Leadership | September 1, 2026
Generative AI has broken a leadership shortcut that organizations used without naming it: familiar face plus familiar voice equals authentic authority. When executives can be convincingly impersonated, the answer is not to suspect everyone. It is a system in which consequential authority can be verified without rank, urgency, or secrecy overriding judgment.
By Frank Farnel | Responsible Public Affairs | Research cut-off: September 1, 2026, 04:00 UTC
Executive summary
- Executive impersonation is no longer an email problem. Criminals can combine cloned voices, manipulated video, copied profile images and credible organizational context to simulate the social experience of receiving an instruction from senior leadership.
- The core vulnerability is cultural. Fraud succeeds when urgency, confidentiality and hierarchy suppress normal challenge. A flawless deepfake is not required if employees already believe that senior requests should be obeyed quickly and discreetly.
- The evidence contains both failure and resilience. Arup confirmed that its Hong Kong operation lost HK$200 million after a fraudulent video conference. Attempts involving WPP, Ferrari and LastPass failed because employees noticed a channel or behavioral anomaly, paused and verified.
- Organizations need four proofs for consequential instructions: proof of identity, proof of intent, proof of authority and proof of action. A face on a call may contribute to identity, but it cannot satisfy the other three.
- Leaders must surrender the privilege of exceptional process. If a chief executive can bypass dual approval by invoking secrecy or urgency, an impersonator inherits the same power. Good leadership makes verification an expected form of professionalism, not an act of disloyalty.
The authority signal has been separated from the authority
Organizations have always used proxies for authority. A signature, a voice on the telephone, an email address, a face in a meeting and knowledge of confidential context all allowed people to decide that an instruction was genuine. None was perfect. Together, they usually felt persuasive.
Generative AI changes the cost and quality of imitation. Public interviews provide voice material. Conference videos provide facial movement. Professional networks reveal reporting lines. Corporate announcements supply transaction language. A compromised account or copied profile picture supplies the invitation. The attacker does not need to invent an executive from nothing; the organization has already published most of the raw material.
The result is more than a cybersecurity threat. It is a leadership problem because the attack uses the organization’s own authority architecture. The criminal borrows the executive’s urgency, confidentiality, status and presumed access to strategy. The employee is not merely fooled by pixels. The employee is placed inside a familiar power relationship and encouraged to behave exactly as the culture has taught.
INTERPOL and the United Nations Office on Drugs and Crime made this development a central issue at their March 2026 global fraud summit, noting that generative AI, including deepfake video, audio and chatbots, makes it easier to impersonate trusted people and defraud victims. [1] The FBI’s 2025 Internet Crime Report recorded more than $20 billion in reported losses across cyber-enabled crime, with business email compromise among the largest loss categories. That total is not a deepfake-loss figure, but it shows the scale of the financial environment into which synthetic impersonation is being introduced. [2]
The leadership question is therefore not whether employees can learn to spot every fake. They cannot. It is whether the organization can prevent apparent authority from becoming executable authority without independent proof.
A theory of zero-trust leadership
The phrase zero trust comes from cybersecurity. NIST defines zero-trust architecture as an approach that grants no implicit trust to a user or asset solely because of location, network or ownership; authentication and authorization remain discrete decisions. [3]
Applied to leadership, the principle needs careful translation. It does not mean that colleagues should distrust one another, that every conversation requires forensic examination or that relationships no longer matter. It means that recognition is not authorization. The more consequential the requested action, the less the organization should rely on a sensory impression or hierarchical cue.
A useful model separates four proofs:
- Identity: Is the person who they appear to be? A corporate account, authenticated device or known callback channel can contribute to the answer.
- Intent: Did that person actually issue this specific instruction? A real account can be compromised, and an old recording can be reused.
- Authority: Is the person entitled to authorize this class of action? Chief executive status does not necessarily confer unilateral authority to change bank details, release protected data or override sanctions controls.
- Action: Has the requested transaction passed the approvals, segregation of duties and technical controls required for execution?
A convincing face can answer only part of the first question. It cannot prove intent, organizational authority or a properly approved action.
