Why Following All Security Rules Still Led to a $25 Million Loss

Why Following All Security Rules Still Led to a $25 Million Loss
A finance professional at Arup, a multinational engineering firm, did everything by the book. They received an email from the company’s CFO requesting a confidential transaction. They were skeptical at first. Then came a video call with not just the CFO, but several senior colleagues. Everyone looked right. Everyone sounded right. The employee verified what they saw and heard, then authorized fifteen transactions totaling $25.6 million. Every person on that video call was AI-generated. The money vanished into criminal accounts across multiple countries.
This incident marks a fundamental shift in cybersecurity defense. For years, security training emphasized verifying requests through multiple channels. “If an email seems suspicious, ask for video confirmation” became standard advice. The Arup case proved that advice is now obsolete. When criminals can generate perfect real-time video and audio of executives using just seconds of publicly available footage, the traditional verification playbook collapses.
The implications reach far beyond one company’s loss. Business Email Compromise attacks have caused over $3 billion in losses in the United States alone in recent years, with AI-driven attacks accelerating that trend. Understanding why following established security protocols failed in this case reveals critical gaps in how organizations approach fraud prevention.
The Anatomy of Modern Business Email Compromise
Business Email Compromise represents a category of fraud where attackers impersonate executives or trusted business partners to authorize fraudulent transactions. Traditional BEC attacks relied on email spoofing, compromised accounts, or social engineering through text alone. The Arup case introduced a new dimension: AI-generated video and audio that passed human scrutiny in real time.
The attack followed a multi-stage pattern designed to bypass standard security awareness:
- Initial contact via email claiming to need a confidential transaction
- Invitation to a video call to “verify” the request
- Participation of multiple “senior executives” to create social proof
- Instructions to keep the transaction secret from other colleagues
- Multiple smaller transactions rather than one large transfer
This layered approach exploits a critical vulnerability in human psychology. Employees receive training to spot suspicious emails, creating initial skepticism. The video call invitation functions as the second stage, specifically designed to overcome that skepticism. When the employee sees familiar faces and hears familiar voices, their trained caution evaporates.
Why Visual and Vocal Verification Failed
The collapse of “I saw and heard them” as a security control represents one of the most significant shifts in fraud prevention. For decades, confirming someone’s identity through live video and audio provided reasonable assurance. AI technology has eliminated that assurance entirely.
Voice cloning technology now requires as little as three seconds of audio to generate convincing synthetic speech. Face cloning systems can produce real-time video from a handful of publicly available images. Setup time for these attacks has dropped from hours or days to single-digit minutes. Any executive who has appeared in a company video, given a conference presentation, or participated in a webinar has provided sufficient source material.
The Arup attackers likely collected their training data from legitimate business videos, investor presentations, or conference appearances. These sources provide high-quality audio and video in professional contexts, making the synthesized output even more convincing. The employee on the receiving end had no reason to doubt what their eyes and ears confirmed.
Current AI detection tools cannot reliably identify sophisticated deepfakes in real time during video calls. While forensic analysis after the fact might reveal artifacts like inconsistent lighting, unnatural facial movements, or lip-sync errors, expecting an employee to spot these issues during a live conversation with their CFO is unrealistic. The technology has advanced beyond human perceptual ability to detect.
The Social Proof Multiplier Effect
A critical element in the Arup attack involved multiple “senior executives” appearing on the video call. This wasn’t accidental. The presence of several authority figures creates a psychological phenomenon called social proof, where people look to others to determine correct behavior.
When an employee sees their CFO making a request, they might question it. When they see the CFO plus three other senior leaders, all apparently in agreement, questioning becomes much harder. The employee thinks: “If all these experienced executives are on this call, it must be legitimate.” This multiplies the perceived authority of the request exponentially.
The attackers also leveraged the “secret transaction” framing. By requesting confidentiality, they prevented the employee from seeking verification from colleagues who weren’t on the call. This isolation tactic is standard in BEC attacks, but combining it with multi-person video creates a particularly effective trap. The employee cannot check with others without appearing to violate a direct instruction from multiple senior leaders.
