6 Real-World CEO Fraud and Deepfake Attacks: Successful vs. Thwarted

Explore six real-world deepfake attack examples involving Arup, Ferrari, WPP, LastPass, Wiz, and an energy firm—separated by successful and thwarted outcomes.

Arup, Ferrari, WPP, LastPass, Wiz, and an unnamed energy company are often placed in the same lists of deepfake attack examples. Their outcomes were very different. Two organizations made confirmed transfers. Four stopped the reported attempt before the attacker achieved its objective.

The cases show where executive impersonation becomes financial or security impact. A familiar face, voice, profile photo, or meeting presence can make a request credible. The request should still pass an authorization process that the apparent executive cannot bypass.

Key Takeaways

  • Arup and the unnamed energy company suffered confirmed financial losses. Ferrari, WPP, LastPass, and Wiz thwarted the reported attempts.
  • Attackers combined synthetic media with established business email compromise tactics: authority, secrecy, urgency, and unusual transactions.
  • The thwarted attacks stopped at different points, including a private challenge, staff escalation, channel anomalies, and a mismatch between public and everyday speech.
  • Audio or visual flaws can trigger scrutiny, but they are unreliable as identity checks.
  • Independently initiated verification, dual approval, payee controls, and transaction limits remain effective even when a caller looks and sounds genuine.

Six CEO Fraud and Deepfake Attacks at a Glance

The table uses successful when the reported attacker objective produced a confirmed transfer or compromise. Thwarted means the public account says the intended payment, data disclosure, or credential theft did not occur.

TargetYearImpersonation methodReported objectiveOutcomeDecisive failure or control
Arup2024Email followed by a multi-person video call using fake voices and imagesAuthorize confidential transfersSuccessful: HK$200 million transferredApparent social corroboration from senior colleagues displaced the employee’s initial suspicion
Unnamed UK energy company2019AI-assisted voice clone of the German parent-company CEOSend an urgent supplier paymentSuccessful: €220,000 transferred; a later request was refusedFamiliar voice and authority secured the first payment before anomalies appeared
Ferrari2024WhatsApp messages and a cloned CEO voiceSupport a confidential deal and currency transactionThwartedThe recipient asked about recent shared knowledge that the caller could not provide
WPP2024Fake WhatsApp profile, Teams, voice clone, public footage, and chatCreate a new business and solicit money and personal detailsThwartedThe targeted leader and other staff did not accept the staged meeting as sufficient proof
LastPass2024WhatsApp calls, texts, and a cloned-voice messageUndisclosed social-engineering objectiveThwarted: LastPass reported no impactThe employee recognized an abnormal channel and forced urgency, then reported it
Wiz2024Cloned-voice messages sent to dozens of employeesObtain credentialsThwarted: no credential loss was reportedEmployees noticed that the conference-derived voice did not match the CEO’s everyday speech

Successful Deepfake Fraud Attacks

Both successful cases turned executive familiarity into permission to move money. The methods differed, but each request crossed the point where a persuasive communication was treated as sufficient authorization.

Arup: A Multi-Person Video Call Led to HK$200 Million in Transfers

The Arup case began with doubt. A finance employee in Hong Kong received a message about a secret transaction and reportedly suspected phishing. A video conference then appeared to resolve that concern. The participants looked and sounded like senior colleagues, including the company’s chief financial officer.

According to reporting confirmed by Arup, the employee made 15 transfers to five local bank accounts. The total was HK$200 million, roughly £20 million or US$25 million at the time. Arup confirmed that fake voices and images were used.

The incident is sometimes described as a “deepfake CEO call,” but the public record does not establish that Arup’s global CEO was one of the impersonated people. The confirmed account refers to the CFO and other senior officers or colleagues. Precision matters because the attack’s strength came from apparent agreement among several trusted people, not from a single CEO likeness.

Arup also said its internal systems were not compromised. In a later World Economic Forum interview, CIO Rob Greig described the event as technology-enhanced social engineering. People were deceived into making transactions even though the attackers had not breached the company’s network.

The video meeting supplied synthetic social corroboration. Once several apparent colleagues confirmed the same story, the employee’s original phishing suspicion lost weight. A safer workflow would treat the meeting as part of the request and require a separate authorization path, such as a callback to a known number plus dual payment approval.

The Unnamed Energy Company: One Voice Clone Secured a €220,000 Transfer

One of the earliest widely reported cases of AI voice fraud occurred in 2019. The managing director of a UK energy company received a call that sounded like the CEO of its German parent company. The caller reproduced the executive’s accent and speech rhythm and ordered an urgent €220,000 transfer to a supposed Hungarian supplier.

