AI-based attacks on the rise: real cases that changed the threat model
Nathan Chadwick · · 6 min read
TLDRRead the short version
- AI did not invent fraud. It industrialised manufactured trust, so familiar faces and voices are no longer evidence of identity.
- Arup lost about US$25 million after an employee joined a video call where every other participant was a deepfake.
- WPP and Ferrari were targeted the same way and stopped it through verification. Ferrari's exec asked a question only the real CEO could answer.
- The pattern is consistent: public media as source material, urgency plus secrecy, multi-channel stacking, and process saving companies when eyeballs fail.
- Controls that survive a perfect clone: payment dual control, callback to a known number, shared secrets, hiring identity checks, and family code words.
AI did not invent fraud. It industrialised trust attacks#
Cybercrime has always been about tricking people and systems. What changed is the production line.
Attackers no longer need a gifted forger, a perfect accent, or a week to write convincing email. Generative AI lets them clone voices from a few seconds of audio, assemble fake executives for a video call, rewrite phishing in fluent local language, and sit through job interviews behind a synthetic face. The malware still matters. The newer problem is manufactured trust.
Here are real cases that show what that looks like outside the demo reel.
Arup: a deepfake boardroom that moved millions#
In early 2024, a finance employee at engineering firm Arup in Hong Kong joined what looked like a normal video conference with senior colleagues, including people who resembled the company's CFO.
Every other participant on that call was fake.
Hong Kong police and later public reporting described the pattern: an initial message about a confidential transaction, then a multi-person deepfake meeting built from publicly available video and audio. Convinced by familiar faces and voices, the employee made 15 transfers totalling about HK$200 million (around US$25 million) to attacker-controlled accounts. Arup later confirmed it was the victim and said internal systems were not compromised. The attackers did not need a zero-day. They needed a believable meeting.
That is the lesson people still underweight: if your payment controls treat "I saw them on the call" as verification, AI can buy that verification.
WPP and Ferrari: near misses that should count as warnings#
Not every AI attack succeeds. The failures are useful because they show what stopped the loss.
In May 2024, scammers targeted WPP, the global advertising group. Reporting based on CEO Mark Read's internal warning described a fake WhatsApp account using his image, a Microsoft Teams meeting, AI voice cloning, and public footage used to impersonate senior leaders. The aim was to push an agency leader into a confidential "new business" setup that would have exposed money and personal details. Staff vigilance and verification stopped it.
In July 2024, a Ferrari executive received WhatsApp messages that appeared to come from CEO Benedetto Vigna about a confidential acquisition, then a phone call with a convincing clone of Vigna's voice and accent. The executive asked a personal question only the real CEO would know (the title of a book Vigna had recently recommended). The caller failed and hung up.
Two companies. Same playbook: urgency, secrecy, executive impersonation, AI voice or video. Different outcome because someone refused to treat likeness as proof.
Voice clones at home: the family emergency scam#
Corporate cases get headlines. Consumer versions hit kitchens and phones.
Criminals scrape social media audio, school videos, voicemails, or short clips, then call a parent or partner with a cloned voice of a child or relative in distress. The script is classic "virtual kidnapping" or emergency payment fraud, now with a voice that sounds right enough to short-circuit judgement. Law enforcement agencies have warned about this pattern repeatedly as cloning tools became cheap and easy.
If your security advice still starts with "listen carefully to whether it sounds like them," update it. Sounding like them is now a commodity.
North Korean remote IT workers: deepfakes inside the hiring pipeline#
AI attacks are not only payment fraud.
US authorities and security researchers have documented North Korean remote IT worker schemes in which operatives use stolen or synthetic identities to win remote developer and engineering jobs, route company laptops through facilitators, and send earnings back to the regime. Later reporting and industry analysis described the use of AI face-swapping / deepfake interview tech, fabricated resumes, and portfolio material good enough to pass remote hiring screens.
Once inside, the risk is not only sanctions exposure. It is an insider with code access, credentials, and time. This is AI used as an employment mask, not a phishing lure.
AI-written social engineering and criminal LLMs#
Less cinematic, more common: large language models used to industrialise classic attacks.
Threat actors have used criminal-facing LLM tooling and prompt abuse of mainstream models to:
- Write polished business email compromise messages with fewer grammar tells
- Localise phishing for specific countries and industries
- Generate malware variants and obfuscation ideas faster
- Produce fake invoices, contracts, and support scripts at volume
The important shift is quality and scale. A mediocre attacker can now sound like a competent one. A competent attacker can run more simultaneous campaigns without hiring a writing team.
What these cases have in common#
Strip away the novelty and the pattern is consistent:
- Identity theatre beats network hacking in many of the biggest recent losses
- Public media is source material for clones: earnings calls, LinkedIn videos, conference talks, YouTube interviews
- Urgency + secrecy is still the social-engineering payload
- Multi-channel stacking works: email, then WhatsApp, then a call or fake meeting
- Process saves companies when eyeballs fail: out-of-band verification, known-good callback numbers, shared secrets, dual control on payments
Arup shows what happens when the theatre wins. Ferrari and WPP show what happens when verification is non-negotiable even when the voice sounds perfect.
What to do that actually helps#
Skip the vague "be careful with AI" slide. Use controls that survive a perfect clone:
- Payment dual control that cannot be overridden by a video call alone
- Callback to a known number from HR directory or previously verified contacts, never the number that just messaged you
- Challenge questions / shared secrets for high-risk requests, exactly as Ferrari's near miss demonstrated
- No confidential deal talk on new messaging accounts, even if the profile photo looks right
- Hiring identity checks beyond a polished Zoom face: device posture, geolocation anomalies, document verification, in-person or government ID where risk warrants it
- Family code words for emergency payment requests
- Assume voice and face are forgeable in training. Teach staff that realism is not authentication
Bottom line#
AI-based attacks are rising because they attack the one control many organisations still treat as sacred: recognising a person.
The real-world evidence is already dull in the worst way. A Hong Kong finance worker moved tens of millions after a fake meeting. Global firms have been probed with cloned CEOs on WhatsApp and Teams. Families are hit with synthetic voices of people they love. State-linked operators use deepfakes to clear hiring gates. Criminals use generative text to remove the old tells from phishing.
Defenders do not need to win an arms race with every new model. They need to stop equating familiar appearance with verified identity. That habit is what AI is farming now.
References#
Sources and further reading for the claims above.
- CNN Business, Arup revealed as victim of $25 million deepfake scam
- The Guardian, UK engineering firm Arup falls victim to £20m deepfake scam
- The Guardian, CEO of world's biggest ad firm targeted by deepfake scam (WPP)
- Fortune, Ferrari exec foils deepfake plot with a question only the CEO could answer
- MIT Sloan Management Review, How Ferrari hit the brakes on a deepfake CEO
- FBI IC3, Criminals use generative AI to facilitate financial fraud (I-120324-PSA)
- FBI IC3, North Korean IT workers conducting data extortion
- FBI, North Korean IT worker threats to US businesses