The Psychology of Authority Compliance
Understanding why intelligent, trained employees fall for sophisticated scams requires examining how authority affects decision-making. Decades of psychological research demonstrate that people have deep-seated tendencies to comply with authority figures, even when instructions seem unusual.
In workplace contexts, this tendency intensifies. Employees face real consequences for challenging superiors, especially when told a matter is urgent and confidential. The Arup employee likely experienced competing pressures: the trained skepticism from security awareness versus the professional obligation to execute instructions from leadership. When visual and vocal confirmation appeared to validate the request, compliance became the path of least resistance.
This dynamic explains why technology-focused defenses fail. Training employees to “be more skeptical” or “look for deepfake artifacts” asks them to override fundamental human psychology and professional incentives. Effective defense requires changing the system, not expecting individuals to resist sophisticated social engineering through willpower alone.
Process-Based Defense Strategies
The security community’s response to the Arup case has centered on one principle: process over technology. If visual and vocal verification can no longer be trusted, organizations must implement procedural controls that don’t rely on identity confirmation through video or audio.
The callback protocol represents the most straightforward implementation. Any request for fund transfers, regardless of how it arrives, requires verification through a phone call to a known, pre-verified number. This number must be independently sourced from company directories or previous legitimate contacts, not from the email or video call where the request originated.
Critical elements of effective callback protocols include:
- Maintaining verified contact lists independent of email systems
- Requiring callbacks for all transactions above defined thresholds
- Using different communication channels than the original request
- Training employees that callbacks demonstrate professionalism, not distrust
- Establishing clear procedures that authority figures cannot override
The dual approval system provides additional protection by requiring two independent authorizations for significant transactions. This prevents any single compromised employee from executing transfers. Both approvers must follow callback verification procedures, creating multiple opportunities to detect fraud.
Time zone restrictions add another layer. Many BEC attacks involve urgency and requests outside normal business hours. Policies limiting high-value transactions to headquarters business hours eliminate the “urgent request at midnight” scenario that pressures employees into bypassing verification steps.
Formal workflow systems within enterprise resource planning platforms ensure transactions follow documented paths with multiple approval steps. These systems create audit trails and prevent ad hoc verbal or video-based authorizations from bypassing controls.
Updating Corporate Financial Policies
Organizations must explicitly remove “verified by video call” from financial authorization criteria. This requires updating written policies, retraining finance teams, and auditing existing procedures to identify gaps.
Policy updates should specify:
- Video calls cannot substitute for callback verification
- Email instructions, regardless of apparent sender, require callback confirmation
- Transaction urgency does not override verification procedures
- Confidentiality requests do not eliminate approval requirements
- Multiple approvers must independently verify through callbacks
Finance leaders should conduct 30-day audits of recent payments, specifically flagging any transactions authorized primarily through video meetings with management. This identifies existing vulnerabilities and demonstrates whether current procedures would prevent similar attacks.
Executive leadership plays a crucial role by publicly supporting verification procedures. When CFOs and other senior leaders explicitly tell employees, “Always call me back on my known number, even if you just saw me on video,” it creates permission for appropriate skepticism. This messaging must be consistent and repeated regularly.
The Public Information Problem
The Arup attackers needed only publicly available footage to generate convincing deepfakes. This creates a dilemma for executives and public-facing professionals. Business development, thought leadership, and professional visibility often require video content. That same content provides training data for criminals.
Complete invisibility isn’t practical or desirable for most professionals. However, awareness of the risk allows for informed decisions about what to share and where. Executives might limit the amount of high-quality video with clear facial shots and extended speech samples. Companies might restrict internal video content from public access while maintaining external professional presence through other formats.
The more pressing concern involves internal corporate videos and communications. Many organizations record all-hands meetings, leadership updates, and training sessions. If these recordings become accessible outside the organization through data breaches, compromised accounts, or simple misconfiguration, they provide perfect source material for targeted attacks.
