A finance clerk receives a video call from the company CEO. The face on screen is familiar. The voice is calm and urgent. The CEO says an acquisition payment must go out today. The clerk is told to keep the matter quiet. Within an hour, $243,000 is wired to a bank account that turns out to belong to criminals. The real CEO learns about the transfer the next morning. This was not a technical glitch. It was deepfake CEO fraud.

Deepfake CEO fraud pushes business email compromise into a more dangerous era. Criminals use artificial intelligence to clone an executive’s face and voice. They join video calls, leave voicemails, or send short recorded clips. The goal is to convince a person with payment authority to send money. Because the executive appears to speak and move, the fraud bypasses written warning signs that employees have been trained to spot. The same technology also appears in other scams, including AI job scam guide schemes that use fake recruiter videos.

The FBI IC3 tracks business email compromise as one of the costliest cybercrimes in the United States. In 2023, victims reported more than $2.9 billion in adjusted losses tied to BEC. Deepfake video is a small but rapidly growing share of that total. A single case can wipe out a mid-size company’s cash reserves. The good news is that simple verification rules can stop most of these attacks before a wire leaves the building.

FeatureTraditional CEO Email FraudDeepfake CEO Fraud
Contact methodSpoofed email or hacked accountLive video call or recorded video message with cloned face and voice
Trust factorRelies on tone, logos, and email addressExploits the brain’s trust in seeing a known face
Primary red flagOdd language or strange domainLip sync glitches, blurry edges, audio lag, request for secrecy
Typical targetFinance and HR employees with payment accessSame team, with attackers often researching the person first
Loss per eventOften high, but many cases are caughtCan be very high; Arup reported about $25.6 million lost in one attack

What Is Deepfake CEO Fraud?

A finance employee stares at a laptop screen showing a live video call with a senior executive.
Photo by Pexels

Deepfake CEO fraud is a type of business email compromise in which criminals use AI-generated video or audio to impersonate an executive. The attacker typically does not rely only on a fake email or a stolen account. Instead, the criminal creates a synthetic version of a real leader. That fake leader then asks an employee to authorize a wire transfer, share sensitive data, or change payment details.

The raw material for these fakes is often public. A criminal can download an earnings call, a conference keynote, or a short clip from a company social media account. AI tools then map the executive’s face onto a live actor or generate speech that sounds like the target. Some pipelines work in real time. An attacker can sit on a video call while software swaps their face for the CEO’s face and alters their voice to match.

This matters because voice and face are strong trust signals. In a traditional email scam, an employee might notice a strange domain name or odd phrasing. On a video call, the brain accepts what it sees. Criminals exploit that reflex. They add pressure, secrecy, and a tight deadline. The result is a social engineering attack dressed up as a normal executive request.

  • Live video calls where an actor’s face is replaced in real time
  • Short recorded video messages sent through messaging apps
  • Cloned voicemails paired with follow-up text messages

How Does This Scam Work?

A fraud investigator reviews deepfake video frames on a monitor showing two faces that look similar.
Photo by Pexels

Most deepfake CEO fraud follows a repeatable playbook. First, criminals research the target company. They study the executive’s speaking style, reporting lines, travel schedule, and payment workflows. Public videos give them the raw footage they need. In some cases, stolen email or calendar data tells them when the real CEO is unreachable.

Second, the attacker selects a payment person. That might be a finance director, an accounts payable clerk, or an executive assistant. The attacker often impersonates an outside lawyer or a partner firm first. A fake email says a sensitive deal requires immediate payment. Then comes the video call. The caller looks and sounds like the CEO. The screen may be grainy. The audio may skip. The criminal blames a bad connection. The employee is told not to discuss the request with anyone.

Third, the attacker pushes the wire. The account is usually new, offshore, or tied to a mule. Once funds leave, criminals move them quickly. Some transfers are converted into cryptocurrency or split across several banks. This is the same kind of rapid laundering seen in crypto AI investment scam guide frauds. Recovery becomes harder with every hour.

