Early in 2024, a finance employee at the Hong Kong office of Arup, the British engineering and design firm, joined a video call with the company’s chief financial officer and several colleagues. They discussed a confidential transaction. Over the following days the employee made 15 transfers totalling HK$200 million, about US$25.6 million. None of the people on the call were real. According to CNN’s reporting, every face and voice had been generated with deepfake technology, and the whole thing began with a phishing email that appeared to come from Arup’s UK office.
Arup confirmed in May 2024 that it was the victim. Its global chief information officer, Rob Greig, told CNN that the number and sophistication of attacks against the company had been “rising sharply in recent months.” Arup also said none of its internal systems had been compromised. Nobody hacked anything. They just persuaded a person.
That’s the uncomfortable shift. For years, the advice for suspicious emails was simple: pick up the phone, or ask for a quick video chat. Now the voice on the phone and the face on the screen can be faked too. This piece looks at how these scams work, what Canadian fraud data shows, and, most usefully, how individuals and businesses can verify a request before money moves.
Phishing didn’t go away, it got a voice
Deepfake scams are a new costume on an old crime. The Canadian Anti-Fraud Centre (CAFC) describes spear phishing as fraud that exploits existing relationships: a message that seems to come from your boss, your supplier or your company president asking for an urgent wire transfer or a change to payment details. What’s changed is the toolkit. A voice clone or a live video deepfake removes the last checks people relied on.
The ingredients are easy to find. In a March 2025 CBC story, Peter Warmka, a retired CIA officer and certified fraud examiner, said fraudsters need only three to five seconds of someone’s voice, which can come from a social media post. Executives give conference talks, appear in YouTube videos and record podcasts. Their voices are everywhere.
Recent cases, and the ones that failed
The Arup case is the best known, but it isn’t the only one. Several others are instructive precisely because they didn’t work.
WPP, May 2024
Scammers targeted WPP, the world’s largest advertising group, by setting up a fake WhatsApp account in the name of chief executive Mark Read and arranging a Microsoft Teams meeting. As TechInformed reported, citing The Guardian, they used a voice clone of Read together with YouTube footage of him, and impersonated him in the meeting’s chat. The goal was to get a senior executive to set up a new business and hand over money and personal details. Staff were suspicious, and the attempt failed.
Ferrari, July 2024
A Ferrari executive received WhatsApp messages, then a call, from someone who sounded like chief executive Benedetto Vigna, complete with his southern Italian accent, talking about a confidential acquisition. According to Fortune, summarizing Bloomberg’s report, the executive noticed slight mechanical intonations and asked the caller to name a book Vigna had recently recommended to him. The caller couldn’t, and hung up. One personal question beat a sophisticated attack.
Singapore, March 2025
A finance director at a Singapore company was contacted on WhatsApp by someone posing as the firm’s CFO, then joined a Zoom call in which deepfakes of the CEO and other executives appeared. A fake lawyer handled the paperwork. The director transferred about US$499,000. In this case the story ended well: the Singapore Police Force says it worked with Hong Kong police to recover the full amount within days. Its advice afterward was direct: businesses should set up protocols for staff to verify the authenticity of video calls from executives.
Beyond business
The same techniques reach far beyond corporate finance teams. In May 2025 the FBI warned that criminals were sending AI-generated voice messages impersonating senior U.S. officials to build trust before sending malicious links. And families are targets too, as the Canadian cases below show.

What Canadian fraud data shows
The CAFC’s figures for 2025, released during Fraud Prevention Month in March 2026, put reported fraud losses in Canada at $704 million, and $2.4 billion from 2022 through 2025. The centre estimates that only 5 to 10 per cent of fraud is ever reported, so the true cost is many times higher. The Acting Commissioner of Competition said in the same release that AI has given fraudsters powerful tools for convincing impersonations.
The CAFC doesn’t publish a separate “deepfake” category, which makes sense: a deepfake is a technique, not a type of fraud. But the categories it does track show where these tools fit. According to the centre’s 2025 top-10 summary:
| Fraud type (2025) | Reports | Reported losses |
|---|---|---|
| Investment fraud | 4,409 | $351 million |
| Spear phishing | 813 | $67.9 million |
| Relationship (romance) fraud | 1,093 | $63.3 million |
| Job fraud | 2,148 | $50.6 million |
Spear phishing, the category that covers impersonated executives and suppliers, was the second-largest source of reported losses despite relatively few reports. Each successful attack is expensive.
