What Is a Deepfake Video Call Scam?

In Hong Kong, a finance worker joined a video call with his CFO and several colleagues. Every single face on that call was generated in real time. He wired $25.6 million. The tools that did it are free, run on a gaming PC, and fail three specific tests you can run mid-call.

What Is a Deepfake Video Call Scam?
Quick Answer
A deepfake video call scam is a live call where attackers swap their face and voice in real time to impersonate someone you trust, usually a CFO, a boss, or a relative, then pressure you into moving money or handing over access. You spot it in real time by forcing the fake to do something the model cannot render: a full side profile, a slow hand passed across the face, or an unscripted question only the real person could answer. Stop inspecting the picture and start testing the person.

The $25 Million Call Where Only One Attendee Was Real

$25.6M lost across 15 transfers to 5 accounts

January 2024, the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House. A finance employee received an email from the company's UK chief financial officer about a confidential transaction. He thought it was phishing. So he did the responsible thing and joined the video call that followed.

The CFO was on it. So were several colleagues he recognised. They discussed the deal, gave instructions, and the call ended. Over the following days he made 15 transfers totalling HK$200 million, roughly $25.6 million, into five Hong Kong bank accounts. He only discovered the fraud when he checked in with headquarters afterward. Arup's global chief information officer Rob Greig later confirmed the attack publicly and said no internal systems were breached. Nothing was hacked. A meeting was.

Ferrari nearly went the same way in July 2024. An executive received WhatsApp messages and then a call using a cloned voice of CEO Benedetto Vigna, complete with his southern Italian accent, pushing an urgent confidential acquisition. The executive stopped it with one question: what book did you recommend to me last week? The caller hung up.

One company lost $25 million. The other spent four seconds on a question. That gap is the whole story.

💡 Key Insight: The Arup employee did verify. He verified against the attacker.

How a Live Face Swap Reaches Your Screen

~15-25 fps live swap on a single consumer GPU, under $1/hour rented

This is not Hollywood VFX. It is a five step pipeline that a moderately technical person can assemble in an afternoon.

1. Harvest the face. Conference keynotes, earnings calls, podcast clips, LinkedIn video posts. Two to five minutes of clean frontal footage is plenty. Executives publish their own training data. 2. Build the model. Deep-Live-Cam, which trended at number one on GitHub in August 2024, needs a single photo. DeepFaceLive produces better results with a few hours of training on a rented GPU at under a dollar an hour. 3. Feed it to the app. The swapped output goes into OBS Virtual Camera, so Zoom, Teams and Google Meet see it as an ordinary webcam. No exploit, no plugin, no warning. 4. Clone the voice. Thirty seconds of the same audio is enough for commercial voice tools. Many attackers skip this and keep the fakes muted, letting one impersonator speak. 5. Stage the room. Multiple fake participants, video locked at low resolution, an apology about bad hotel wifi, and a script that never wanders.

The detail that gives it away: these models collapse past roughly 45 degrees of head rotation, and they smear when anything crosses the face. So the attacker frames tight, stays centred, and never turns. That constraint is your weapon.

💡 Key Insight: Nobody breaks into your network. They just show up to the meeting wearing your CFO's face.

Why Competent People Approve It Anyway

49% of 575 surveyed companies hit by audio or video deepfake fraud in 2024

The Arup employee was suspicious. That is the part everyone skips over. He suspected the email, escalated to a live call, saw familiar faces, and his doubt evaporated. The scam works by manufacturing the exact reassurance you would go looking for.

The multi-person call kills the one instinct that used to save people. "Check with a colleague" fails when the colleagues are synthetic. Regula surveyed 575 companies in 2024 and 49% reported being hit by audio or video deepfake fraud. Deloitte's Center for Financial Services projects generative AI could push US fraud losses to $40 billion by 2027.

The second force is social, not technical. Asking your chief financial officer to turn her head sideways on camera feels insane. Asking her to wave a hand in front of her face feels like an accusation. That embarrassment is worth more to attackers than any rendering improvement.

And if you are squinting at hairlines hunting for pixel artifacts, you are wasting your time. Most guides still tell you to watch for unnatural blinking and blurry edges. Those tells were real in 2020. A 360p video feed on a corporate wifi connection destroys every one of them, which is exactly why attackers cap the resolution and blame the bandwidth.

💡 Key Insight: The deepfake does not need to be perfect. It only needs to arrive right after you got suspicious.