A successful attack does not require perfect video. It requires a busy employee, a plausible story, and a culture that discourages challenging executives. Attackers know that junior staff often fear looking slow or insubordinate.

Who Does It Target?

The primary target is not the CEO whose face is stolen. It is the employee with payment access. Finance staff, treasury teams, payroll processors, and accounts payable specialists are the front line. Attacker reconnaissance focuses on people who can move money without needing multiple approvals.

Mid-size companies are attractive because they often have fewer layers of payment controls than large banks or multinationals. Small firms with a flat structure may have only one person who handles wires. Nonprofits, school districts, law firms, and construction companies are frequent victims because their payment patterns can be predictable.

The Arup case in Hong Kong showed how far this can go. A finance employee received messages and joined a video call with what appeared to be the chief financial officer and other colleagues. The fake participants instructed several transfers. The company reported losing about $25.6 million. The employee later said the people on the call looked and sounded real. That is the core danger.

Attackers also target new hires. A new finance team member may not know the CEO’s typical tone or approval process. They may be more afraid to question a direct order from a senior leader. Criminals strike when the real executive is traveling, in meetings, or asleep in another time zone. This gap gives the fraudster room to operate. Similar voice cloning tactics appear in AI grandparent scam guide cases, suggesting the underlying tools are cheap and widely available.

How Much Money Is Being Lost?

The FBI’s Internet Crime Complaint Center consistently ranks business email compromise among the most financially damaging crimes. In 2023, FBI IC3 data recorded about 21,489 BEC complaints in the United States with adjusted losses near $2.9 billion. Those numbers include invoice fraud, payroll diversion, and executive impersonation. Deepfake video is a subset of that total, but its share is growing as AI tools become easier to use.

Single cases now rival the losses from a data breach or ransomware event. The Arup deepfake case resulted in a reported loss of about $25.6 million. Other companies have reported losing six and seven figure amounts after a short video call. One fake call can wipe out an entire operating budget.

There is also a secondary cost. A company that falls for this scam loses more than money. It may lose employee trust, face regulatory scrutiny, or face questions from insurers and investors. In some cases, the employee who authorized the transfer is blamed even though the criminal orchestrated a sophisticated deception.

The table below compares traditional email based CEO fraud with deepfake CEO fraud.

What Are the Warning Signs?

A woman in a corporate office holds her phone and compares a payment request on a computer screen.
Photo by Pexels

Deepfake video can look convincing, especially on a phone screen. But real attacks often show small signs. Employees should treat these signals as reasons to pause, not as proof that nothing is wrong.

One warning sign is a sudden request for secrecy. A real executive can explain why a deal is confidential. A fraudster uses secrecy to isolate the target. Another sign is a last minute change to bank details. Attackers often start with one set of instructions and then send a corrected account number. The correction is where the fraud happens.

Video quality matters. A deepfake call may have blurred facial edges, odd lighting, unnatural blinking, or lip movements that do not perfectly match the words. The caller may keep the camera slightly off center or claim the connection is unstable. They may refuse to answer a personal question. If you ask what was discussed at last week’s leadership meeting, the caller may deflect. The fake CEO may also avoid turning their head or standing up, because some face swap tools fail under sharp movement.

Other warning signs include a demand to bypass normal approvals, a payment deadline of less than an hour, and an instruction to use a personal email or encrypted chat. If the caller becomes angry when you ask to verify, that is a red flag. Fraudsters use anger to push people past hesitation. Some attacks also use fake verification tools or bogus security steps as seen in fake AI tools scam guide cases.

  • Urgent wire request marked confidential or legal
  • Last minute change to bank details
  • Video call with blurry edges, lip sync lag, or audio skips
  • Instruction not to contact the real executive
  • Anger or pressure when you ask questions

How Can Organizations Defend Against Financial Loss?

Defense starts with one simple rule: no payment based on a single communication, even a video call. Every wire above a set threshold should require a second verification through a pre-approved channel. That channel should not be the same call, the same email thread, or a phone number provided by the caller.

Create a callback rule. The finance employee must call the executive or colleague on a known internal number before sending money. If the call came from an unknown device, the callback goes to the contact saved in the company directory. This breaks the impersonation loop. Some companies add a verbal code word for high risk transactions. The code word must not be stored in email or public files.

Require two person approval for wires over a certain amount. A second reviewer can spot pressure tactics that the first person missed. Separate duties so the person who enters the payment is not the same person who approves it. For accounts payable, build in a delay for any new or changed bank account. A 24 hour hold on first time payees gives fraud teams time to confirm.

Train finance staff to recognize deepfake red flags and run live simulations. A mock deepfake video call can teach employees how to pause. Training should emphasize that questioning a suspicious payment will not be punished. Company leaders must repeat that message. If the culture punishes questions, the fraudster wins.

Limit high quality video of executives where possible. That is hard for public companies, but leaders can avoid posting long, clear, front-facing clips with steady audio. Use privacy settings on personal accounts. For technical defenses, CISA publishes guidance on deepfake threats and risk mitigation. Some vendors sell detection tools that analyze video for synthetic artifacts. These tools are not perfect, but they can add a useful layer.

Finally, report incidents quickly. Contact the bank and request a freeze or recall. File a report with the FBI IC3 and the FTC. The earlier a report goes in, the better the chance of recovering funds. Deepfake CEO fraud is a crime, but many employees still hesitate to report because they feel embarrassed. Make clear that the victim is the company, not the worker who was deceived. Similar advice helps in other synthetic media scams, such as AI romance chatbot scam guide cases where shame delays action.

Frequently Asked Questions

What is deepfake CEO fraud?

Deepfake CEO fraud is a scam where criminals use AI-generated video or audio to impersonate a company executive. They contact an employee with payment access and request a wire transfer. The fake executive looks and sounds real, which makes the request hard to refuse.

How can I verify a video call from my CEO?

Hang up and call the executive on a known internal number. Ask a question that only the real person would know. Use a pre-agreed code word for high risk transactions. Never rely on the call back number the caller provides.

Are small businesses at risk?

Yes. Small and mid-size businesses are common targets because they often have fewer payment controls. A single fake video call can cause a loss that threatens the entire company.

What should a finance employee do if they receive an urgent wire request by video?

Pause. Do not send money immediately. Verify the request through a second channel. Contact a supervisor or the security team. Call the executive on a known number before approving any transfer.

Can AI detection software catch deepfake calls?

Some tools can flag synthetic video artifacts, but they are not perfect. Detection should support human verification, not replace it. A callback rule and two person approval are stronger controls.

Where should companies report deepfake CEO fraud?

Companies should contact their bank immediately to freeze or recall the payment. They should also file a report with the FBI Internet Crime Complaint Center at ic3.gov and the Federal Trade Commission at reportfraud.ftc.gov.

What Should You Remember?

  • Deepfake CEO fraud uses AI-generated video to mimic executives and authorize fake wire transfers.
  • Finance employees are the main targets, not necessarily the executives themselves.
  • Urgent, secretive payment requests are red flags, even when they come over video.
  • A single attack can cost millions. Arup reported losing about $25.6 million in one deepfake case.
  • Verify every unusual wire through a second channel and a known phone number before sending.
  • Two person approval and first time payee holds block many fraudulent transfers.
  • Report losses quickly to your bank, the FBI IC3, and the FTC.

This article is for general information only and does not constitute legal or financial advice. Scam tactics evolve quickly , always verify current threats through official sources such as the FTC, FBI IC3, BBB, or CISA before acting. If you believe you’ve been defrauded, report it promptly and contact your financial institution.