Blindfy — Digital Protection

Fake CEO video authorizing a transfer: the meeting scam

How fake Zoom meetings with executive deepfakes authorize billion-dollar transfers.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

The CFO joins a hastily called Zoom meeting, sees the "CEO" and two "directors" authorize a confidential transfer, and executes the payment. Every participant was a deepfake.

How the scam works

Attackers collect public C-level videos (talks, interviews), train real-time deepfake models and run the meeting with synchronized synthetic audio.

Common mistake

Trusting video imagery as sufficient authentication for high-value financial movements.

Impact

High-value financial loss, global reputational damage, board proceedings and harm to auditors and insurers.

What works

Mandatory multi-factor confirmation outside the video channel, executive passphrases and a double-check protocol for atypical transactions.

Protection checklist

  • Require confirmation outside the video channel
  • Set a quarterly executive passphrase
  • Implement dual approval for high amounts
  • Train the C-level on deepfake tells
  • Monitor executives' public video exposure
  • Audit the approval flow periodically
  • Simulate the attack with an internal red team

Editorial sources

In the AI era, seeing is no longer believing. Trust becomes protocol, not perception.

← All risk analyses · Blindfy initial assessment