Fraudsters reportedly used AI-generated audio to impersonate the chief executive of a German parent company and persuade the head of its UK energy subsidiary to transfer €220,000. The case was reported by the Wall Street Journal and the firm’s insurer, Euler Hermes.
What happened
- The UK executive believed he was speaking to his boss, who asked for an urgent payment to a Hungarian supplier.
- The money was moved from the Hungarian account to accounts in other countries.
- The fraudsters called again seeking a second payment, but the executive grew suspicious and refused.
- The insurer’s fraud expert said the synthetic voice even captured the chief executive’s accent and speech patterns.
Why it mattered
It was one of the first widely reported cases of voice-cloning technology being used in fraud, and it foreshadowed later deepfake scams. Security experts warned that as voice synthesis became cheaper, phone calls could no longer be treated as proof of identity.
Lessons for organisations
Require call-back verification through known contact details for urgent payment requests, apply dual authorisation for transfers, and train finance staff to treat unusual urgency as a warning sign. Consider agreed code words or other out-of-band checks for senior leaders’ instructions.
Source: Sophos
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.