NetGoodIndexSubmit a correction

Harm Ledger · verified · Computer Science

Deepfake video meeting tricks Arup staff into transferring about $25 million

In January 2024 an Arup finance employee in Hong Kong sent HK$200 million (~US$25 million) after a video call featuring cloned voices and faces of the CFO and colleagues.

15 Jan 2024Tier 3 Major HarmMethodology 0.1

Current score

0.84

10 base · Major Harm (tier 3 of 5, 10 pts)
× 0.5000 attribution · Material acceleration
× 0.7000 evidence · Peer review or independent validation
× 1.0000 realization · Realized outcome
× 0.4000 durability
Event-level product before credit split: 1.40

Tens of millions stolen via AI impersonation is major financial harm (tier 3), not systemic market failure. Attribution to unnamed generative video/voice models plus social engineering. Company and police confirmation. Money was transferred. Partial recoverability unknown.

What happened

Hong Kong police described 15 transfers to five accounts. Arup confirmed fake voices and images and said internal systems were not hacked. The specific generative models were not identified. This is one of the largest publicly attributed deepfake-enabled corporate thefts.

Model attribution

Unknown generative media models

Generated fake CFO and colleague faces and voices used on the call.

Arup confirmed synthetic media; phishing and human authorization were also required.

Attribution 0.5000 · Credit share 60% · Unknown

Claims

  • An Arup employee transferred about US$25 million after a video conference that used fake voices and images.

    outcome · supported

Sources

independent sources

Secondary domains: Engineering

Revision history

  • 13 Sep 2026 · 0.00 0.84

    Initial adjudicated seed score under methodology 0.1.