agentry@news ~/agent/arup-deepfake-fraud-hk200m-stolen-via-ai-video-call $ cat arup-deepfake-fraud-hk200m-stolen-via-ai-video-call.md
title: "Arup deepfake fraud: HK$200M stolen via AI video call"
slug: "arup-deepfake-fraud-hk200m-stolen-via-ai-video-call"
published: "2026-08-04"
beat: "Crime"
tags: ["Crime"]
creator: "Agentry Newsroom"
editor: "Susanne Sperling, Editor — Human in the Loop"
tools: ["Claude (Anthropic)", "Perplexity Sonar"]
creativeWorkStatus: "verified"
dateReviewed: "2026-08-04"
aiActArticle50: "compliant"
humanView: "https://agentry.news/crime/arup-deepfake-fraud-hk200m-stolen-via-ai-video-call"
agentView: "https://agentry.news/agent/arup-deepfake-fraud-hk200m-stolen-via-ai-video-call"

Arup deepfake fraud: HK$200M stolen via AI video call

A Hong Kong engineering consultancy lost approximately US$25.6 million in early 2024 after an employee was tricked into authorizing transfers during a video call with AI-generated deepfakes impersonat

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

The Attack

Arup, the multinational engineering consultancy, fell victim to a deepfake-enabled fraud scheme in early 2024 that resulted in the theft of HK$200 million (approximately US$25.6 million) across 15 separate transfers, according to incident reports and security analysis Security Boulevard.

The attack unfolded when a finance employee at Arup's Hong Kong office joined what appeared to be a legitimate video conference call. On the call were what the employee believed to be the company's CFO Mark Read and other senior colleagues, all issuing instructions to move funds Hard2bit. The video participants were entirely AI-generated deepfakes, synthetic video and audio recreations designed to impersonate real executives.

The employee, convinced the call was genuine, authorized the transfers. By the time the fraud was discovered, the money had been moved in 15 separate transactions.

Current Status and Recovery

The funds were reportedly not recovered following the incident Finance Feeds. Hong Kong police investigated the attack, but no arrests have been publicly reported in available documentation.

No court filings, regulatory penalties, or sentencing has been disclosed in relation to the case to date.

Broader Context

The Arup incident exemplifies a growing category of agent-enabled fraud: attacks where synthetic media—audio, video, or both—acts as the malicious agent, impersonating authorized parties to extract value. Unlike traditional business email compromise (BEC) schemes that rely on text, deepfake-based attacks add video and voice authenticity, reducing skepticism during real-time interactions Adaptive Security.

The technical barrier to generating convincing deepfakes has fallen sharply. Voice cloning and facial reenactment tools now require minimal training data—sometimes just seconds of audio or video—making executive impersonation feasible at scale. The synchronization of synthetic video with cloned audio during a live call creates an unprecedented social engineering vector.

While the Arup case occurred in 2024, it remains one of the highest-value verified deepfake fraud incidents on record and has become a reference point in enterprise security discussions about AI-driven identity fraud.

agentry@news $