The new face of AP fraud: deepfakes, fake vendors, and the $25 million phone call

Robert Lynch
Robert Lynch

AP & P2P Analyst

The new face of AP fraud: deepfakes, fake vendors, and the $25 million phone call

In January 2024, a finance employee at Arup, the UK-headquartered engineering firm behind projects like the Sydney Opera House, joined what looked like an entirely normal video call. On the screen were the company’s CFO and several familiar colleagues. Over the course of the call, the employee was instructed to process a series of urgent transfers. Fifteen separate payments later, Arup had been defrauded to the tune of roughly $25 million (some reports put the precise figure at $25.6 million, or HK$200 million).

Every single person on that call, other than the employee, was an AI-generated deepfake.

How the Arup deepfake video call led to a $25 million loss

The Arup case, confirmed by Hong Kong police and first reported publicly in May 2024, is now one of the most closely examined AP fraud incidents on record, and it is worth understanding in detail because it breaks a lot of assumptions finance teams still rely on.

It didn’t start with the video call. It started with a phishing email impersonating Arup’s UK-based CFO, asking for a confidential transaction. The employee was initially sceptical of the email, exactly what a well-designed AP control process should produce. The problem is what happened next: the employee was invited onto a video call to “confirm” the request, and on that call they saw and heard the CFO and other colleagues, all speaking, gesturing, and responding in real time.

The attackers had built these personas from publicly available footage: conference recordings, webinars, earnings calls, anything with enough clean audio and video of the real executives to train a model on. There was no live human being to catch out with a trick question. The synthetic CFO didn’t need to be perfect. It only needed to be convincing enough, for long enough, to outweigh one employee’s instinct that something was off. It worked, on 15 separate occasions.

This is the uncomfortable part for anyone who assumes “I’d know a deepfake if I saw one”: in the flow of a normal working day, on a normal call, with a normal-sounding request, most people won’t stop to run a forensic analysis of pixel artefacts. They’ll do their job.

How voice cloning fraud and vendor bank detail scams are spreading

Arup is the largest and best-documented case, but it sits inside a much older, still-widening pattern.

A few years earlier, the CEO of a UK-linked energy firm authorised a transfer of roughly €220,000 after a phone call using what he believed was the voice of his German parent company’s CEO. It was an AI-cloned voice. That case has been circulating in security reporting for some time now; it’s less “new 2026 threat” and more evidence that voice and video impersonation fraud has been building, quietly, for years while most AP processes carried on as before.

More recently, and closer to the day-to-day reality of most finance teams, is a pattern that doesn’t need any AI-generated face at all. In May 2026, a Quebec-based packaging manufacturer filed a lawsuit alleging it had been defrauded of CA$203,664. The company had received a genuine invoice from its insurance broker.

Eight days later, an email arrived that looked, on the surface, identical to prior correspondence: same subject line, copies of the real invoices, the broker’s usual tone, from a domain that swapped “-ca.com” for the genuine “.ca”. It said the broker’s bank details had changed. The company paid. The fraud wasn’t discovered for over a month, until the real broker called, chasing an unpaid invoice.

No deepfake, no synthetic voice, just a well-timed, well-written email and a domain that looked right at a glance.

Why AI is making invoice fraud and BEC scams harder to detect

What links Arup and the Quebec case isn’t the technology; it’s that both attacks were built to survive a human’s normal, reasonable level of scrutiny. AI has lowered the cost and the skill required to do that convincingly, at scale. Cloning a voice or a face used to require specialist tools and real effort.

Now it’s increasingly automated. Newer variants reportedly use AI to intercept invoice PDFs in transit and alter the embedded bank account number in a way that is visually indistinguishable from the original, defeating the classic “does this look right” check entirely.

The numbers back up how quickly this has scaled. In the UK, Action Fraud figures cited by the National Crime Agency and NatWest, in a joint campaign launched in January 2026, showed £3.9 million lost across 83 reported invoice fraud cases in September 2025 alone, an average of roughly £47,000 per case, with invoice fraud accounting for 85% of all payment-diversion fraud losses that month.

In the US, the FBI’s Internet Crime Complaint Center reported business email compromise losses of around $3 billion in 2025, one of the largest categories of cybercrime loss it tracks. And in November 2025, ACCA warned that procurement and third-party fraud remain badly underreported globally, often absorbed quietly as “operational leakage” rather than logged and investigated as fraud. The real number, in other words, is bigger than any of the above.

How to prevent AP fraud: controls that actually work

None of this means AP teams are defenceless; it means the controls need to catch up to how the fraud actually works now. Three things matter most.

Segregation of duties, so no single person can both approve a vendor change and release a payment against it. Independent, out-of-band verification of any bank detail change, using a phone number already on file, never one provided in the request itself, a call, not a reply to the same email thread that might already be compromised. And a full audit trail of who changed what, when, and on what authority, so that when something does slip through, it’s traceable in hours rather than the month it took the Quebec broker’s client to notice.

These aren’t new ideas. What’s changed is how badly they’re needed, and how quickly a business can lose the ability to apply them once an attacker is inside a genuine vendor relationship rather than an obviously fake one.

This is exactly the gap that SoftCo’s Supplier Lifecycle Management (SLM) capability, part of the SoftCoAP platform, is built to close: independent verification of any bank detail change, and a complete, auditable record of every supplier interaction. If you want to see how this plays out in more detail, including more recent cases and a practical breakdown of AP fraud controls, register for our upcoming webinar, “The Payment You Didn’t Authorise: How Fraudsters Are Targeting AP Teams in 2026”, or take our AP controls self-assessment to see where your own process might be exposed.