Arup, the London-based engineering and design firm, confirmed that fraudsters stole about HK$200 million (roughly US$25 million) after targeting an employee in its Hong Kong office with a deepfake-enabled impersonation scheme. According to the company and Hong Kong police, the employee first received a message appearing to come from Arup’s UK office about a confidential transaction and initially suspected phishing, but later joined a video conference in which AI-generated voices and images convincingly mimicked the company’s CFO and other colleagues.
Believing the meeting was legitimate, the employee transferred funds to multiple Hong Kong bank accounts before checking with headquarters and discovering the scam. Arup said it reported the incident to Hong Kong police in January, that the case remains under investigation, and that its internal systems were not compromised and business operations were unaffected. The theft has drawn attention to the growing use of deepfake video, voice spoofing, and business email fraud in corporate payment scams, with security experts warning that generative AI is making executive impersonation attacks more convincing and scalable.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Arup confirmed that it was the company targeted in the Hong Kong deepfake fraud case and said fake voices and images had been used to deceive an employee. The company reiterated that its systems were not compromised and that the matter remained under police investigation.
Hong Kong police revealed that a multinational company had lost about HK$200 million after an employee was deceived by AI-generated video and voice impersonations during a conference call. The disclosure brought wider attention to the scale and sophistication of deepfake-enabled business fraud.
Arup notified Hong Kong police in January after discovering the fraudulent transfers. The case was opened for investigation, and Arup later said its operations and financial stability were unaffected and that no internal systems were compromised.
A finance employee in Arup's Hong Kong office received a message about a confidential transaction and then joined a video conference featuring AI-generated impersonations of the company's CFO and other staff. Believing the participants were legitimate, the employee transferred about HK$200 million (roughly US$25 million) to fraudsters across multiple Hong Kong bank accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcecfodive.com
Open sourcecnn.com
Open sourceedition.cnn.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.