-band verification: Require secondary verification over a separate internal communication channel for non-standard payment transfers regardless of executive rank.
- Treat unexpected channels as high risk: Flag communication attempts occurring over unapproved external channels such as personal WhatsApp or SMS.
- Deploy multi-channel simulation training: Integrate voice and video scenarios into awareness programs using a dedicated vishing simulation platform to train staff against multi-stage attacks.
- Adopt internal challenge protocols: Encourage employees to ask contextual challenge questions when handling urgent high-value operational directives.
PhishCare campaign reports provide an additional documentation boost for organizations working towards ISO 27001, SOC 2 Type II, PCI DSS, HIPAA, or NIST CSF, where ongoing security awareness training is recognized as a best practice by auditors and certification bodies.
Final Thoughts
Deepfake video call scams succeed because synthetic media fits seamlessly into existing social engineering chains. Phishing sets the initial premise, open-source media provides training data, and real-time generative video supplies visual trust.
By establishing rigorous out-of-band verification standards and addressing multi-channel attack paths directly, organizations can protect their operations against evolving synthetic impersonation threats.
Frequently Asked Questions
What is a deepfake video call scam?
It is a fraud attempt in which attackers use AI-generated video or voice cloning to impersonate a trusted person, usually a senior executive, on a live video meeting or phone call. The goal is typically to authorize a fraudulent payment or extract sensitive information.
How do attackers make convincing deepfakes of company executives?
Publicly available audio and video is usually enough. Earnings calls, keynote talks, YouTube interviews, LinkedIn videos, and podcasts provide the raw material to train voice and face models. No internal access to the target company is required to build a convincing impersonation.
What was the largest reported deepfake video call scam?
For a single incident, the UAE bank heist in January 2020 ($35 million) remains the largest publicly documented loss to a voice-cloned deepfake. The Arup case in Hong Kong ($25.6 million in early 2024) is the largest publicly documented loss involving a multi-person deepfake video conference.
Can a deepfake video call be detected in real time?
Reliably spotting a modern deepfake by eye or ear is difficult and getting harder. The more practical defense is process-based: independent verification through a separate channel, a personal question the caller could not have prepared for, and treating unusual communication channels as a red flag by default.
How can organizations train employees against deepfake video call scams?
Effective training goes beyond spotting suspicious emails to cover the full multi-channel attack pattern, including follow-up voice and video calls. Regular, realistic simulation of the whole pattern, not just individual email templates, has been shown to significantly improve employee response.
Content Reviewed By

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking. He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.
View LinkedIn ProfileStrengthen Your Organization Against Multi-Stage Cyber Attacks
PhishCare, developed by CyberSapiens, provides comprehensive phishing and security awareness training platforms designed to help teams build lasting defense habits against evolving social engineering tactics.







