Purportedly AI-Generated Deepfake Reportedly Used to Impersonate DNB Bank CFO and CEO in Live Teams Meeting

Cybercriminals attempted to defraud DNB Bank's Singapore office by using deepfake video and audio to impersonate the bank's CEO and CFO during a live Microsoft Teams meeting. The attackers requested a multi-million dollar wire transfer, but bank employees identified the fraud and avoided financial loss. DNB security officials noted that the deepfakes were created using publicly available footage and highlighted the increasing accessibility of such tools for criminal activity.

Unknown cybercriminals reportedly used purported deepfakes to impersonate DNB Bank's CFO and CEO during a live Microsoft Teams meeting, instructing employees at the bank's Singapore office to transfer millions of Singapore dollars. The video and voice were allegedly cloned from public footage and appeared convincing. DNB identified the attempt as a "CEO fraud" and avoided losses, calling it their first encounter with a live deepfake meeting.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation

The incident involves cybercriminals using deepfake technology to impersonate bank executives in a live meeting to execute a targeted CEO fraud scam.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The incident was caused by human malicious actors who intentionally deployed deepfake technology post-deployment to execute a financial scam.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Risk Level 3: Limited Risk. The report describes the use of deepfakes, which are AI-generated content subject to transparency obligations under the EU AI Act.

AI system and alleged parties

  • AI system: unspecified
  • AI purpose: Deepfake Video Generation; Voice Generation
  • Behaviour type: Tool
  • Alleged developer: Unknown voice cloning technology developers, Unknown deepfake technology developers
  • Alleged deployer: Unknown scammers impersonating DNB Bank officials, Unknown scammers
  • Alleged harmed parties: Kjerstin Braathen, Ida Lerner, DNB Bank employees, DNB Bank

Harm severity

Highest direct severity in any category: Negligible. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Negligible, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Negligible, indirect Negligible
  • Psychological: direct Negligible, indirect Negligible
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

People affected

  • Occurrences reported: 1
  • People reportedly exposed: 5

Potential causes

Management

  • Active Monitoring Decision: Security chose to proceed with the suspicious call to study attacker methods.

Technology

  • Accessible Deepfake Tools: Cheap or free AI tools allow creators to synthesize realistic media easily.
  • Live Stream Deepfake Injection: Attackers successfully fed real-time deepfake feeds into a Teams meeting.

Data Inputs

  • Publicly Available Media: Public executive video and audio recordings were harvested to train the AI.

Human Factors

  • Overreliance on Visual Cues: Observers initially trusted the meeting due to familiar faces and voices.

Process and Methods

  • No Meeting Verification Protocol: There was no official process to verify the identity of video call hosts.
  • Out-of-Band Communication: Initial contact via WhatsApp bypassed secure corporate communication channels.

Regulatory Environment

  • Unregulated Generative AI: Lack of strict regulatory oversight on the creation of deepfake software.

Information quality

  • Classification confidence: High
  • Reason for confidence: The report is highly detailed, coming directly from DNB executives and security personnel who experienced and analyzed the attack. The sequence of events, the detection method, and the lack of financial loss are clearly documented.
  • Ambiguities identified: The exact software used to generate the deepfakes is not specified, only that such tools are easily accessible online.
  • Alternative interpretations: None. The event is clearly a targeted CEO fraud attempt using synthetic media.

Cybercriminals targeted DNB Bank's Singapore branch using real-time deepfake video and audio of the CEO and CFO during a live Microsoft Teams meeting to solicit a multi-million dollar transfer. The attempt was detected and blocked by bank staff, resulting in zero financial loss. This incident demonstrates an evolved capability in AI-enabled financial fraud.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Multiple nations
  • Primary target: Singapore
  • Other affected: Norway
  • Alleged perpetrator: Unknown

Threat characteristics

  • Imminence: Long-term. The active incident has concluded with no loss, representing an ongoing strategic concern regarding deepfake capabilities rather than an active crisis.
  • Autonomy: Human-controlled. The AI tool was directly controlled and deployed by human scammers to generate and loop media during a live call.
  • Novelty: Evolved capability. Represents an advancement of existing CEO fraud techniques by utilizing real-time, interactive deepfake video and audio during a live video conference.

Impact by dimension

  • Physical security: Negligible. No physical systems, kinetic threats, or critical infrastructure were targeted or affected in this commercial banking fraud attempt.
  • Information security: Minor. Involves deepfake impersonation of corporate leadership, but was a localized financial scam rather than a state-sponsored intelligence or disinformation campaign.
  • Sovereignty: Negligible. No government systems, sovereign decision-making, or state functions were targeted or disrupted.
  • Economic security: Minor. Attempted multi-million dollar fraud against a financial institution, but zero financial loss occurred due to successful detection by bank staff.
  • Societal stability: Negligible. No impact on civil liberties, societal stability, or human rights; isolated incident targeting a specific corporate entity.
Explore in the interactive Incident Tracker