Live face-swapped video calls — the scam that stole $25 million in one meeting.
In the most famous case so far, a finance employee in Hong Kong joined a video conference with his company's CFO and several colleagues — all of whom were deepfakes — and wired out roughly $25 million on their instructions. Seeing was believing. That's exactly what the attackers counted on.
Real-time face swapping has left the research lab: consumer tools can now puppet a stolen face over a live webcam feed. The targets are businesses (executive impersonation for wire fraud), individuals (romance scammers who can finally 'prove' they're real on video), and families (video versions of the emergency call).
How the scam works
1
Source material
Photos and video of the target — an executive's conference talks, a stolen dating profile's owner, anyone with a public face — train the model.
2
The live puppet
On the call, the attacker's face movements drive the victim's trusted face. Voice cloning covers the audio. Short, low-resolution, 'bad connection' calls hide the seams.
3
The ask
For businesses: an urgent, confidential wire or a change to payment details. For individuals: video 'proof' that dissolves your last doubt before the money request that follows.
4
The pressure
Deepfake calls are kept brief and one-directional. Long, interactive conversation is the enemy of the technology — so the script avoids it.
Red flags to watch for
!
Video proof arriving exactly when you doubted
If someone dodged video for weeks and suddenly offers a short, blurry call right when you got suspicious, the call is the costume.
!
Short calls, bad quality, excuses to end
Brief or blurry video can raise suspicion, but ordinary connection problems look the same. Treat quality as a weak signal, not proof.
!
Visual artifacts
Odd edges, lighting, motion, or occlusion may appear in some manipulated video, while capable deepfakes may show none. Visual artifacts are supplementary clues and never establish identity.
!
Meeting requests from odd channels
A 'confidential' video meeting scheduled through personal email or WhatsApp rather than the company calendar is a setup, whatever the faces show.
!
Instructions that bypass process
Any payment, credential, or data request whose justification is 'the person told me on video' should trigger process, not obedience.
What to do
✓
Verify through a known channel
Contact the person using a known number, official company chat, or an in-person route that you initiate. Do not rely on contact details or accounts supplied by the suspicious meeting.
✓
Require normal approval controls
No wire, vendor change, credential reset, or sensitive-data release should rest on a call alone. Keep dual approval and documented change-control steps in force regardless of who appears on video.
✓
Use visual checks only as weak clues
Movement requests or visible artifacts can supplement verification, but passing or failing them is not proof. Never approve money, credentials, or data without known-channel confirmation and required controls.
✓
If money moved
Call the bank immediately for a recall attempt, file with ic3.gov, and preserve the meeting invite, recording, and messages. Speed is the only real lever on wires.
Frequently asked questions
Can deepfakes really run live on a video call?
Yes. Real-time face swap tools run on ordinary gaming hardware. Quality varies — which is why attackers keep calls short and blame the connection — but 'good enough for a compressed webcam feed' was passed years ago.
How did the $25M Hong Kong scam work if the whole meeting was fake?
The attackers reconstructed multiple executives from public appearances and staged a group call where only the victim was real. Group settings actually help attackers: peer pressure plus authority, and the victim mostly listens.
Is there software that detects deepfake calls?
Detection tools exist but can miss manipulated media or flag genuine media. Do not use a detector or visual test as an approval gate; confirm through known channels and keep payment and access controls in place.
Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.