Executive Summary
In January 2024, a finance employee at Arup's Hong Kong office received an email, purportedly from the company's UK-based CFO, requesting a confidential transaction. To verify, the employee joined a video conference with individuals appearing as the CFO and other senior colleagues. Convinced by the authenticity of the participants, the employee executed 15 wire transfers totaling approximately $25.6 million to designated bank accounts. Subsequent investigations revealed that the video call participants were AI-generated deepfakes, and the entire scenario was orchestrated by cybercriminals. This incident underscores the evolving sophistication of cyber threats, where attackers leverage advanced AI technologies to create highly convincing social engineering schemes. Organizations must recognize that traditional verification methods, such as visual and auditory confirmation, can be compromised. Implementing multi-factor authentication, establishing robust verification protocols, and educating employees about emerging threats are crucial steps in mitigating such risks.
Why This Matters Now
The Arup deepfake scam highlights the urgent need for organizations to adapt their security measures to counter AI-driven social engineering attacks. As cybercriminals increasingly employ sophisticated technologies like deepfakes, traditional verification methods become insufficient, necessitating enhanced protocols and employee training to safeguard against such evolving threats.
Attack Path Analysis
The attacker utilized agentic AI to conduct reconnaissance, crafting personalized phishing emails and deepfake video calls to impersonate trusted executives. Upon deceiving the target, the attacker gained initial access, potentially escalating privileges by exploiting trust within the organization. The attacker then moved laterally within the network, establishing command and control channels to exfiltrate sensitive data, leading to significant financial loss.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker employed agentic AI to perform reconnaissance, gathering publicly available information to craft highly personalized phishing emails and deepfake video calls, impersonating trusted executives to deceive the target.
MITRE ATT&CK® Techniques
Social Engineering
Impersonation
Spearphishing Voice
Obtain Capabilities: Artificial Intelligence
Multi-Factor Authentication Interception
Multi-Factor Authentication Request Generation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 12.6.2
NYDFS 23 NYCRR 500 – Cybersecurity Awareness Training
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – Multi-Factor Authentication
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
AI-enhanced phishing targeting wire transfers and executive impersonation poses extreme risk to financial institutions with high-value transaction workflows and regulatory compliance requirements.
Banking/Mortgage
Deepfake video calls and multi-channel social engineering attacks threaten banking operations through compromised trust verification systems and fraudulent transaction approvals.
Health Care / Life Sciences
HIPAA-regulated healthcare organizations face heightened risk from agentic AI reconnaissance targeting patient data through sophisticated email impersonation and zero trust security gaps.
Information Technology/IT
IT sector organizations are prime targets for AI-powered reconnaissance attacks exploiting cloud infrastructure, Kubernetes environments, and multi-cloud visibility weaknesses for data exfiltration.
Sources
- Phishing 3.0: The Fight Moves to Agent Versus Agenthttps://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus.htmlVerified
- Threat actor abuse of AI accelerates from tool to cyberattack surfacehttps://www.microsoft.com/en-us/security/blog/2026/04/02/threat-actor-abuse-of-ai-accelerates-from-tool-to-cyberattack-surface/Verified
- AI as tradecraft: How threat actors operationalize AIhttps://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/Verified
- AI brands as bait: How threat actors are using the AI hype in social engineeringhttps://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, Aviatrix CNSF would likely limit the attacker's ability to exploit compromised credentials to access sensitive systems.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's lateral movement by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
While financial loss and reputational damage may still occur, Aviatrix Zero Trust CNSF would likely limit the scope of the impact by containing the attacker's activities and reducing the blast radius.
Impact at a Glance
Affected Business Functions
- Financial Transactions
- Executive Communications
- Vendor Management
- Employee Training
Estimated downtime: 7 days
Estimated loss: $25,000,000
Potential exposure of sensitive financial data, executive communications, and vendor information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced threat detection systems capable of identifying AI-generated phishing attempts and deepfake content.
- • Enforce multi-factor authentication (MFA) across all critical systems to prevent unauthorized access.
- • Conduct regular security awareness training for employees to recognize and report sophisticated social engineering attacks.
- • Deploy zero trust segmentation to limit lateral movement within the network and contain potential breaches.
- • Establish robust egress security and policy enforcement to monitor and control outbound data transfers, preventing unauthorized exfiltration.



