🚨Arup Loses $25M to AI-Generated Deepfake Scam
Your video calls aren't safe anymore, and that's a big deal
TL;DR
An advanced deepfake attack on Arup resulted in $25M being transferred to third-party accounts. Traditional security measures are failing as these attacks grow more sophisticated.
In January 2024, professional services firm Arup suffered a massive financial loss of around $25 million due to an AI-generated deepfake scam. The attack involved impersonating the company's CFO in a video call and convincing employees to transfer funds to third-party accounts. This incident highlights how traditional security measures that rely on visual and auditory verification are no longer sufficient against sophisticated AI attacks. Experts now recommend low-tech solutions such as hardware-based security keys or verbal passphrases for multi-factor authentication (MFA).

Key Points
In January 2024, Arup suffered a $25m loss due to an AI-generated deepfake attack on their video call system.
The deepfake replicated executives' appearances and voices with such accuracy that it bypassed all visual and auditory verification methods.
Low-tech security measures like hardware-based FIDO2 keys are now recommended by the NSA, FBI, and CISA for MFA.
Verbal passphrases shared among team members can help prevent social engineering attacks but must be consistently enforced.
Running simulated deepfake calls as part of employee training is crucial to improve awareness and response mechanisms.
Why It Matters
If you're conducting high-stakes video calls, your current security protocols are likely outdated. The Arup incident shows that visual/audio verification alone isn't enough against AI-generated deepfakes. Consider implementing FIDO2 hardware keys or verbal passphrases for MFA to stay ahead of these threats.
Frequently Asked Questions
Why does this matter?
If you're conducting high-stakes video calls, your current security protocols are likely outdated. The Arup incident shows that visual/audio verification alone isn't enough against AI-generated deepfakes. Consider implementing FIDO2 hardware keys or verbal passphrases for MFA to stay ahead of these threats.
What happened?
An advanced deepfake attack on Arup resulted in $25M being transferred to third-party accounts. Traditional security measures are failing as these attacks grow more sophisticated.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,293 builders reading daily.