This model changes the employee’s task. Instead of deciding whether a video “looks fake,” the employee asks whether the request is independently valid. That is a more durable question because it remains useful even when synthetic media becomes impossible to distinguish reliably in real time.
Case one: Arup and the cost of simulated consensus
What is established
In early 2024, a finance employee in Hong Kong received messages concerning a confidential transaction and joined a video conference that appeared to include senior company officers. Hong Kong police said the employee made 15 transfers to five local bank accounts totaling HK$200 million—about US$25.6 million at the time. The employee discovered the fraud after contacting headquarters. Police classified the case as obtaining property by deception. [4]
Arup later confirmed that it was the company involved. Its global chief information officer said the attack had not compromised the firm’s internal systems and that the frequency and sophistication of attacks had been rising. In a later discussion published by the World Economic Forum, Arup emphasized cyber resilience and organizational learning rather than treating the event as an isolated technical anomaly. [5]
What the case teaches
The most important feature was not one fake chief financial officer. It was the simulation of a meeting. Multiple apparently familiar participants created social confirmation. The employee did not face a lone, improbable request; the employee appeared to witness a group of senior colleagues accepting the same confidential transaction.
Analysis This is simulated consensus. It attacks a common organizational heuristic: if several credible people are present and nobody objects, the request must be legitimate. In real meetings, silence is already a weak indicator of agreement. In a synthetic meeting, silence can be programmed.
The case also shows why deepfake-detection training alone is insufficient. An employee under time pressure cannot be expected to evaluate lip synchronization, compression artifacts and vocal cadence while senior figures appear to wait. The durable control is procedural: unusual transfers, altered beneficiaries and confidential transactions require independent verification and approval outside the meeting in which they are requested.
Limitation The public record does not reveal every internal control, the exact technical construction of the conference or the complete recovery position. It would be unfair to infer individual negligence from the published facts. The defensible conclusion is narrower: apparent collective authority resulted in transactions that the real organization had not authorized.
Case two: WPP and the value of behavioral inconsistency
What is established
In May 2024, WPP chief executive Mark Read warned senior colleagues that criminals had attempted to impersonate him. According to reporting based on Read’s internal warning, the attackers created a WhatsApp account using a publicly available photograph, used a cloned voice and incorporated YouTube footage into a Microsoft Teams meeting. They sought to persuade an agency leader to help establish a new business and provide money or personal information. The attempt failed. [6]
Why the attempt failed
The attack reproduced elements of Read’s identity, but the pattern of behavior did not fit. An unfamiliar channel, a special project, an unusual request and pressure toward confidentiality created a mismatch between the apparent person and the expected process.
That distinction matters. As synthetic media improves, visual anomalies will become less reliable. Organizational anomalies remain available: the chief executive does not normally use this account; acquisitions do not begin this way; personal documents are not gathered through this route; the executive has not asked this person to establish a business before.
Analysis Leaders create a behavioral signature through routine. Consistent channels, known delegation patterns and respect for controls make impersonation harder. Executives who routinely use personal messaging applications, demand exceptions or create secret projects inadvertently train the organization to accept the exact conditions attackers will imitate.
Read’s decision to alert colleagues also demonstrates a leadership response. Public embarrassment can tempt organizations to conceal failed attempts. Sharing the pattern turns one employee’s suspicion into collective defense. An unsuccessful attack is valuable intelligence if leaders make it discussable.
Case three: LastPass and the power to ignore the CEO
What is established
On April 10, 2024, LastPass disclosed that an employee had received calls, text messages and at least one voicemail on WhatsApp containing an audio deepfake of chief executive Karim Toubba. The employee recognized that the channel and forced urgency were inconsistent with normal business practice, ignored the messages and reported the incident to the internal security team. LastPass said the attempt had no impact on the company. [7]
The real control was cultural
Technology played a role, but the decisive control was permission not to comply. The employee treated an apparent CEO instruction as a signal to evaluate, not an order that suspended judgment.
Many organizations encourage staff to report phishing while preserving a culture in which senior executives expect immediate response. Those messages collide when an attacker impersonates the executive. The employee must choose between security training and perceived career risk.
