Skip to content
ZDNET·

🚨Arup Loses $25M to AI-Generated Deepfake Scam

Your video calls aren't safe anymore, and that's a big deal

TL;DR

An advanced deepfake attack on Arup resulted in $25M being transferred to third-party accounts. Traditional security measures are failing as these attacks grow more sophisticated.

In January 2024, professional services firm Arup suffered a massive financial loss of around $25 million due to an AI-generated deepfake scam. The attack involved impersonating the company's CFO in a video call and convincing employees to transfer funds to third-party accounts. This incident highlights how traditional security measures that rely on visual and auditory verification are no longer sufficient against sophisticated AI attacks. Experts now recommend low-tech solutions such as hardware-based security keys or verbal passphrases for multi-factor authentication (MFA).

Arup Loses $25M to AI-Generated Deepfake Scam — ZDNET

Key Points

1

In January 2024, Arup suffered a $25m loss due to an AI-generated deepfake attack on their video call system.

2

The deepfake replicated executives' appearances and voices with such accuracy that it bypassed all visual and auditory verification methods.

3

Low-tech security measures like hardware-based FIDO2 keys are now recommended by the NSA, FBI, and CISA for MFA.

4

Verbal passphrases shared among team members can help prevent social engineering attacks but must be consistently enforced.

5

Running simulated deepfake calls as part of employee training is crucial to improve awareness and response mechanisms.

Why It Matters

If you're conducting high-stakes video calls, your current security protocols are likely outdated. The Arup incident shows that visual/audio verification alone isn't enough against AI-generated deepfakes. Consider implementing FIDO2 hardware keys or verbal passphrases for MFA to stay ahead of these threats.

deepfakeai-attackmfavideo-call-security

Frequently Asked Questions

Why does this matter?

If you're conducting high-stakes video calls, your current security protocols are likely outdated. The Arup incident shows that visual/audio verification alone isn't enough against AI-generated deepfakes. Consider implementing FIDO2 hardware keys or verbal passphrases for MFA to stay ahead of these threats.

What happened?

An advanced deepfake attack on Arup resulted in $25M being transferred to third-party accounts. Traditional security measures are failing as these attacks grow more sophisticated.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,293 builders reading daily.

Also get