Key Takeaways
- A deepfake video call impersonating the chief financial officer cost the engineering firm Arup roughly $25.6 million in early 2024. A familiar face and voice are no longer proof of identity.
- Documented deepfake losses so far involve business and executive impersonation, plus one case of a customer's own cloned voice defeating a bank's voice check. A wave of scammers deepfaking your specific bank's representative is a plausible risk, not yet an established reported pattern.
- The one defense that works no matter how convincing the fake is: hang up and call back on a number you look up yourself, never a number the caller hands you.
- Be suspicious of any urgent demand to move money by wire transfer, cryptocurrency, or gift card, and report fraud at ReportFraud.ftc.gov.
$25.6 Million and Every Face Was Fake: The Arup Deepfake Call
Picture the finance employee at Arup, a global engineering firm, sitting on a video call in January 2024. On the screen sat the company's chief financial officer and several familiar colleagues, all asking to move money for a confidential deal. Everyone looked right. Everyone sounded right. Over the days that followed, the employee approved roughly $25.6 million across fifteen separate transfers, and every face on that call except the employee's own was a deepfake. Nobody on the other end was real.
That story matters to you even though you will never wire millions on behalf of an engineering firm. It marks the moment the oldest advice about fraud, trust your eyes and trust a familiar voice, quietly stopped being enough. If a rendered chief financial officer can pass on a live video call, then the next call claiming to be "your bank" deserves the same patient skepticism. This article is about a single calm habit that guards your money and your credit nest when you can no longer take a face or a voice as proof: verify before you act.
The one habit that survives any fake
No rendered face and no cloned voice can answer the real number when you dial it yourself. The callback is the whole defense.

Why a Familiar Voice Is No Longer Proof of Anything
The tools behind these fakes have slid out of research labs and into cheap, off-the-shelf apps. A short clip of someone speaking, pulled from a webinar, a social video, even a voicemail greeting, can be enough raw material to generate a synthetic voice that sounds like them, and video is racing down the same curve. You don't need to follow the engineering to feel the consequence. The cues you have leaned on your whole life, a recognizable timbre or a familiar face, are now things a stranger can manufacture on a laptop.
Deepfake
A synthetic video or audio clip generated by AI to imitate a real person's face or voice closely enough to pass as genuine.
What's Actually Been Reported and What Hasn't
It helps to be exact about what has actually been reported, because precision is its own defense against panic. The documented deepfake losses so far cluster around businesses, not retail bank customers. The Arup transfers are the headline example. A separate case reported in 2025 involved roughly $499,000 lost to a deepfake Zoom call in Singapore. The BBC has reported a different and revealing twist: a case in which a customer's own cloned voice was used to defeat a bank's voice-identification check, the mirror image of a scammer pretending to be the bank.
What is not documented, at least not yet, is a wave of criminals convincingly deepfaking a named bank's representative and phoning ordinary customers at scale. It is a plausible extension of techniques that clearly work, and treating it as a live possibility is wise. But it has not been established as a reported pattern, and you deserve the honest version rather than a scary one. Reporting from InvestigateTV in April 2026 documented a related harm, real people's likenesses dropped into advertisements they never made, including a Texas sheriff in a supplement ad and a Virginia cosmetologist appearing to sell life insurance, not bank-representative impersonation. Knowing where the evidence stops keeps you skeptical without leaving you paralyzed.
The Real Scale: $12.5 Billion Lost to Fraud in 2024
The scale of impersonation fraud is easier to pin down. The Federal Trade Commission, the federal agency that tracks consumer fraud reports, published data for 2024 showing $12.5 billion reported lost to fraud, up 25% from the year before, drawn from 2.6 million reports. Imposter scams, someone pretending to be a person or institution you trust, were the single most-reported category, at $2.95 billion. That is the most recent fully published annual total, and it describes a problem that was already enormous before convincing video fakes entered the picture.
Reported Fraud in 2024 (Federal Trade Commission)
| Figure | Amount |
|---|---|
| Total reported fraud losses | $12.5 billion |
| Change from the prior year | Up 25% |
| Fraud reports filed | 2.6 million |
| Imposter-scam losses (most-reported) | $2.95 billion |
Imagine Nico, a hypothetical newcomer with a thin credit file who just opened his first account. He gets a call that shows his bank's name on the screen and a calm voice saying his card was flagged for fraud and he needs to "verify" his login to stop a transfer. Nothing about the voice sounds off. In the old world, that reassurance might have been enough. In this one, the reassuring voice is exactly the part that can be faked. If you're still building your nest, this is the season to make verification a reflex, a small egg of a habit you tuck away now and rely on later.
Identity vs. Channel: The Distinction Scammers Need You to Miss
Here is the mental shift that protects you: identity and channel are two different things, and only the channel is trustworthy. Who a caller claims to be, their voice, their face, the name on your screen, can all be forged. How you reach them back, on a number you looked up yourself, cannot be. Caller ID is easy to spoof, so a call that displays your bank's real name proves nothing at all. The whole con depends on collapsing those two things, on getting you to treat a convincing voice as if it were a verified line.
