In January 2024, a finance employee at UK engineering firm Arup joined a video call with people he believed were the company’s CFO and several senior colleagues. Every person on that call was an AI-generated deepfake. He made 15 wire transfers totalling $25.6 million before the fraud was discovered when he checked directly with Arup’s London headquarters.
That incident was not a sophisticated nation-state attack. It was social engineering, built using publicly available video and audio of Arup’s executives, executed with tools accessible to any criminal with a mid-range laptop. UK incidents in 2024 and 2025 followed: cloned-voice approvals of supplier bank-detail changes, deepfaked calls impersonating senior executives, AI-generated phishing emails with perfect English and personalised hooks scraped from LinkedIn.
This article focuses on what has materially changed in 2026, what the specific attack types look like in practice, and the process controls that close the gap that technical defences leave open.
What Has Actually Changed: Why AI Makes This a Different Threat
Voice Cloning: What It Takes to Fake a Colleague’s Voice in 2026
Voice cloning now requires as little as 30 seconds of audio to produce a convincing synthetic replica of someone’s voice. That audio does not need to come from a private source. A LinkedIn video, a company website recording, a podcast appearance, or a recorded webinar provides more than enough source material. Security researchers have demonstrated that modern voice clones pass casual recognition by people who know the target personally.
In 2019, a UK energy firm lost €220,000 after an employee received a phone call from someone who sounded exactly like the company’s CEO, directing a transfer to a trusted supplier. That was early-generation voice cloning at a time when the technology required significant effort to produce. In 2026, the same capability is available via consumer tools at near-zero cost. A 2024 Starling Bank study found that 28% of UK adults reported being targeted by an AI voice cloning scam in the previous 12 months.
Deepfake Video: From the Arup Incident to Today
The Arup attack used a multi-person deepfake video call, with AI-generated versions of multiple senior executives appearing simultaneously in a live meeting. At the time it was reported, this felt like an outlier. It is not. Real-time face-swap technology has continued to develop, and deepfake video that passes visual inspection on standard video call tiles, at typical Teams or Zoom resolution, is achievable on consumer hardware with open-source tooling.
Arup’s CIO, Rob Greig, has said publicly that it took him less than an hour to create a convincing deepfake video of himself after the incident. His conclusion: this happens more frequently than most organisations realise. The fraud is not always reported, and when it is, it is rarely attributed to deepfake technology in public statements.
AI-Generated Phishing: Why the Bad Grammar Test No Longer Works
The most reliable visual signal for a phishing email used to be poor English: awkward phrasing, grammatical errors, mismatched formality. AI writing tools have rendered that signal useless. Phishing emails generated by large language models are now grammatically correct, tonally appropriate, and contextually accurate. They reference real projects, real contacts, and real recent events, scraped from LinkedIn profiles, company websites, and public social media.
The volume is the other change. What once required a human to craft individually can now be generated at scale, personalised to each recipient, across thousands of targets simultaneously. The economics of phishing have changed completely.
The Three Attack Types Your Team Needs to Recognise
The Fake Executive Call: Voice and Video Impersonation for Financial Fraud
The attack pattern: a finance team member receives a call or video meeting invitation from someone presenting as a senior executive or external adviser. The request involves a financial transfer, an urgent supplier payment, or a confidential transaction. The voice or face matches the person they expect to be speaking with. The request creates time pressure.
The tell: the request came through an unexpected channel, involves unusual urgency or secrecy, and asks for action that bypasses normal authorisation processes. The Arup attack began with a phishing email that the employee initially suspected was fraudulent. His doubt was overcome when the video call appeared to confirm the request was legitimate. The video call was the deception mechanism, not the reassurance.
The target: finance teams, PAs to senior leaders, and anyone with payment authorisation.
The Supplier Account Change: Social Engineering Your Finance Team
The attack pattern: a message arrives from what appears to be a known supplier, informing the finance team that their bank details have changed and requesting that future payments be redirected. The message may be preceded by a voice call from someone claiming to be at the supplier, using a cloned voice sample. The email arrives from a domain that closely resembles the real supplier’s domain.
The tell: the request to change payment details arrives unsolicited, with urgency, and does not come through the supplier’s normal contact. The phone number used for the follow-up call is not the pre-registered contact number.
The target: finance teams processing regular supplier payments, particularly where the supplier relationship is established, and the contact is trusted.
The Credential Harvest: AI-Personalised Phishing Targeting Apple IDs and SSO Accounts
The attack pattern: an AI-generated phishing email arrives that references specific context, a recent project, a named colleague, a genuine event, making it credible enough to act on. The email directs the target to a convincing replica of a login page for Microsoft 365, Google Workspace, or an Apple ID sign-in. Credentials are captured. The attacker now has authenticated access.
For businesses running managed Mac fleets, this attack vector has a specific downstream risk that is worth naming directly. A compromised Apple ID on a managed Mac can give an attacker access to Managed Apple Account credentials, iCloud Drive business data, and potentially DMS enrolment tokens, depending on how the Apple Business environment is configured. A compromised SSO account can propagate access across every application the employee uses through single sign-on. The credential is the key to the entire environment, not just one account.
The tell: the email references a genuine context, but the link destination does not match the expected domain. The request creates urgency around account verification, password expiry, or security alerts.
Why Technical Defences Alone Are No Longer Sufficient
What Email Filtering Catches and What It Misses
Email filtering with DMARC, SPF, and DKIM, correctly implemented, is effective against spoofed domains and bulk phishing. It does not catch a well-crafted message sent from a legitimate-looking domain registered by an attacker, a message delivered via LinkedIn, WhatsApp, or iMessage, or a voice call. The attack surface for social engineering extends well beyond the email inbox, and technical filtering applies only to the channels it monitors.
What MFA Protects and What It Does Not
Multi-factor authentication protects accounts from being accessed with stolen credentials alone. It does not prevent an employee from being manipulated into approving a fraudulent payment on a deepfake video call. It does not prevent a finance team member from changing supplier bank details after a convincing phone call. The deception in these attacks happens at the human decision point, not at the login screen.
MFA is a necessary control. It is not sufficient.
The Channel-Switching Problem: Why Attackers Move Across Platforms
A sophisticated social engineering attack rarely relies on a single channel. The Arup attack started with an email, moved to a video call, and ended with wire transfers that followed normal authorisation channels because the attacker had already established trust through the video call. Isolated security controls that monitor one channel at a time miss the cross-channel pattern entirely.
When the trust established on a video call is used to authorise an action taken through a legitimate business system, there is no technical alert. The transaction looks correct at every control point. The deception occurred upstream of all of them.
The Process Controls That Close the Gap
The Callback Protocol: Verifying Requests Through a Second Channel
Any request received via call or video that involves a financial transaction, a credential change, or a sensitive data transfer should be verified by calling back on a known, pre-registered number, not the number the request came from. This applies even when the voice or face matches someone the employee knows.
The callback must be initiated by the employee to a number already on record. A fraudster who has just impersonated a CFO on a video call can also answer a call to the number provided in that same call. The verification only works if the callback goes to a number that exists independently of the request.
These processes feel slow until the first time they stop a fraud. At that point, they feel like the most important thing in the building.
Financial Authorisation Rules: What No Voice or Video Call Should Be Able to Approve Alone
No payment, transfer, or financial commitment above a defined threshold should be authorised based on a voice or video request alone, regardless of who appears to be making it. The rule should be written into the financial policy and communicated clearly to everyone with payment authorisation.
The specific controls: any transfer above the threshold requires written confirmation via email from the requester’s known address; any change to supplier bank details requires written confirmation plus a callback to the supplier’s pre-registered number; any request described as urgent, confidential, or unusual is treated as higher risk, not lower.
Supplier Verification: What to Check Before Changing Payment Details
Bank detail change requests from suppliers are one of the most common and most successful social engineering vectors. The process control is simple and should be non-negotiable: any request to change supplier payment details is verified by a callback to a pre-registered number for that supplier before the change is made. The verification call is initiated by the finance team, not the supplier.
Maintain a register of pre-registered contact numbers for all suppliers above a minimum payment threshold. Update it only through a verified process. Do not update it based on information provided in the same communication that requested the bank detail change.
What Your Team Needs to Know: Awareness Training That Actually Works
What to Include in a 30-minute Briefing
Awareness training for social engineering is different from phishing click simulation. It cannot be tested with a fake email and a scorecard. The most effective format is scenario-based: show the team what a deepfake call actually looks like, play a voice clone example using audio samples available in the public domain, and walk through the Arup case in detail.
The three patterns to establish: unexpected urgency is a signal, not a reason to act faster; any request to bypass a normal authorisation process is a red flag, regardless of who is asking; verification through a second independent channel is always appropriate and never rude.
How to Run a Live Social Engineering Test Without Damaging Trust
Awareness training is a Cyber Essentials requirement, and regulators are increasingly expecting evidence of it in the context of AI-enabled threats specifically. Testing social engineering resilience requires a different approach from phishing simulation: scenario walkthroughs, tabletop exercises, and live examples of current attack techniques are more effective than gotcha-style fake attacks that damage trust between staff and the IT function.
Dr Logic can run a social engineering awareness session for your team that covers the current threat landscape, the specific process controls above, and a live demonstration of voice and video deepfake capabilities, so your team understands what they are being asked to defend against.
Related Articles
- Social Engineering 2.0: Deepfakes, AI Impersonation and the New Insider Threat
- Social Engineering in Cyber Security: The Human Risk Every SME Overlooks
- Cyber Essentials for Mac Offices: What UK Businesses Need to Know
FAQs
How much audio does an attacker need to clone someone's voice?
Security researchers have demonstrated convincing voice clones produced from as little as 30 seconds of audio. That audio does not need to come from a private source: a LinkedIn video, a company website recording, a podcast appearance, or a recorded presentation provides sufficient material. Anyone with a visible public profile, including most senior leaders, is a potential voice cloning target.
What is the most important process control against deepfake fraud?
The callback protocol: any request received via call or video that involves a financial transaction, credential change, or sensitive data transfer must be verified by calling back on a pre-registered number, one that exists independently of the request itself. This single control would have prevented the Arup fraud. The callback must be initiated by the recipient to a number already on record, not a number provided in the request.
Is awareness training a Cyber Essentials requirement?
Cyber Essentials requires that staff understand and follow security policies. Regulators are increasingly expecting evidence of training that addresses current threat types, including AI-enabled social engineering. The most effective format for social engineering awareness is scenario-based, using real examples and live demonstrations of deepfake capabilities, rather than phishing simulation exercises alone.



















































