Deepfake fraud is an operations problem now, not a definition problem. Five attack scenarios, five controls that stop them, and where UK law sits in 2026.
A finance employee joined a video call. The chief financial officer was there, along with three colleagues whose faces he knew from the office. The CFO asked for an urgent transfer. Fifteen payments, twenty-five million dollars in total. He signed them off.
Everyone else on that call was a deepfake. He was the only real person in the room.
The firm was Arup, the London-headquartered engineering group, and the impersonated CFO was UK-based. It happened in January 2024. Arup's information officer later made a point that matters more than the sum: no system was breached and no data was taken. What happened was social engineering with better tools.
That distinction is the whole argument. A deepfake does not exploit a gap in your network. It exploits a gap in how your organisation confirms that a person is who they appear to be.
The underlying technique has not changed much. A model trains on existing photographs and recordings of a target, then reproduces the face and the voice.
Two things did change, and they are the reason this moved from curiosity to operational risk. Production became cheap, and it became real time. An attacker no longer has to send you a prepared clip. They can join the call.
That kills the defence most organisations quietly rely on, which is that somebody would notice. Video quality on a live call is poor at the best of times, and an attacker can lean on that. The defence has to move from perception to process.

A call arrives in the name of the managing director, often late in the day. There is a crisis and an approval is needed now. The target is usually a finance or operations lead. The picture is deliberately poor, which conceals the artefacts and also explains itself away.
The tell is never visual. The tell is that a payment or a permission is being asked for outside the normal route, with time pressure attached.
A smaller version of the Arup case, and far more common because it costs almost nothing. The finance director's voice is cloned and attached to an email as a voice note. "Release this invoice, I have approved it."
Invoice redirection fraud is decades old. The voice file changes the arithmetic, because the recipient now believes they have confirmed the instruction with a human.
A remote role is advertised. The candidate interviews well and the references check out. They are hired, equipment is posted to them, and months later internal material starts appearing where it should not.
This one is no longer speculation. Eleven allied governments issued a joint warning that operatives linked to North Korea are using real-time deepfake video to defeat identity checks in live interviews, supported by AI-generated CVs and fabricated portfolio sites. The estimate attached to that activity is around eight hundred million dollars channelled to weapons programmes in 2024. In July 2026 the FBI disclosed that it had identified an operative doing remote contract work inside a United States federal agency.
Hiring is a security perimeter now. Most organisations do not treat it as one.
A synthetic video of a listed company's executive. A merger is off, or a plant is closing. The share price moves within minutes and the attacker profits from the position they took first. The correction arrives half an hour later and recovers only part of the ground.
The exposure here is not only the company's. It is the shareholder's, and the speed of the correction depends entirely on how prepared the communications function is.
Banking, insurance, wealth management. An instruction arrives in the client's voice: change the account, move the funds, grant the authority.
Any process that treats a voice as proof of identity is open today. Voice biometrics on its own is no longer a control.
Two-channel verification. No instruction involving money or permissions is confirmed through the channel it arrived on. A request made on a video call is verified by telephone or in person. This is the cheapest item on the list and it closes the three most expensive attacks.
Callback discipline. The verification call goes to the number held in your own directory, not to the number that contacted you. An attacker can control the inbound route. They cannot control your directory.
Internal rehearsal. At least once a year, unannounced, run a simulated approach using a cloned executive voice. Record who approved, who asked for confirmation, and how long detection took. A reflex you have never measured is not a control.
Scenario training by function. The five scenarios above are the body of the training. Abstract warnings do not change behaviour; specific scenarios do. Finance, HR and client service teams need separate sessions, because the attack aimed at each of them is different.
Insurance and contractual review. Check today whether your cyber policy covers a transfer made by a deceived employee. Many policies respond to a system breach and not to authorised-but-induced payment. In the Arup case there was no breached system to point at.

Control | Cost | Time to stand up | Attacks it closes |
Two-channel verification | None, a process decision | Days | One, two, five |
Callback discipline | None, a process decision | Days | One, two, five |
Internal rehearsal | Low | Weeks | All, by measuring the reflex |
Scenario training | Medium | Weeks | All |
Insurance and contract review | Policy dependent | Weeks | Limits the size of the loss |
The first two rows can be decided in a meeting and applied the next morning, and between them they close the attacks that cost the most. Start there.
This is where a British organisation should be careful, because the position is often described inaccurately.
The United Kingdom has no equivalent of the European transparency obligations and no general duty to label AI-generated content. Four regulators are addressing AI through the powers they already hold, and Ofcom's AI strategy for 2026 and 2027 confirms the shape of it: there is no AI licence and no AI approval, only continuing duties about how the technology is used.
There is targeted legislation, and it is worth being precise about what it covers. Section 138 of the Data (Use and Access) Act 2025 came into force on 6 February 2026 and criminalises the creation of non-consensual intimate images, not only their distribution, which puts the UK among a small number of jurisdictions to go that far. Under the Online Safety Act 2023 the same conduct is treated as a priority offence and Ofcom holds platforms to detection and removal duties. That is a serious regime. It addresses a different harm from the one in this article, and it does not reach deepfake-enabled payment fraud.
Corporate deepfake fraud is prosecuted through general law, principally the Fraud Act. There is, however, a second regime worth putting on the same page. Since 1 September 2025 large organisations have been exposed to the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023. The threshold catches organisations above £36m turnover, above £18m balance sheet total, or more than 250 employees, and it reaches subsidiaries of a large group. The penalty is an unlimited fine.
Read that offence carefully before drawing the wrong conclusion. It bites where somebody associated with your organisation commits fraud intending to benefit it and you had no reasonable prevention procedures in place. Being the victim of an external deepfake does not trigger it. The connection is indirect and still useful: the regime raised the bar on what counts as reasonable fraud prevention, and the procedures that satisfy that duty are the same controls listed above.
One European point does reach British organisations. Article 50 of the EU AI Act has applied since 2 August 2026, and its scope follows the output of an AI system rather than the location of the company. A UK organisation with no European office can be inside it if what its systems produce is used in the European Union. Our note on the scope triggers goes through that in detail.
Arup is a global engineering firm with an experienced finance function and documented processes. It happened anyway.
Reported losses from deepfake-enabled fraud now run into billions, and most of the reported total was recorded across 2025 and the first part of 2026. Those figures come from industry trackers rather than official statistics, so they are better read as a direction than as a precise sum. The direction is not in dispute.
The scale came down as well. This is no longer only a twenty-five million dollar story. It now shows up in mid-sized organisations, on payments small enough that nobody escalates them.
One page. List every role in your organisation that can start a movement of money or a change of permissions. Beside each role, write two things: the channel an instruction arrives through, and the channel it gets confirmed through.
Every row where those two are the same is an open door. That is your list.
Henry Ajder advises organisations on synthetic media and is on our speaker roster. Here he takes the question most boards start with.
Watch: Should We Be Worried About Deepfakes?
Synthetic video or audio produced by a model trained on existing footage and recordings of a real person, close enough to the original to pass as genuine. Two properties make it an operational problem rather than a curiosity in 2026: production is cheap, and it runs in real time, which means an attacker can join a live call rather than send a prepared clip.
Not reliably, and planning on it is the mistake. On a live call the attacker keeps the picture quality low, which hides the artefacts and also gives them an innocent explanation. Detection has to sit in the process rather than in the viewer: an instruction is never confirmed through the channel it arrived on.
Executive impersonation aimed at starting a payment, in two forms. One is the synthetic video call, of which the Arup case is the largest documented example at fifteen transfers and twenty-five million dollars. The other is a cloned voice note attached to an invoice approval, which is far more common because it costs almost nothing to produce.
Any instruction involving money or permissions is confirmed through a different channel from the one it arrived on, and the confirming call goes to the number in your own directory rather than the number that contacted you. It costs nothing because it is a process decision rather than a purchase, and it closes the executive call, the cloned voice approval and the fraudulent client instruction together.
It is the subject of a joint warning from eleven allied governments. Operatives linked to North Korea use real-time deepfake video to defeat identity checks during live interviews, supported by AI-generated CVs and fabricated portfolio sites, with an estimated eight hundred million dollars channelled to weapons programmes in 2024. In July 2026 the FBI disclosed it had found an operative working remotely inside a United States federal agency.
No. The United Kingdom has no equivalent of the European transparency obligations and no general labelling duty. Four regulators are applying existing powers instead, and Ofcom's AI strategy for 2026 and 2027 is explicit that there is no AI licence and no AI approval, only continuing duties about how the technology is used.
No, and this is worth getting right. The offence under the Economic Crime and Corporate Transparency Act 2023, in force since 1 September 2025, bites where a person associated with your organisation commits fraud intending to benefit it and you had no reasonable prevention procedures. Being deceived by an external deepfake does not trigger it. The relevance is indirect: the regime raised the standard for reasonable prevention procedures, and those procedures are the same controls that stop inbound deepfake fraud.
Read the policy before assuming so. Many cyber policies respond to a system breach and exclude payments an employee was deceived into authorising. In the Arup case there was no breached system, which is exactly the gap. Ask your broker specifically whether social engineering and authorised push payment losses are covered, and at what limit.