Your phone rings and you see it's your wife calling. You pick up and you hear her say:
"I've been kidnapped. They have the kids. Do exactly what they say."
And then a scream.
A dark, gravelly voice then says: "You pay £30,000 into this account, or you never see them again. We are watching you. You call the police, say goodbye. The bank account is in your text messages."
The phone goes dead.
Petrified and panicking, your head agonising over the scream you just heard, your brain racing with thoughts, you hurriedly make the transaction and text.
"Done. Paid. Where are they?"
Meanwhile, your wife and kids are happily at the shopping centre, completely unaware you have just transferred £30k to scammers using AI voice technology to mimic your wife.
They got her voice using Facebook and Youtube. They knew you had kids and chanced it. It was all over so fast, in your vulnerable state, you were stung.
It was widely reported that US mother Jennifer DeStefano told the US Senate about a version that reached her, where she heard what she believed was her daughter sobbing while a man demanded a million dollars, negotiating down to $50,000 while her daughter sat safely on a school ski trip.
The FBI advises that if you receive a message like this, verify that your person is safe before considering anything else. Faked proof-of-life images often carry small tells such as a missing tattoo, an odd background or a birthmark in the wrong place.
AI scams are here, and they are fooling people everywhere. They work just as well on companies.
A finance worker in Arup's Hong Kong office received an email from the company's UK CFO asking him to handle a confidential transaction. He was suspicious, which is exactly what his training had taught him to be, so he asked for a video call.
The CFO was on the call. So were several colleagues he recognised. They looked and sounded right, and they confirmed the request in real time, so he made 15 transfers totalling around $25m.
But every person on that call was an AI fake. He was the only real one in the room.
Arup's CIO later confirmed that none of the company's systems had been compromised and no data was taken. The attackers built their fakes out of video and audio the company had already published.
Deepfakes can be very bad for your bank account.
Quality scams
The quality of the scam that can be run against you is set by the quality of the data available about you.
When I started writing about data governance today (part of the Executive Summary's AI Strategy Triangle series I am powering through), I fell asleep, dribbled a bit and wished I could be on holiday.

I couldn't bring myself to build a new framework without showing you the implications of weak data governance.
Because governance is a dull word for something quite important. It covers who inside your company can see and do things with your data, and where that data can go.
AI tools have made this an utter nightmare, both in what you lazily leak out of the company and the sudden high volume of deepfake scams.
So no, we're not really doing data governance today.
Now do this
At work
- Be careful of people asking you for things when you can't see them.
- On video calls, if you're unsure, ask the person to hold up three fingers and do some weird finger puppet stuff. AI struggles with that for now.
- If someone asks you to move money, hang up and ring them back on a number you already have. Every time, however senior they are.
- Decide the amount above which that phone call is compulsory, then tell everyone who can pay an invoice.
- If you're an employee, scammers wait for you to put your job on LinkedIn. Then they email you (firstname.lastname@) pretending to be your boss asking you to WhatsApp them directly. They ask you to buy vouchers and expense it. Don't fall for it.
- Agree who speaks for the company if a fake version of your staff turns up in front of customers.
At home
- Agree a safe word tonight with your family in case you get a scam call. If a call is about money or an emergency, hang up and ring the person back on the number in your phone. Every one of these scams needs you to stay on the line.
- Never say a name on the phone. These calls often start with a scream and no name, and the frightened parent supplies it. Test it out if you're unsure with a fake name.
- Tell your parents about this properly rather than assuming they have read about it. Older folks lose the most money to this and are the least likely to have heard. Grandparents are often conned with deepfakes. Get your grandkids to build a deepfake and show their grandparents how it works.
If you're trying to find your way on AI as a leadership team or an organisation, give me a buzz. I'll help you get there faster.
Have a nice evening.
Dan x
Subscribe