Deepfake CEO Fraud in 2026: What Actually Stops the Call
Real-time voice and video deepfakes are cheap, fast and convincing enough that finance teams are being socially engineered on live video calls. Here is the 2026 playbook — the attack pattern, the controls that survived contact with attackers, and the ones that did not.

The 2024 Arup case — a finance employee wiring USD 25 million after a video call with a deepfaked CFO and colleagues — is no longer an outlier. In 2026 we are tracking a similar pattern in the mid-market every few weeks, and the attackers have gotten cheaper, faster, and much less awkward on camera.
This is the working playbook we hand to finance and treasury teams before the next call.

The 2026 attack pattern, step by step
1. Reconnaissance. LinkedIn, earnings-call recordings, conference videos and podcast appearances provide the target's face and voice at broadcast quality. Ten minutes of audio is enough for a production-grade voice clone. 2. Pretext. An email from a spoofed or compromised address invites the finance contact to an urgent, confidential video call — usually framed as an unannounced acquisition, a regulatory issue, or a discreet payment to a lawyer or advisor. 3. The call. A real-time avatar of the CEO or CFO joins on Zoom / Teams / Meet. In the more sophisticated variants, two or three colleagues also join — all deepfaked, all in character, all discouraging the target from calling anyone back to verify. 4. The instruction. A specific bank account, a specific amount, a specific deadline before market open. The urgency is the control the attacker has over the victim's judgement. 5. The cleanup. The account is drained within hours through a chain of mule accounts, often crossing three jurisdictions before the first fraud report is filed.
Controls that survived contact with attackers
1. A named out-of-band callback, always
Every payment above a threshold — we recommend anything unusual, not just anything large — requires a callback to a number that is *not* the number on the invoice, the email, or in the call. The number is pulled from an internal directory the attacker cannot influence. Zero exceptions, including "the CEO said not to call anyone".
2. A per-employee code phrase
Executives and their finance counterparts agree a short code phrase, rotated quarterly, stored in a password manager, and asked on any unexpected call about money. Deepfakes handle voice and face; they do not handle a shared secret the attacker never saw.
3. Multi-person authorisation, on the payment rail
Move the second-person check into the banking workflow, not the email thread. If a single employee can release the wire, the attacker only has to convince one person.
4. A "no urgent M&A calls" policy, published
The single most effective control we have seen: a written, executive-signed policy that says the company never announces confidential deals over an unscheduled video call and never asks finance to act before the next business day. When the attacker pitches the urgency, the employee has a policy to point at.
Controls that did not work
- Deepfake-detection browser extensions. Detection lags generation by six to nine months. Do not build the control around a model that has to keep up with the attacker's model.
- "Just look for artefacts." 2026-era real-time avatars do not have obvious artefacts under normal lighting. Training employees to trust their eyes on video is worse than useless — it produces false confidence.
- Voice-biometric IVR. Voice cloning defeats voice biometrics. Treat voice as an identifier, never as an authenticator.
What to do in the next 30 days
- Publish a one-page payment-authorisation policy signed by the CEO and CFO. Include the callback rule and the "no urgent M&A calls" clause verbatim.
- Rotate a code phrase between every executive and their finance counterpart. Store it in the corporate password manager, not in email.
- Run one tabletop with the finance team using a scripted deepfake call. The learning outcome is not detection — it is the reflex to hang up and call back.
- Add a payment-anomaly detector on the outbound wire rail. New beneficiary + new jurisdiction + above-threshold + outside business hours is a very small set of transactions and a very effective filter.
The organisations that lose the money in 2026 are not the ones with the worst technology. They are the ones without a written rule that lets an employee say "no" to a convincing face on a familiar tool.

