AI generated voices and deepfake video calls are now convincing enough to move real corporate money, and the jump from a $240,000 wire fraud in 2019 to a $25 million video call scam in 2024 shows how fast the exposure has grown, according to The420.in. Cybersecurity experts cited in that reporting, including Prof Dr Dennis-Kenji Kipker of the cyberintelligence.institute in Frankfurt and Prof Triveni Singh, a cybercrime expert and former Indian Police Service officer, say AI has fundamentally altered the terms of financial fraud by letting attackers automate social engineering at a scale no manual fraud operation could match. A separate analysis published the same day by Forbes reached a similar conclusion, describing fraud prevention as a living discipline rather than a puzzle to be solved once and forgotten.
How does AI voice cloning defeat financial controls?
With only a few seconds of recorded audio, generative models can now reproduce a person’s voice closely enough to defeat the phone based verification that banks and finance departments have relied on for decades, The420.in reports. That is what happened in 2019, when fraudsters cloned the voice of a German company’s chief executive and convinced the head of its UK subsidiary to wire roughly $240,000 to a fraudulent account, one of the earliest documented cases of AI voice cloning used against a business rather than an individual. The same playbook is now landing in India, where SEBI has already flagged deepfake CEO impersonation reaching listed companies, warning finance teams not to trust a familiar voice or face on a call without independent confirmation.
What happened in the $25 million Arup deepfake call?
The larger and more widely cited case involves Arup, the UK engineering firm behind projects such as the Sydney Opera House. According to CNN’s reporting on the incident, an employee in the firm’s Hong Kong office authorized 15 wire transfers totaling roughly $25 million after joining a video conference in which every other participant, including the person who appeared to be the chief financial officer, was an AI generated fake built from public video and audio of real executives. No one has been arrested and the funds were not recovered. The420.in cites the case as the clearest evidence that deepfake video, not just cloned audio, has moved from novelty to an operational fraud tool.
How much is AI enabled fraud actually costing companies?
The scale is now large enough that regulators are tracking it as its own category. The FBI’s 2025 Internet Crime Report recorded $893 million in losses tied to AI described scams, the first time the bureau has broken out AI enabled fraud separately in the report’s 25 year history, according to Malwarebytes’ coverage of the report. Investment scams accounted for more than $632 million of that total. None of this suggests AI enabled fraud is only a consumer problem: the same cloned voice and deepfake video techniques hitting individual victims are what emptied Arup’s accounts.
| What happened | AI voice cloning and deepfake video calls are being used to authorize fraudulent wire transfers, with losses escalating from thousands to tens of millions of dollars per incident |
|---|---|
| Who said it | Prof Dr Dennis-Kenji Kipker (cyberintelligence.institute) and Prof Triveni Singh, cybercrime expert and former IPS officer, cited by The420.in |
| Key cases | 2019 voice clone wire fraud ($240,000); 2024 Arup deepfake video call fraud ($25 million) |
| Scale | $893 million in AI described scam losses reported to the FBI in 2025, the first year tracked as a separate category |
| Recommended fix | Independent channel verification, callback confirmation for high value transfers, multi factor authentication, continuous awareness training |
What should CISOs and finance teams do differently?
Kipker and Singh converge on the same point despite coming from different disciplines: the fix is not purely technical. Singh, who investigated cybercrime as a police officer, argues that technology alone cannot eliminate financial fraud because human behavior remains the weakest link, a conclusion that lines up with the broader shift from compliance driven security awareness training toward human risk management that CISOs have been pushing through in 2026. The420.in’s recommended controls are unglamorous but specific: verify any request for a wire transfer or credential reset through a separate, independently confirmed channel, never approve a high value transfer on the strength of a phone call or video alone, enforce multi factor authentication on finance systems, and run continuous training so staff recognize a cloned voice or a synthetic face as a plausible attack rather than a paranoid worry.
For India specifically, the exposure carries a governance dimension. India’s evolving policy environment already puts personal liability on CISOs for control failures, and a wire fraud authorized because a finance officer trusted a deepfaked voice or video call is exactly the kind of incident that regulatory scrutiny is starting to focus on. That fits the broader argument that AI is changing what CISOs need to know: a control built around does the voice or face match no longer holds, and boards should expect security leaders to say so before the next wire transfer goes out, not after.
The pattern across both cases, five years and roughly a hundredfold jump in losses apart, is that attackers upgraded their tools faster than most finance departments upgraded their verification habits. That gap, more than any single piece of malware, is what coverage of enterprise deepfake readiness has been warning about all year, and it is the gap AI voice cloning and deepfake video fraud are now built to exploit.
Frequently asked questions
What is AI voice cloning fraud?
AI voice cloning fraud uses generative audio models to recreate a real person’s voice from just a few seconds of recording, then uses that cloned voice on a phone call to authorize a fraudulent action such as a wire transfer. In 2019, cloned executive audio was used to steal roughly $240,000 from a German company’s UK subsidiary.
How much money has been lost to deepfake and voice cloning fraud?
Reported losses vary widely by incident. A 2019 voice cloning case cost a German company about $240,000, while a 2024 deepfake video call led an employee at engineering firm Arup to authorize roughly $25 million in transfers. In the United States, the FBI’s 2025 Internet Crime Report recorded $893 million in AI described scam losses overall.
How can companies defend against AI generated voice and video fraud?
Security experts recommend never approving a high value transfer based on a phone call or video alone. Instead, confirm the request through a separate, independently verified channel, use callback verification, enforce multi factor authentication on finance systems, and run ongoing awareness training so staff treat a cloned voice or synthetic face as a plausible threat.

Leave a Reply