---
title: "Deepfake scams: how AI voice and video fraud targets finance"
description: "How deepfake scams and AI voice cloning target finance teams, what the Arup and Ferrari cases teach, and a verification protocol your team can run today."
url: https://realpayee.com/blog/deepfake-scams
canonical: https://realpayee.com/blog/deepfake-scams
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# Deepfake scams: how AI voice and video fraud targets finance teams

> A deepfake scam uses AI-generated voice or video to impersonate a person you trust, usually an executive or a vendor contact, and push you to move money. You cannot reliably spot a good deepfake by ear or eye. You stop it with process: never act on an inbound call or video, and confirm the request on a channel you start.

_Fraud prevention · Published 2026-10-05 · 5 min read · By the RealPayee team_

## Key takeaways

- Deepfakes make the **inbound** channel untrustworthy: a call, voice note or video meeting proves nothing about who is on the other end.
- In 2024, an Arup employee transferred about **$25.6 million** after a video call in which every other participant was a deepfake.
- A Ferrari executive stopped a cloned-voice CEO call with **one personal question** the impostor could not answer.
- The defense is a short, rehearsed protocol: hang up, call back on a known number, ask a challenge question, and never let urgency override it.

## What is a deepfake scam?

A deepfake scam is social engineering with synthetic media. The criminal uses AI tools to clone a voice from a few public clips (an earnings call, a podcast, a conference talk, a voicemail greeting) or to generate a live video face, then contacts someone who can move money. The script is the same as classic [CEO fraud](https://realpayee.com/ceo-fraud): something urgent and confidential, a new account, no time to follow the normal process. What changes is the proof. A familiar voice or face used to be good evidence. It no longer is.

Deepfakes are usually layered onto business email compromise rather than replacing it. A typical sequence: an email or chat message sets up the story, then a short call or video meeting "from the CFO" removes the doubt. That combination is what makes these attacks effective against careful people.

## Two real cases every finance team should know

### Arup: a video call full of deepfakes

In early 2024, an employee in the Hong Kong office of the engineering firm Arup received a message about a confidential transaction and joined a video conference with what appeared to be the company's UK-based CFO and several colleagues. Every other person on the call was a deepfake. Reassured by seeing familiar faces, the employee made a series of transfers totaling about **$25.6 million** before the fraud was discovered.

The lesson is not that the employee was careless. The lesson is that a multi-person video call, which most training would treat as strong verification, was the attack itself.

### Ferrari: stopped by a personal question

In July 2024, a Ferrari executive received WhatsApp messages and then a call from someone using a convincing imitation of CEO Benedetto Vigna's voice, discussing a confidential deal. Something felt off, so the executive asked about a book Vigna had recommended to him a few days earlier. The caller could not answer and hung up. [Fortune reported the attempt](https://fortune.com/europe/2024/07/27/ferrari-deepfake-attempt-scammer-security-question-ceo-benedetto-vigna-cybersecurity-ai/).

The lesson: the executive did not try to judge whether the voice was synthetic. He tested for knowledge that only the real person had. That works regardless of how good the deepfake is.

## How AI voice cloning scams reach accounts payable

Executive impersonation gets the headlines, but voice cloning also targets AP through vendors. Common patterns:

- **The "confirming" call:** an email requests a vendor bank-detail change, then a call from "the vendor's controller" confirms it, so the team believes a callback already happened.
- **The voicemail:** a cloned voice note from a known contact asks AP to watch for new remittance details.
- **The executive approval:** an AP clerk who flags a suspicious change receives a call from "the CFO" telling them it is fine to proceed.
- **The help desk reset:** a cloned employee voice asks IT to reset multi-factor authentication, giving the attacker access to a finance mailbox for a later BEC attack.

> [!WARNING]
> **An inbound call is not a callback**
> If they called you, nothing has been verified. Verification only counts when you start the contact, using details you already had before the request arrived.

## Red flags of a deepfake call or video

Visual and audio glitches (odd blinking, lip sync drift, flat intonation) are worth noticing, but do not rely on them: tools improve every few months, and a poor connection hides artifacts. Behavioral signals are more reliable:

| Signal | Example |
| --- | --- |
| New channel for this person | The CEO, who always uses Teams, messages you on WhatsApp from an unknown number |
| Payment plus secrecy | "Keep this between us until the deal is announced" |
| Pressure on timing | "The window closes in an hour" |
| Resistance to a callback | "My phone is dying, just use this line" or "I'm about to board" |
| Camera or audio excuses | Video is choppy, they keep the call short, they avoid back-and-forth |
| Process bypass | "Skip the second approver this time, I'm authorizing it" |

## A deepfake verification protocol for finance teams

Write this down, get leadership to endorse it publicly, and practice it. The goal is that no one has to make a judgment call under pressure.