Deepfakes in Canadian scams
The CAFC issued a bulletin on deepfake fraud in July 2024, warning about fake videos of politicians, celebrities and news anchors promoting investment platforms. The human cost of those scams can be devastating. CP24 reported in June 2026 on an 86-year-old woman in Sault Ste. Marie who lost $900,000, including money from a mortgage on her condo, after seeing a fake video of Prime Minister Mark Carney endorsing a crypto platform.
Voice clones show up in the so-called grandparent or emergency scam. The CBC story mentioned above described an Oshawa, Ont., grandmother who heard what sounded like her grandson saying he’d been arrested and needed $9,000. A CIBC customer service agent flagged the suspicious transaction and the money never left her account. According to CAFC figures cited by CBC, Canadians lost nearly $3 million to this type of scam in 2024. Because so few frauds are reported, the real total is very likely higher.
How to verify a request before money moves
Spotting a deepfake by eye or ear is getting harder, and we’d argue it’s the wrong goal. The CAFC bulletin does list technical tells such as unnatural movements, mismatched audio and inconsistent lighting, and they’re worth knowing. But the more reliable defence is a process that doesn’t depend on judging whether a face looks real.
For businesses
- Call back on a number you already have. Never use the phone number, meeting link or email address supplied in the request. Look it up in your own directory. This is the CAFC’s core advice for spear phishing, and it defeats nearly every variant.
- Require two people for unusual payments. Any new payee, changed bank details or urgent transfer above a set threshold should need approval from a second person through a separate channel.
- Treat secrecy as a red flag. Arup, WPP, Ferrari and the Singapore case all involved a “confidential” deal. Real executives rarely tell staff to bypass normal controls.
- Agree on a verification question or code word. Ferrari’s executive used a personal question. A pre-agreed phrase for authorizing payments does the same job more reliably.
- Slow down deliberately. Urgency is the attacker’s main weapon. Build in a short mandatory pause for out-of-pattern requests.
- Brief the people most likely to be targeted. Finance, payroll and executive assistants should hear about these cases by name.
For families
- Set up a family safe word that a real relative in trouble would know.
- If you get a distressing call, hang up and call the person directly on the number you already have, as the CAFC recommends for emergency scams.
- Remember that, as the CAFC points out, the Canadian justice system doesn’t let anyone be bailed out with cash or cryptocurrency. Being told there’s a “gag order” and you mustn’t tell anyone is a classic warning sign.
- Be skeptical of any video of a public figure promoting an investment. Check whether a platform is registered with your provincial securities regulator before sending money.
If you’ve lost money, contact your bank right away, then report to local police and the CAFC at 1-888-495-8501 or online. For a larger business loss, it’s also worth speaking to a lawyer and your insurer promptly.
Trust the process, not the face
The lesson from the past two years isn’t that we should become paranoid about every video call. It’s that seeing and hearing someone are no longer proof that you’re dealing with them. The cases that ended well, at Ferrari, at WPP, at a bank in Ontario, all turned on someone pausing and checking through a channel the scammer didn’t control.
That’s cheap to build into a business or a family. Write down the rule, agree on a callback habit, and make it normal to say, “I’ll call you right back.” Anyone legitimate will understand. Anyone else will hang up.
Sources and further reading
- CNN: Arup revealed as victim of US$25 million deepfake scam (2024)
- TechInformed: WPP CEO targeted by deepfake scam
- Fortune: Ferrari foils deepfake attempt with a security question
- Singapore Police Force: Business impersonation scam funds recovered (2025)
- Malwarebytes: FBI warns of AI voice impersonation of officials
- Canadian Anti-Fraud Centre: Fraud Prevention Month 2026
- CAFC: Top 10 frauds of 2025 (PDF)
- CAFC: Bulletin on fraud using deepfakes
- CAFC: Spear phishing
- CAFC: Emergency scams
- CBC: Senior almost scammed with suspected AI voice cloning (2025)
- CP24: Ontario senior loses $900,000 in deepfake crypto scam (2026)
Leave a comment