When Seeing Is No Longer Believing

In January 2024, an employee in Arup’s Hong Kong office received instructions concerning a confidential transaction that appeared to come from the engineering group’s UK-based chief financial officer. The employee initially suspected that the message might be fraudulent, so a video conference was arranged with people who appeared and sounded like the CFO and several other colleagues.

The meeting provided the reassurance that the original email had failed to provide. The familiar faces, voices and apparent participation of several senior executives created the impression that the instruction had been independently confirmed. The employee subsequently made 15 transfers totalling HK$200 million to five Hong Kong bank accounts.

The other apparent participants in the meeting had been digitally created. Artificial intelligence had allowed the fraudsters to reproduce the voices and images of senior colleagues and place them together in what appeared to be a live management discussion.

The case attracted worldwide attention because it challenged one of the assumptions on which modern international business depends. An email might be treated cautiously, while a live conversation with recognised colleagues had traditionally provided a much stronger form of confirmation. The Arup incident showed that an email, a familiar voice, a recognisable face and a group video conference could all originate from the same fraudulent source.

The technology was new, although the underlying objective remained familiar. The fraudsters wanted an employee to transfer genuine company money to accounts under their control, using authority, urgency and apparently authentic communication to overcome normal caution.

Two earlier frauds involving companies operating in Vietnam show how the same threat developed through compromised email systems, and how the outcome depended upon the treatment of supplier bank-account changes.

The account in Poland

On 11 September, the finance director of a manufacturing company in Vietnam received a request involving a Chinese supplier that was building a machine containing strategic components required to address a production shortage.

The supplier relationship was genuine, the machine was genuinely under construction, and the production requirement was urgent. Emails from the supplier described progress, requested an initial payment of €103,000 and warned that delays could affect completion and delivery.

The payment request contained one significant change. The supplier wanted the money sent to a different bank account.

The existing account was held with an international bank in Amsterdam, while the replacement account was with the same banking group in Katowice, Poland. The explanation provided through the email correspondence was that an audit had begun and that the Amsterdam account had been frozen.

The finance director had introduced a control requiring every supplier bank-account change to be put forward by the head of procurement and approved by the finance director. The rule brought the proposed amendment into view before somebody in the accounts department could treat it as routine supplier maintenance.

The timing immediately caused concern. The bank-account change appeared at the same moment as a rush order intended to resolve a production shortage. The company needed the machine, the supplier appeared to be waiting for payment, and any delay could potentially affect production.

The finance director held the payment.

The decision rapidly became a commercial issue. Procurement feared that the supplier would stop work, production feared that the shortage would interrupt manufacturing, and the chief executive faced the prospect of delayed output. All the relevant managers worked on the same site, so the disagreement developed through direct conversations and face-to-face meetings.

Procurement produced emails showing that the supplier was requesting payment and applying pressure. The correspondence appeared coherent because the order, machine and delivery problem were all genuine. From the operational perspective, finance seemed to be allowing an unusual banking detail to threaten a strategically important delivery.

The finance director’s concern extended beyond the supplier. Rush orders often create favourable conditions for fraud because urgency limits the time available for checking and places pressure on anyone who delays the transaction. The combination of the rush order, the changed banking jurisdiction and the explanation involving a frozen account raised the possibility that somebody inside the company understood the operational circumstances and was using them.

Several explanations remained possible. An external attacker might have compromised the supplier’s communications, an employee of the supplier might have attempted to divert the payment, or somebody within the procurement function might have been involved. The Polish account created a further line of enquiry, and background checks were carried out on procurement staff to establish whether any personal or commercial connections with Poland existed.

As the weeks passed, the supplier continued to send messages asking for payment. Procurement continued corresponding with people whom they believed to be the supplier’s sales staff, while the pressure surrounding the machine and its delivery continued to grow.

The correspondence presented a convincing commercial story because much of it was genuine.

The attackers had compromised the supplier’s email environment and intervened selectively. Some authentic messages travelled normally between the two companies, while others were intercepted, replaced or removed. Emails about the machine, progress and non-payment often continued because they helped preserve the credibility of the conversation.

Where the attackers substituted a message, they reproduced the genuine commercial content but sent it from an email address containing a one-character variation that nobody initially recognised.

Procurement therefore believed it was communicating with the supplier, while on some occasions it was communicating with the fraudster. The compromised mailbox gave the attackers access to genuine information about the order, allowing them to construct messages that fitted naturally into the real conversation.