1. **Inbound requests are never verification.** Any request to move money or change bank details that arrives by call, voice note, video or chat is treated as unverified, whoever it appears to come from.
2. **Hang up and call back on a known number.** Use the number in your HR or vendor file, never one supplied in the request.
3. **Ask a challenge question** the real person can answer and a researcher cannot: something from a recent internal meeting, not from LinkedIn. Some teams agree a rotating code word for payment approvals.
4. **Keep the normal approval chain.** No executive, however senior, can waive the second approver or the threshold rule by phone.
5. **Make slowing down safe.** Executives state in writing that they will never be upset by a callback, and thank staff who do it.
6. **Escalate and log.** Report suspected attempts to security and finance leadership, and keep the record. Attempts usually come in waves.

### A callback script your team can use

"Thanks, I'll action this as soon as I've confirmed it through our normal process. I'm going to call you back on the number we have on file in the next few minutes." Then hang up, find the number independently and call. If the request was real, the cost is five minutes. If it was not, the attacker usually disappears at this step.

## How to train for deepfake scams

- **Use the real cases.** Walk through Arup and Ferrari in a 20-minute session with AP, treasury, payroll and executive assistants.
- **Run a drill.** With leadership's approval, send a test request (an email, then a call from a colleague playing the executive) and see whether the protocol is followed. Debrief without blame.
- **Reduce what can be cloned where it is cheap to do so.** Avoid publishing executives' direct numbers, and consider whether voicemail greetings need the executive's own voice.
- **Include executives.** They are the impersonated party and need to know the protocol so they do not undermine it.

## Where detection tools fit

Deepfake detection tools can flag synthetic audio or video, and adoption is growing, but only **17% of organizations** in the AFP's 2026 survey said they were using AI for fraud mitigation. Detection is also an arms race. The control that does not depend on winning it is verification of the person and the request through an independent channel. That is what RealPayee does for payment requests: it holds bank-detail changes and large payments until the real contact or executive confirms out-of-band, using phone-bound approval or ID plus live selfie, and keeps the evidence. See how it compares with manual callbacks in our [comparison](https://realpayee.com/compare).

## Frequently asked questions

### What is a deepfake scam?

A deepfake scam uses AI-generated voice or video to impersonate a trusted person, such as an executive or vendor contact, to persuade someone to send money or sensitive data.

### How do AI voice cloning scams work?

Criminals take short public recordings of a person's voice, generate a synthetic copy, and use it in calls or voice notes. The voice adds credibility to a request that usually also arrives by email or chat.

### How can you tell if a call is a deepfake?

Often you cannot. Instead of judging the voice, hang up and call back on a number you already had, and ask a question only the real person could answer.

### Is a video call enough to verify a payment request?

No. The Arup case showed a multi-person video call can be entirely fake. Verification has to be a contact you initiate through a channel you already trusted.

### What should finance teams do after a deepfake attempt?

Report it to security and leadership, warn the team because attempts come in waves, file a complaint at ic3.gov if money moved, and review whether the protocol was followed.

## Sources

- [Fortune: Ferrari exec foils deepfake attempt with a personal question](https://fortune.com/europe/2024/07/27/ferrari-deepfake-attempt-scammer-security-question-ceo-benedetto-vigna-cybersecurity-ai/)
- [AFP: over 75 percent of US firms experienced payments fraud in 2025, while AI adoption for fraud mitigation lags](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/over-75-percent-of-us-firms-experienced-payments-fraud-in-2025-while-ai-adoption-for-fraud-mitigation-lags)

## Related

- [Business email compromise examples and how to stop them](https://realpayee.com/blog/business-email-compromise-examples) - Seven business email compromise (BEC) examples finance teams see, the red flags in each, and the specific control that stops it before money moves. (markdown: https://realpayee.com/blog/business-email-compromise-examples.md)
- [Accounts payable segregation of duties: a practical matrix](https://realpayee.com/blog/segregation-of-duties-accounts-payable) - How to segregate duties in accounts payable, with a role matrix, small-team workarounds and the gap segregation of duties does not close: impersonation. (markdown: https://realpayee.com/blog/segregation-of-duties-accounts-payable.md)
- [CEO fraud and deepfake executive calls: how finance teams stop them](https://realpayee.com/ceo-fraud) - How CEO fraud works - from spoofed emails to deepfake video calls - and the verification steps that stop fake payment requests. (markdown: https://realpayee.com/ceo-fraud.md)
- [Wire fraud prevention: how to stop bank wire fraud](https://realpayee.com/wire-fraud-prevention) - Controls that prevent business wire fraud: out-of-band verification, payment thresholds, dual approval and audit trails. (markdown: https://realpayee.com/wire-fraud-prevention.md)
- [Compare: manual callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare) - An honest comparison of approaches to stopping vendor-impersonation and fake payment requests. (markdown: https://realpayee.com/compare.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/blog/deepfake-scams · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
