ADVISORY

Deepfake CFO Fraud Is Now a Board-Level Risk: A Detection and Payment-Control Playbook

THREAT INTEL · 7 MIN READ · ZENC LABS RESEARCH · 2026

In early 2024, a finance employee at engineering firm Arup joined a video call with what appeared to be the CFO and several colleagues, and authorized transfers totaling roughly US$25 million. Every other participant on that call was a deepfake. The attack required no malware and no network intrusion. It attacked the one system with no patch cycle: human trust in a familiar face and voice.

▲ SECONDS OF AUDIO NOW SUFFICE FOR A USABLE VOICE CLONE · VIDEO-CALL DEEPFAKES CONFIRMED IN LIVE FRAUD · PRIMARY TARGET: PAYMENT AUTHORITY

Anatomy of the attack

The pattern is consistent: reconnaissance on LinkedIn and earnings calls harvests voice and video of executives; a pretext creates urgency and secrecy ("confidential acquisition, board-level only"); the deepfake call delivers the instruction; and pressure prevents the victim from verifying through normal channels. The technology is new, the psychology is classic business email compromise.

Controls that actually stop it

Board question worth asking this quarter: "If our CFO's voice requested an urgent transfer today, what, other than an employee's suspicion, would stop it?" If the answer is "nothing," the control gap is structural.

Where ZenC Labs fits

Our deepfake-resilience engagements combine a controlled impersonation drill against your real payment workflow, control redesign with your finance leadership, and detection integrated into the SOC, so a suspicious call becomes a logged, investigated incident rather than a private doubt.

SOURCES: Hong Kong Police / public reporting on the 2024 Arup incident · FBI IC3 advisories on BEC and synthetic media · ZenC Labs threat intelligence

Could your finance team catch a cloned voice?

We run deepfake-resilience drills against your actual payment workflow and close the gaps we find.

Book a resilience drill