Three Tests That Break a Live Fake in Under Ten Seconds

4 seconds: the length of the question that saved Ferrari

Stop analysing the image. Give the model a task it was never trained for.

TestWhat you sayWhat breaks
Full profile turn"Turn and look at your left wall for me."Swap models train on frontal faces. Past ~45 degrees the face tears, snaps back, or the real jaw bleeds through.
Hand occlusion"Wave your hand slowly across your face."Fingers smear, the face flickers, or the hand vanishes behind the mask layer.
Unscripted memory"What did we argue about on Tuesday?"The impersonator has a script, not a relationship. Hesitation, deflection, or a pivot back to urgency.
Physical prop"Pick up something from your desk and hold it next to your ear."Objects crossing the face boundary expose the mask edge.

Honest caveat: I have run the profile test on a colleague on genuinely terrible hotel wifi and gotten what looked like a false positive. Real compression stutters too. So treat these as signals, never proof.

The actual defense is procedural. Write one rule and enforce it without exception: no money moves and no credentials change on the authority of a call, ever. Hang up, and call back on a number from your own contacts, not from the invite. Agree a spoken passphrase with your family and your finance team this week. Require two humans on two separate channels for any transfer above a threshold you set today.

💡 Key Insight: Authenticate the channel, not the face. Faces are now rendered assets.

Key Takeaways

🎯Arup lost $25.6 million in 15 transfers after one employee joined a video call where the CFO and every colleague on screen was a real-time deepfake.
📌Free tools like Deep-Live-Cam and DeepFaceLive push a swapped face into OBS Virtual Camera, so Zoom and Teams treat it as an ordinary webcam. No exploit required.
⚡Victims often fall for it precisely because they were already suspicious. The fake call is staged to be the verification step you went looking for.
🔑Run the profile test today: on any call involving money or access, ask the person to turn fully sideways and wave a hand across their face. Face swap models collapse past roughly 45 degrees of rotation.
💎Live swap quality improves every quarter, but the occlusion and rotation weakness is architectural. Build a callback-and-passphrase rule now, because visual detection has maybe 18 months left.

FAQ

Q: Can I just use a deepfake detector app during the call?
A: No. Detection tools lag new generation methods by months and typically need clean, high bitrate footage, which is the opposite of a compressed 360p conference stream. Ferrari was saved by a question about a book recommendation, not by software.

Q: Isn't it paranoid to ask my boss to turn sideways on a video call?
A: It feels awkward for about three seconds, and that awkwardness is exactly what attackers are counting on. Frame it as company policy rather than personal doubt: "Standard check before I touch a payment, mind turning your head?" A real executive will respect it and a fake one will resist.

Q: What should I set up for my family tonight?
A: Pick one spoken passphrase, something no social media post could reveal, and tell every family member that any request for money or urgent help must include it. Then add a rule that anyone calling in distress gets hung up on and called straight back on their saved number.

Conclusion

Your face and voice are already public training data, and the software that weaponises them runs on a gaming PC for the price of a coffee. Send one message today, to your finance lead or your parents, establishing that no money moves on the strength of a call alone. Then agree a passphrase, because the next call you get may look and sound exactly right and still be nobody at all.

💡 Lucas's Insight

For a century, seeing a face meant something. That assumption is being retired in real time, and most of us have not updated the software in our heads. What unsettles me is not the technology but the direction of the fix: we are drifting toward a world where trust has to be re-established with cryptographic keys and shared secrets rather than recognition, and something quietly human gets lost in that trade. So ask yourself honestly, when was the last time you verified a person rather than a picture of one? Whatever answer you give now, your grandchildren will find it charmingly naive.
  • How to Spot Deepfake Video Call Scams?
    Scammers can now fake a live video call of your CEO or your child. The good news: even the best deepfakes still fail simple physical tests you can run mid-call. Here's exactly how to catch them.
  • How Do Deepfake Video Calls Enable Romance Scams?
    Romance scammers used to fail one test: the video call. Real-time face-swap software killed that defense. A criminal in a Southeast Asian scam compound can now appear on camera as a smiling stranger, speak in a cloned voice, and run forty relationships at once.
  • How Are AI Deepfakes Used in Romance Scams?
    Romance scammers are now using real-time AI deepfake video and cloned voices to impersonate attractive strangers — and sometimes even your own family members. The technology costs less than $20/month and is shockingly convincing. Here's what the attack looks like and how to protect yourself today.

Also on AI Future Lab