Forbes reported, citing The Wall Street Journal and the company’s insurer Euler Hermes, that the transfer was completed. The caller later claimed it had been reimbursed and asked for another payment. The victim then noticed that no reimbursement had arrived and that a later call came from an Austrian number. He rejected the additional request, but the first payment had already moved through other accounts.

The victim stopped a follow-up request, but the initial transfer made the attack successful overall.

The insurer reportedly believed commercially available AI voice software was involved. The specific software, training material, and perpetrators were not identified publicly. The defensible lesson is narrower: voice recognition supported trust, while the request lacked a separate control strong enough to block the initial transfer.

Thwarted CEO Deepfake Attacks

The next four attacks did not achieve their reported objectives. Each was interrupted at a different point, and each stopping point has limits that security teams should understand.

Ferrari: A Private Question Broke the CEO Impersonation

In July 2024, a Ferrari executive received WhatsApp messages from someone claiming to be CEO Benedetto Vigna. The messages came from an unfamiliar number and referred to a confidential acquisition, an NDA, and a deal requiring discretion. A call followed, using a voice that reportedly reproduced Vigna’s southern Italian accent convincingly.

The recipient did more than listen for an artificial cadence. He asked the caller to name a book the real Vigna had recently recommended to him. The caller could not answer and ended the conversation. Reporting based on people familiar with the episode says Ferrari opened an internal investigation; the company declined to comment on the account.

The private question moved identity verification away from the voice and tested recent context that the attacker apparently did not possess.

Security teams should still treat personal questions as an emergency check rather than a payment control. Answers can leak through email, messaging, meetings, or public posts. A verified callback and multi-person approval process provide stronger protection for a financial action.

WPP: A Mixed-Media Teams Meeting Failed to Win Trust

The attempt against WPP illustrates how several weak credibility signals can be assembled into a convincing business interaction. Attackers created a WhatsApp account using a public photo of CEO Mark Read and arranged a Microsoft Teams meeting that appeared to involve Read and another senior executive.

During the meeting, the attackers reportedly used a cloned voice, YouTube footage, and the chat window to impersonate Read. The targeted agency leader was asked to establish a new business through which the attackers could solicit money and personal information.

The WPP attempt was a mixed-media operation rather than one continuous live video deepfake. Public imagery, recorded footage, chat, cloned audio, and a familiar collaboration platform all supported the same pretext. Moving from WhatsApp to Teams did not provide independent confirmation because the attacker controlled the transition.

WPP confirmed that the attempt failed. Read warned colleagues about requests involving passports, payments, and secret transactions, and the company credited the vigilance of its people, including the targeted executive.

The practical lesson is to trace each channel to its origin. A meeting invite sent by a new WhatsApp account is still an unverified approach, even when the next screen displays familiar faces and a corporate platform.

LastPass: An Unusual Channel and Forced Urgency Triggered Reporting

In April 2024, a LastPass employee received calls, texts, and at least one voicemail on WhatsApp from someone impersonating CEO Karim Toubba. The voicemail used a deepfake of Toubba’s voice.

The employee recognized that WhatsApp was outside the company’s normal business communication channels. Forced urgency added another social-engineering signal. Rather than engaging, the employee ignored the messages and reported them to the internal security team.

In its public disclosure, LastPass said the attempt failed and had no impact. The company believed the model was likely trained on publicly available recordings, although the attackers’ exact production process was not established.

Known-channel expectations reduced uncertainty quickly. They gave the employee a concrete reason to stop and a defined place to report the contact. Approved channels cannot prove identity by themselves. Accounts can be compromised and phone numbers can be spoofed. Attackers may also learn internal habits. Channel anomalies should trigger escalation; sensitive requests still need independent verification.

Wiz: Conference Audio Exposed the Voice Clone

Wiz CEO Assaf Rappaport described a credential-theft attempt that reached dozens of employees in October 2024. The employees received voice messages that appeared to come from him and asked for credentials.

The attackers had apparently built the clone from audio of Rappaport speaking at a conference. According to Rappaport’s account reported by TechCrunch, his public-speaking voice differs from the way he speaks with employees in daily work. Recipients noticed that the message did not sound like the Assaf they knew. No credential loss was reported.

Context betrayed the source material. A sample can capture a person’s vocal characteristics without capturing how that person normally addresses a particular audience.

The mismatch can expose an attack, but it is a fragile defense. Attackers can collect informal recordings, use more samples, or improve the model. Organizations should not make employees responsible for judging whether a voice sounds sufficiently authentic. A CEO should never request credentials, and any credential-related instruction should follow a documented, verifiable process.

What Changed the Outcome: A Control Hierarchy for Executive Impersonation

The most durable controls focus on the requested action, regardless of how convincing the person appears.

