In May 2024, British engineering firm Arup confirmed an incident that became a global warning: an employee in the finance team, in Hong Kong, had wired around $25 million across 15 separate transactions. The chief financial officer had asked for it. The employee had seen his face on a video call and heard his voice. Only later did anyone find out: it was a deepfake.

What makes this case matter more than others is not the sophistication of the technique — it is what it exposes. For centuries, companies built controls on a simple premise: you recognize the face and voice of whoever is asking, so the request is legitimate. But recognizing a person is no longer proof of who they are. And in Brazil and Latin America, where executive approval processes already carry time-zone gaps and trust shortcuts, a fake identity finds even more fertile ground.

Arup was not an isolated case. According to a Gartner survey released in 2025, 62% of organizations experienced an incident involving a video or audio deepfake in the prior 12 months. Much of that activity centered on audio calls: another Gartner survey found that 41% of affected organizations faced a deepfake combined with social engineering on an audio call — someone calling to request an urgent transfer, the voice synthetic and convincing, the request appearing to come from the top.

The problem: visual identity became useless for authorizing sensitive actions

The reason the Arup employee fell for the scam was not naivety. It was design: he was authorized to make transfers. The video call created the illusion that whoever could authorize the transfer was on the line. Neither of those two facts was false — only the medium carrying them was.

High-quality audio deepfakes need as little as 3 seconds of an original voice sample to reach an 85% match, according to an analysis by Security.org. Video is somewhat slower to fake convincingly, but only marginally. The technical gap between a deepfake that fools a human and one that does not is measured in weeks, not months. And it keeps shrinking.

The result is that traditional defenses — recognizing a voice, seeing a face, confirming by email — stopped proving anything. Someone gains the authority to move money because the company's identity system said yes. If that system still rests on "you recognized the person," then anyone who can fake a face and a voice inherits that authority. And in a live video call, urgency adds pressure: questioning feels like wasting time, and wasting time feels like failing to follow an order that appears to come from above.

Companies that try to fix this with "ban video calls for transfer requests" create a different problem: approvals get slower, more bureaucratic, and — paradoxically — closer to email, which is just as easy to fake.

Why traditional policies fail

Why traditional policies fail

According to Deloitte's Center for Financial Services, fraud enabled by generative AI in the US banking sector could reach $40 billion a year by 2027, up from $12.3 billion in 2023. Most companies responded the only way they knew how: more policies, more approval chains, more confirmation emails, more checklists.

The problem is that adding an approval step to an already slow process does not remove the risk — it just spreads it around. If the second approver also relies on recognizing a voice or a face, you now have two deepfakes in a row, not one.

Banning video calls does not solve it either. The word "ban" assumes there is a real, workable alternative. If the official alternative is "send an email or call by phone," someone under pressure — "wire $25 million today or lose the contract" — will see little difference. A faked email is just as easy as a faked call.

What all these controls have in common is that they try to prove identity from the middle up: looking at the face, the voice, the email. The failure starts at the wrong point.

What has to be in place

A secure payments and approvals environment does not rely on recognizing who asked. It relies on separating "the person who made the request" from "the person authorized to do what was requested."

Corporate identity, not convenience biometrics. Whoever transfers money needs to authenticate through Active Directory, a physical badge or a corporate token — not through a voice or a face captured by a camera. Company identity is the gatekeeper, not the camera in the meeting room. The person enters the approval system as "Ana Ferreira from finance," and the system knows Ana was let go in July — so she never reaches the transfer account, no matter how perfect her voice sounds.

Segregation of duties: who requests, who authorizes. The employee who submits a transfer is one person. Whoever approves it is someone else, on a different screen, with controlled access. And if the transfer targets a new bank, exceeds a threshold, or goes to a beneficiary outside the approved list, a third person has to step in — say, the compliance manager.

Approval without a video call. Every sensitive approval happens inside a closed system, through a channel that is neither audio nor video: a form, a work order, a ticket that stays on record. Because if someone says "I saw the approval on the Zoom screen," nobody can tell whether that was a real Zoom call or a deepfake.

An auditable trail of who requested, who reviewed and who approved. A record showing: at 2:47 pm, person A (finance department) submitted a $25M transfer to account X. At 3:12 pm, person B opened the approval ticket. At 3:49 pm, they approved it. If it turns out the next day that person B was the victim of a deepfake and never actually approved anything, there is still a record — and that record makes the transfer traceable, reversible, and legally defensible.

That is how Skyller was designed: corporate identity as the entry point, access matching each person's role, human approval before a sensitive action, and an audit trail of every movement.

From the scam to the safeguard

From the scam to the safeguard

The Arup case does not prove the company did something wrong. It proves nobody had done something right — because nobody had designed a safe path for this. The employee was authorized. The request came from a familiar face and voice. From his point of view, everything checked out.

The payoff of a governed environment here is twofold. In the short term: the transfer would never have left the system. In the long term: even if it had, the audit trail would show clearly that the approval came from someone who was out of the company that day, and the transaction could have been reversed in hours, not weeks.

There is a second, less obvious gain: when sensitive approvals live inside a system, with segregation of duties and no dependence on facial recognition, a company can automate parts of the flow. If the transfer goes to a bank account already on the approved beneficiary list, the amount is under the limit, and the requester is a two-year employee with a clean record, then an AI agent can approve it automatically, without a human in the loop — because the decision is not "do I recognize this face?" but "does this transaction fit a policy I already know?"

A checklist for your next meeting

Before adding another layer of approval, it is worth going through these points with finance and IT leadership:

  1. Is every transfer approval recorded somewhere an auditor can check later? If the answer is "yes, but only in email," you do not have a trail. If it lives in a centralized system with a timestamp and the approver's name, that is solid — but it needed to already work that way.

  2. When someone is let go, how long before they lose access to the approval system? If the answer is "a few days" or "whenever someone remembers," you have a risk window. The ideal window is hours — and that is only possible if identity comes from Active Directory, not from a standalone account created months ago.

  3. Can a director approve a large transfer alone, or does it need a second approval? Two approval steps guarantee nothing if both people are on the same faked email thread. But they cut the risk if the second step is a form inside a system, not a Zoom conversation.

  4. Is there a policy banning transfer approvals over video calls, and a policy spelling out exactly how they must be approved? If not, someone under pressure will ask over Zoom, and you will only find out afterward.

Try Skyller for free