Organizations should audit what video content exists, where it’s stored, who can access it, and whether access controls are adequate. The same principle applies to publicly traded companies required to hold investor calls and publish executive presentations. While eliminating this content isn’t feasible, understanding it as potential attack vectors allows for appropriate compensating controls.
Training Beyond Traditional Phishing
Security awareness programs must evolve beyond identifying suspicious emails. Employees need to understand that any communication channel can be compromised, including video calls, voice calls, and even in-person meetings where identity might be questioned.
Effective training should include:
- Simulated deepfake scenarios where employees receive video messages from fake executives
- Practice with callback protocols using realistic business scenarios
- Clear scripts for professionally questioning requests without career risk
- Examples of actual BEC attacks, including the Arup case
- Regular testing that measures whether employees follow verification procedures
The training must address the psychological barriers to verification. Employees need explicit permission to question authority figures and clear procedures that protect them when following verification protocols. Organizations should celebrate employees who properly challenge suspicious requests, reinforcing that verification demonstrates competence rather than distrust.
What This Means for Different Roles
Finance and accounting professionals face the most direct risk from BEC attacks. They must become comfortable with callback verification as a standard practice for every transaction above established thresholds. This includes requests that appear to come from the CEO, CFO, or board members. The more senior the apparent requester, the more critical the verification.
IT security teams need to implement technical controls supporting process-based defenses: maintaining verified contact lists, enforcing dual approval workflows, implementing time zone restrictions, and creating audit trails. They should also prepare incident response procedures specifically for suspected deepfake attacks, including immediate transaction reversals and law enforcement notification.
Human resources professionals should update onboarding materials to include verification procedures as core job skills. New employees should learn callback protocols and verification workflows as part of standard business processes, not as special security measures.
Executive leadership must model appropriate behavior by expecting and welcoming verification callbacks. When a CFO tells finance teams, “I’m glad you called to verify, that’s exactly what you should do,” it reinforces the culture change needed to prevent attacks.
The Broader Implications for Business Communications
The Arup case raises uncomfortable questions about trust in business communications generally. If video calls can’t be trusted, what about voice calls? What about email with digital signatures? What about collaboration platforms?
The answer isn’t to abandon digital communication but to recognize that identity verification through technological means alone has become insufficient. Every communication channel requires additional verification through separate channels, especially when financial transactions or sensitive data are involved.
This represents a significant operational burden. Organizations must balance security requirements against business efficiency. Completely verification-intensive processes would slow decision-making unacceptably. The solution involves risk-based approaches: higher-value transactions require more verification, while routine operations continue with existing controls.
Some organizations are implementing code words or authentication phrases known only to specific individuals. These provide an additional verification layer but must be managed carefully to prevent them from becoming widely known or written down in insecure locations.
Moving Forward After a Verification Collapse
The collapse of visual and vocal verification as security controls requires fundamental changes in how organizations approach fraud prevention. Technology-focused detection solutions remain valuable research directions, but they cannot serve as primary defenses while AI generation outpaces detection capabilities.
The path forward centers on process, procedure, and culture. Organizations must implement and enforce verification protocols that don’t rely on confirming identity through video or audio. They must create environments where questioning authority demonstrates professionalism rather than insubordination. They must accept that additional verification steps, while operationally burdensome, cost far less than a single successful BEC attack.
For individuals entering cybersecurity or business roles, the Arup case provides a critical lesson: following rules designed for yesterday’s threats won’t protect against tomorrow’s attacks. Security isn’t a checklist of completed training modules or a technology solution to deploy. It’s an ongoing process of adapting defenses as attack methods evolve, questioning assumptions about what “verified” means, and implementing procedures that acknowledge human psychology rather than expecting people to overcome it through awareness alone.
The employee who lost $25 million followed every rule they knew. The failure wasn’t individual; it was systemic. Organizations that update their systems, policies, and cultures to reflect the new reality of AI-enabled fraud will protect themselves. Those that continue relying on visual and vocal verification will eventually appear in similar case studies, wondering how they could follow all the rules and still lose millions.
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify
