By Donato Poveda
Published 2026-08-06
6 Min Read
Corporate Security
0:00 / 0:00

In January 2024, an employee in Arup's Hong Kong office joined a video conference about a confidential transaction. Every other colleague on the screen, including the British engineering firm's UK-based chief financial officer, looked & sounded exactly as they should. Over the following days the employee made 15 transfers to five Hong Kong bank accounts, totalling HK$200 million, about US$25.6 million.

None of those colleagues were on the call. Hong Kong Police, through Acting Senior Superintendent Baron Chan Shun-ching, said the fraudsters had downloaded existing video of the colleagues & added artificial-intelligence voices to it. The participants were pre-recorded. The employee was not in a conversation with anybody.

It did not begin on that call. It began with a phishing message in mid-January purporting to come from that chief financial officer, describing a secret transaction that had to be carried out. Email was the way in. Arup has said publicly that none of its internal systems were compromised, which is the company's own account & not an independent forensic finding.

The synthetic face is also rare, & saying so makes the case stronger. In 2025 the FBI logged 135 business email compromise complaints with an artificial-intelligence nexus, against 24,768 such complaints in total. Treasury's financial-crimes regulator cited the Hong Kong case by name in its November 2024 deepfake alert, so the typology is formally tracked. It is still not what is emptying corporate accounts.

Now take the video out. What is left is the shape the federal data describes: a request arrived carrying enough credibility, somebody with the standing to approve a payment approved it, & the money left. Nothing there required a synthetic face, & nothing required a broken control. The video is the memorable part of this case. The payment path is the one to focus on.

An empty corporate conference room in mid-morning light, a long table with a wall-mounted display showing a blank video-call grid, chairs pushed in, nothing happening

Where the Money Actually Leaves

Business email compromise ranks second of twenty-four crime types by reported loss in the FBI's 2025 Internet Crime Report, at $3.05 billion, & ninth of those same twenty-four by complaint count, at 24,768 complaints. The second-largest loss pool in American cybercrime comes off the ninth-largest complaint pool.

Set that against ransomware, which absorbs most of the security budget & nearly all of the vendor marketing. In the same report, ransomware losses come to roughly 1 percent of business email compromise losses, & one qualification belongs in the same breath: the FBI's ransomware figure excludes lost business, wages, files, equipment & third-party remediation, so it runs conservative. Ransomware is serious. It is not where the money leaves.

The money leaves by the ordinary route. In that same report, 86 percent of business email compromise funds moved by wire transfer or automated clearing house: ordinary rail, ordinary speed, ordinary authority, moving money the way payroll moves. Every one of those transfers was authorized by somebody with the standing to approve a payment, using a procedure the organization wrote down on purpose.

The Exception Is the Attack Surface

The United States Treasury made this argument in 2019, & the title of its document is the argument. FinCEN advisory FIN-2019-A005 is "Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes," & one of its section headings reads "Vulnerable Business Processes Compromised."

Its finding is that these actors identify processes vulnerable to compromise, through openly available information about their targets or through cyber-enabled reconnaissance, & then insert themselves into a business relationship by impersonating somebody critical to it. Reconnaissance is FinCEN's own word. On what decides the payout the advisory is blunt: "A scheme's probability of success and the potential payout from fraudulent payment instructions often depends on the criminal's knowledge of their victim's normal business processes, as well as weaknesses in the victim's authorization and authentication protocols." Neither half of that lives in the mail gateway.

Most organizations, regardless of size, have a documented way to move money faster than their normal approvals allow: the urgent payment procedure, the emergency wire, the confidential transaction authority, the after-hours approval. It exists for legitimate reasons, competent people signed it off, & it sits in a policy almost nobody reads twice. It is also, in my experience, the least audited control in the building.

The attacker does not break the exception. He qualifies for it, & the exception performs exactly as it was written to perform.

FinCEN establishes that the reconnaissance runs on openly available information, but no federal advisory enumerates what that information is. So this list is my own observation from the assessments I run, not federal guidance: the org chart on the About page, the conference programme naming the finance director, the out-of-office reply giving a deputy & a return date, the press release announcing a new supplier, the professional-network profile where an accounts payable specialist lists the approval workflow as an accomplishment. None of it is confidential. Assembled, it is a briefing on how your money moves & who can move it.

This is also the one thing generative AI genuinely changed. It did not create the fraud, which predates it by decades. What it retired was the informal authentication organizations quietly relied on: recognizing a face, a voice, the way a colleague asks for something. Those were never controls, only substitutes for a written verification step, & they have stopped working.

Auditing the Exception

An audit here starts with a document, not a system. Find the written procedure that lets a payment move faster than the normal approval chain, then ask who verified it last, & how. Not whether it exists. Whether anybody used it in the past year, & whether a record of that verification survives.

Three controls worth testing against are federal.

Three more belong in the same audit, & none appears in any federal advisory. I am labeling each so nobody mistakes it for FBI or Treasury guidance.

A printed payment authorization procedure lying on a desk with one clause marked, a black desk telephone beside it, a manila vendor file open alongside in flat daylight

An organization can spend its whole security budget on the inbox & still lose the money, because the inbox is not where the money is. The money is in the exception: a paragraph in a finance policy, legitimate, approved by competent people for good reasons, & the attacker's entire job is to arrive looking like the situation it was written for.

In Hong Kong the money left by ordinary bank transfer, authorized from inside the company. That is the uncomfortable part of this case & also the useful part, because a payment process is something an organization can read, test & rewrite, while a person's judgment on a bad morning is not.

Audit the exception, not the inbox. At Scopos Strategies the payment exception is where an assessment starts, ahead of the mail gateway & ahead of the phishing training, because it is the door the money actually goes through.

What is your organization's documented way to move money faster than the normal approvals allow, & when did anybody last test that it works the way the document says?

Sources

Back to Insights

This article was produced with AI assistance. The perspective and security expertise are the author's own.