  1. Turn anomalies into mandatory pauses. A new phone number, unexpected messaging app, secret acquisition, unusual payment, credential request, or pressure to bypass colleagues should halt the workflow. Employees need a defined escalation route and explicit permission to delay an executive request.

  2. Verify through a path the requester did not provide. Call a known number from the corporate directory, start a fresh message in an established account, or contact an authorized colleague independently. Do not use the callback number, meeting link, or contact details supplied in the suspicious exchange.

  3. Verify the action as well as the person. A real executive account can be compromised, and an attacker may know enough private context to answer a challenge. Confirm the payment destination, payee change, credential request, data disclosure, and business purpose against existing records and policy.

  4. Require controls that one executive cannot waive. Dual authorization, separation of duties, transaction limits, cooling periods for new payees, and bank confirmation for unusual transfers reduce dependence on one employee’s perception. These layered BEC controls also protect against ordinary account takeover and email impersonation.

  5. Practice the decision under realistic pressure. Exercises should cover phone calls, voice messages, video meetings, email handoffs, and hybrid sequences. Finance, executive support, IT help desk, HR, and administrators with access to sensitive systems need scenarios tied to the actions they can authorize.

  6. Prepare for rapid containment and recovery. If money moves, contact the bank and law enforcement immediately. Preserve messages, audio, headers, phone numbers, meeting details, beneficiary information, and timestamps. A suspected impersonation should also trigger a check for compromised accounts or internal data exposure, even when the visible attack appears to be pure fraud.

Deepfake detectors can add a warning signal, but they should not become the approval mechanism. Compression, background noise, unfamiliar generation methods, and ordinary false positives can affect results. More importantly, a detector cannot determine whether a legitimate executive’s request complies with payment policy. Deepfake detection limits reinforce the case for action-based verification.

Rehearse the Moment an Executive Impersonation Becomes Convincing

Policies are easiest to follow when employees have practiced the exact moment authority and urgency begin to override doubt. Brightside provides a controlled way to rehearse that decision across the channels used in these cases.

For audio scenarios, administrators can upload a 1–2 minute recording and create a custom executive voice for self-service voice phishing simulations. The simulated calls can run as voice-only attacks or as hybrid sequences that combine a live call with a trackable phishing email. Teams can test whether employees pause, verify, refuse the requested action, and report the approach when the caller sounds familiar.

Video deepfake exercises use a different delivery model. They are managed engagements produced and run by the Brightside team, with the scenario and target audience scoped for each customer. They are not launched through the self-service voice workflow.

Brightside supplies the rehearsal layer, while the organization’s identity, finance, and escalation controls handle caller verification and payment authorization. The platform does not offer live deepfake detection. Realistic practice paired with enforced workflows makes the correct response easier to execute under pressure.

CEO Fraud and Deepfake Attack FAQs

Which of these CEO deepfake attacks were successful?

Arup and the unnamed UK energy company suffered confirmed transfers. Arup lost HK$200 million through 15 transactions after a synthetic video conference. The energy company transferred €220,000 after a cloned-voice call. Ferrari, WPP, LastPass, and Wiz reported thwarted attempts with no confirmed achievement of the attackers’ stated objectives.

Was the Arup attack a cyberattack or financial fraud?

It was deepfake-enabled social engineering that produced financial fraud. Arup said its internal systems were not compromised and no company data was affected. The attackers used fake voices and images to persuade an employee to authorize transfers. Security teams still need to investigate for account or data compromise because similar impersonation attacks can use stolen internal information.

How can an employee verify a CEO’s identity during a suspicious call?

End or pause the exchange and initiate contact through a trusted route, such as a number already stored in the corporate directory. A private question can help, as the Ferrari case showed, but it should not authorize a sensitive action. Confirm the request, destination, and business purpose through the organization’s established approval process.

Can deepfake-detection software prevent CEO fraud?

Detection can flag suspicious audio or video, but it cannot reliably prevent CEO fraud by itself. Performance may vary with call quality and generation methods, and a genuine executive can still make an unsafe or policy-breaking request. Treat detector output as one signal while enforcing independent verification, dual approval, transaction controls, and reporting procedures.

What controls best protect high-value payments from executive impersonation?

Use dual approval, separation of duties, independently verified payee changes, transaction limits, and confirmation through a known contact route. Employees should be allowed to stop a payment when urgency, secrecy, or an unusual channel appears. Banks and internal incident responders should have a documented rapid-response path if a transfer is made.

Executive Presence Cannot Replace Authorization

The decisive point in each case was whether the request crossed an authorization boundary or was interrupted.

Security and finance teams should review which actions can be approved on the strength of a call, message, or meeting. A recognizable executive can make an approach plausible. Only a trusted process should make it actionable.