Suppose Riley, a hypothetical rebuilder two years into steadying her credit after a rough stretch, gets a text and then a call about a "suspicious $600 charge." The caller is warm, knows a few real details about her, and urges her to move her balance to a "safe" account right away. The pressure to act immediately is the tell. Real institutions do not lose the ability to help you in ten minutes; a scammer needs those ten minutes because a callback would end the illusion. When someone manufactures urgency, that is your cue to slow down, not speed up.
What Verifying Actually Looks Like
So what does verifying actually look like? The Federal Trade Commission's own guidance on voice cloning, published in April 2024, lays out a protocol that works just as well against a faked video call. Do not trust the voice. If a caller claims a loved one, or your bank, is in trouble and needs money, hang up and call back on a number you already know is theirs: the one printed on the back of your card, on a statement, or on the official website you typed in yourself, never a number or link the caller hands you. Be suspicious of any demand to pay or move money by wire transfer, cryptocurrency, or gift card, because those are the channels fraudsters prefer precisely because they're hard to reverse. And report what happened at ReportFraud.ftc.gov so it feeds the same data that helps the flock see the storm coming.
Got an unexpected call, text, or video asking you to move money right now?
The callback is the whole game. It costs you two minutes and a moment of mild social awkwardness, and it defeats a deepfake completely, because no rendered face and no cloned voice can answer the real number when you dial it yourself. Build that pause into every unexpected call about money, and the most sophisticated impersonation in the world has nowhere to land.
If a Call Gets Past You: Protect Your Credit Nest First
One Steady Line: A Voice Is Not Verification
It's worth naming why this feels so disorienting. For all of human history, a familiar face and a familiar voice were reliable proof of identity, and our instincts were built around that. Deepfakes break the instinct, not the defense. The defense was never really your ears or your eyes; it was the boring step of confirming through a channel you control. That step still works, and it works no matter how good the fakes get, because it doesn't depend on detecting the fake at all.
Share the habit, too. Scammers lean hardest on people who feel isolated and rushed, older relatives, someone in a hard financial season, anyone caught off guard. A quick family agreement, we always hang up and call back, no exceptions and no judgment, turns a private rule into a flock that watches for storms together. You don't have to become an expert in spotting synthetic media, and you never will need to chase every new tool the fraudsters adopt. You only have to hold one steady line: a voice is not verification, a face is not verification, and the one thing that still counts as proof is the number you look up and dial yourself.
Come back to that video call at Arup. Every face on the screen looked real, every voice sounded real, and none of it was, and the loss ran to roughly $25.6 million because there was no pause between believing and acting. That pause is the entire lesson. You will almost certainly never face a fabricated boardroom, but you may well get a call, some ordinary afternoon, from a voice that insists it's your bank and that something is wrong and that you must move money now. When that call comes, you already know what to do. You thank them, you hang up, and you dial the number on your own card. If the concern was real, the real institution will still be there to help. If it wasn't, you just watched a deepfake collapse the instant it met a channel it couldn't fake.
Action Items
Frequently Asked Questions
1. What happened in the Arup deepfake case?
- In January 2024, a finance employee at the engineering firm Arup authorized roughly $25.6 million across fifteen transfers after a deepfake video call impersonated the company's chief financial officer and colleagues. Every participant on the call except the employee was a synthetic fake.
2. Are scammers deepfaking banks to call regular customers?
- Documented deepfake fraud so far involves executive impersonation against employees and a reported case in which a customer's own cloned voice defeated a bank's voice-identification check. A wave of scammers deepfaking a named bank's representative and calling retail customers at scale is a plausible extension of known techniques, but it has not been established as a reported pattern.
3. How do I verify a call that claims to be my bank?
- Do not trust the voice. Hang up and call back on a number you look up yourself, such as the one printed on your card or statement, never a number or link the caller provides. Be suspicious of urgent demands to pay by wire transfer, cryptocurrency, or gift card, and report fraud at ReportFraud.ftc.gov.
4. Can I trust caller ID if it shows my bank's real name?
- No. Caller ID is easy to spoof, so a call that displays your bank's real name proves nothing at all. Identity and channel are two different things, and only the channel you reach out on, a number you looked up yourself, can be trusted.
5. How much did Americans lose to fraud in 2024?
- The Federal Trade Commission published data for 2024 showing $12.5 billion reported lost to fraud, up 25% from the year before, drawn from 2.6 million reports. Imposter scams were the single most-reported category, at $2.95 billion.
6. What should I do if a scam call gets past me?
- Move quickly but not frantically. Pull and read all three of your credit reports at no cost, look for accounts, inquiries, or addresses you don't recognize, dispute anything that isn't yours, and consider placing a fraud alert or a security freeze so a thief can't open new accounts in your name.