Stop Detecting Deepfakes: Make the Fraud Irrelevant by Design — SmarterArticles
Stop Detecting Deepfakes: Make the Fraud Irrelevant by Design<br>July 29, 2026
The video call looked entirely ordinary. A finance worker in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House and the Beijing National Stadium, sat in front of a screen filled with familiar faces. The company's chief financial officer, based in the United Kingdom, was there. So were several other colleagues, recognisable, talking, moving, present. There had been an email a few days earlier, supposedly from that same CFO, asking for a confidential transaction. The worker had been suspicious. Emails lie. But now here was the CFO himself, on camera, and the request was repeated with the easy authority of a senior executive. Reassured by what he could see and hear, the employee did as he was asked. Over the following days he made fifteen separate transfers, roughly 200 million Hong Kong dollars in total, around 25 million US dollars, into five different bank accounts.
Every other person on that call was a fabrication. The CFO was a deepfake. The colleagues were deepfakes. The entire meeting, the nods and the small talk and the instructions, had been synthesised from publicly available footage of real Arup staff. The only human being in the room was the victim. The fraud was not uncovered by clever technology or a sharp-eyed analyst. It surfaced later, in the most mundane way imaginable, when the employee happened to check in with the company's actual headquarters about the secret payment he had been making. By then the money was gone. Two years on, none of it has been recovered, and nobody has been publicly identified or charged.
The Question We Keep Answering Wrongly
The instinct, reading a story like that, is to ask how the worker could have been fooled, and then to reach for a solution shaped like a better fool-detector. Train staff to spot deepfakes. Buy software that scans video streams for the tell-tale artefacts of synthesis. Teach everyone the current list of giveaways, the unnatural blinking, the odd lighting around the hairline, the faint smear where a jaw meets a neck. This is the reflex of an entire industry, and it is the wrong reflex. It commits us to an arms race we are structurally certain to lose, and it quietly loads the entire weight of defence onto the least reliable component in any system, which is a human being looking at a screen and deciding whether to believe their own eyes.
There is a different question, and it is the one this piece is about. As synthetic deception becomes not merely good but effectively perfect, should our goal be to get better at spotting lies, or to redesign the relationships and everyday processes that currently depend on our ability to detect them at all? The wager here is that the second path is not only possible but already, quietly, winning in the places where people have had the sense to try it. The trick is a reframing so simple it sounds glib until you follow it through. Treat every incoming request as a requirements problem in which the attacker has helpfully written out their preferred solution in advance. Then refuse that solution and satisfy the underlying legitimate need through a channel the attacker cannot reach.
The stakes are not marginal. Long before deepfake video calls entered the picture, the plainest version of this fraud, business email compromise, in which a criminal impersonates a trusted party to redirect a payment, had become one of the most lucrative crimes on earth. The FBI's Internet Crime Complaint Center titled a 2024 advisory “Business Email Compromise: The $55 Billion Scam,” reflecting more than 55 billion US dollars in reported losses worldwide over roughly a decade. The trend since has not bent downwards. The Bureau's report for 2025 records 1,008,597 complaints and 20.877 billion dollars in reported losses, a rise of 26 per cent on the year before, with business email compromise accounting for 3.05 billion of that total, the second costliest category of cyber-enabled fraud after investment scams. Every one of those losses turned on someone believing a message that appeared to come from a party they trusted.
That report also does something none of its predecessors did. For the first time it puts a number on the synthetic contribution specifically, attributing more than 30 million dollars of business email compromise losses to scams involving AI, and more than 5 million to distress scams in which voice cloning was used to imitate a relative. Those sums look modest beside the totals, and it would be a mistake to read them as the measure of the problem. They are a floor rather than a ceiling. A victim can only report what they noticed, and the entire purpose of a competent synthetic is that nobody notices; a cloned voice that works leaves behind a complaint about an ordinary fraud, if it leaves behind a complaint at all. What the...