The supplier saw a customer that had placed an order and failed to make the expected payment. The customer saw a supplier that was building the machine and insisting that payment should be sent to a newly nominated account. Each side received enough authentic information to sustain its understanding of events.

When all the correspondence was extracted, printed and reviewed in sequence, the evidence initially appeared to increase the suspicion surrounding procurement. The department had exchanged messages with the bogus address, relied on those communications to support the account change and applied pressure for the payment to proceed.

One interpretation was that somebody within procurement controlled the altered address and had used the correspondence to create support for the new bank account. The same evidence also supported another explanation in which procurement staff had acted in good faith while communicating through a channel that had been quietly redirected.

The turning point came when the disputed correspondence was compared with the documents created when the supplier had originally been established. The company had strong controls over new vendor creation, and the original email addresses and bank details had been independently confirmed and retained.

The one-character difference in the fraudulent email address then became visible. Procurement could produce no original onboarding document connecting the altered address to the supplier because the address had never formed part of the genuine relationship.

On 23 October, approximately six weeks after the first request, direct communication with the genuine supplier confirmed that the bank-account instruction had been fraudulent.

The supplier’s email system had been compromised. The attackers had substituted selected messages, filtered communications that could reveal the account change and allowed enough genuine correspondence to continue for both organisations to believe that they remained in contact with each other.

The €103,000 initial payment remained within the company.

The control requiring finance director approval had brought the proposed change into view, while professional scepticism kept the payment on hold throughout six weeks of genuine operational pressure. The investigation also showed that suspicious circumstances can point towards the wrong person. The rush order and procurement’s correspondence with the fraudulent address justified investigation, while the evidence eventually placed the source of the attack inside the supplier’s compromised email system.

The trusted supplier

A similar fraud later occurred at an international solar-energy company with operations connected across Vietnam, China, Japan, Singapore and the United Kingdom.

The company had used the same Chinese supplier for approximately two years, during which shipments worth around US$18 million had been completed successfully. The underlying commercial relationship, equipment purchases, invoices and planned deliveries were all genuine.

The chief executive was based in Vietnam, the financial controller worked in London, the finance director approved payments from another location, funding came through Singapore and the equipment was sourced from China. Each participant depended heavily upon electronic communication and saw only part of the overall transaction.

An attacker compromised the Vietnamese chief executive’s computer or email environment and sent a message that appeared to come from the supplier, instructing the London financial controller to amend the beneficiary bank account.

A delivery problem was already creating commercial pressure. The controller believed that responding flexibly would help operations and keep the equipment moving, so she changed the supplier’s bank details and processed several transfers totalling approximately US$450,000.

The finance director approved the payments against genuine invoices that had already passed through the company’s commercial authorisation process. The information presented for approval showed the liabilities and amounts, while the recent change to the beneficiary account remained outside his view.

The weakness lay in the separation between approving the purchase and approving the destination of the money. The controller could receive the bank-change instruction, amend the supplier record and prepare the payments without ensuring that the finance director consciously reviewed the new beneficiary.

The Singapore bank eventually recovered approximately US$220,000, leaving the company with a loss of around US$230,000.

Commercial pressure influenced both Vietnam cases, although it operated differently. In the manufacturing company, the pressure became visible through face-to-face discussion and the finance director maintained the payment hold. In the solar-energy company, the pressure moved through a geographically dispersed process in which the controller believed that flexibility supported operations, while the finance director saw genuine invoices without seeing the changed account.

Moving the control closer to the payment

For a current manufacturing client, the monthly vendor payment run is now compared with previous months before the file reaches the chief executive for authorisation. AI carries out the review in minutes and  draws attention to changes in bank accounts, material movements in payment values and unusual departures from established payment patterns, giving the chief executive visibility of what has changed rather than presenting only a list of invoices and amounts.

This approach brings supplier master-data changes into the payment approval process. A genuine invoice can support a fraudulent payment when the beneficiary account has been altered, so approval needs to cover both the commercial liability and the destination of the money. Independent verification through previously established contact details remains essential whenever a supplier requests a bank-account change.

Artificial intelligence can strengthen this control by analysing bank locations, email addresses, payment histories, recent master-data changes and unusual expressions of urgency. Its value lies in identifying combinations of signals that deserve investigation, while responsibility for verification and payment release remains with accountable managers.

Across the three cases, the methods became progressively more sophisticated, moving from compromised supplier email to compromised customer email and then to synthetic executives participating in an apparent video conference. The enduring defence remained the same: changes in where money is sent require independent verification through a channel beyond the control of the person requesting the change, supported by professional scepticism and the willingness to delay payment when commercial pressure is greatest.