Analysis A reporting channel works only if employees believe that false alarms are acceptable. If people are criticized for delaying a legitimate request, they will learn to comply with the next illegitimate one. Leaders must make the cost of verification explicit: a short delay is an authorized control, not a failure of responsiveness.
The LastPass case also shows that sophisticated media can be defeated by ordinary context. WhatsApp was not the expected route. Urgency was unexplained. The request arrived outside a familiar workflow. Strong culture converts those inconsistencies into action.
Case four: Ferrari and the limits of personal security questions
What is established
In July 2024, a Ferrari executive received WhatsApp messages and a call appearing to come from chief executive Benedetto Vigna. The caller referred to a confidential acquisition and used AI to imitate Vigna’s voice. Suspicious of small inconsistencies, the executive asked a question linked to a book Vigna had recently recommended. The caller could not answer and ended the call. The attempted fraud failed. [8]
A successful interruption—not a complete system
The employee’s question was intelligent because it shifted verification away from the compromised channel. It tested recent shared context the attacker apparently lacked. The episode illustrates the value of personal knowledge and the courage to interrupt apparent authority.
It should not, however, become a blueprint based on secret questions. The UK National Cyber Security Centre warned in its 2025 review that data breaches are eroding the value of personal information—previous addresses, schools and other “secret answers”—for secure identity verification. [9] Social media and corporate biographies make many personal details discoverable; a conversational model may infer others.
Balanced assessment The Ferrari response was an excellent improvised stop. A mature organization should not depend on improvisation. The verification question should be replaced or reinforced by a trusted callback, cryptographic authentication, a pre-agreed code that is regularly changed, and transaction controls that no voice can override.
From recognition to authorization: a decision matrix
| Request level | Examples | Minimum proof | Independent control | Stop condition |
|---|---|---|---|---|
| Routine | Schedule change, ordinary information request | Authenticated corporate channel | Normal workflow record | Unexpected external channel or unusual data request |
| Sensitive | Confidential document, new counterparty, personnel data | Identity plus explicit confirmation of intent | Callback through a known directory or authenticated approval | Secrecy used to prevent normal confirmation |
| High consequence | Payment, beneficiary change, credential reset, privileged access | Identity, intent and role authority | Dual approval and technical separation of duties | Any attempt by one person—regardless of rank—to bypass controls |
| Exceptional | Acquisition, crisis payment, sanctions-sensitive action, major disclosure | Full authorization chain | Legal/finance validation, board or committee authority where required | Urgency unsupported by a documented emergency procedure |
Key evidence
- HK$200 million: amount transferred in the Hong Kong deepfake-conference fraud later confirmed by Arup. Police said the employee made 15 transfers to five accounts. Source
- November 13, 2024: FinCEN issued a formal alert to financial institutions on fraud schemes involving deepfake media and generative AI. Source
- May 15, 2025: the FBI warned that malicious actors were using AI-generated voice messages to impersonate senior U.S. officials. Source
- More than $20 billion: total cyber-enabled crime losses reported to the FBI’s IC3 in 2025; this is not a deepfake-only figure. Source
- March 16–17, 2026: INTERPOL and UNODC’s global fraud summit identified deepfake video, audio and chatbots as tools making trusted-person impersonation easier. Source
What leaders should do now
Declare that rank cannot waive verification
The chief executive and board should state plainly that no leader will ask an employee to bypass financial, legal, security or data controls through an informal channel. This promise must survive a real crisis. One genuine exception can validate dozens of future imitations.
Create a trusted route for executive confirmation
Use corporate directories, authenticated applications and known devices. Verification must move to a channel selected independently by the recipient—not a telephone number, link or participant supplied inside the suspicious request. A callback is useful only when the callback data itself is trusted.
Separate identity from transaction approval
Even a genuinely authenticated executive should not be able to authorize and execute a high-risk action alone. Dual approval, beneficiary cooling-off periods, privileged-access controls and bank confirmation protect against both impersonation and compromised real leaders.
Design a confidentiality protocol
Secrecy is legitimate in acquisitions, investigations and sensitive personnel matters; it is also a favorite instrument of fraud. Confidential workflows should specify who can confirm the matter, which approval records remain mandatory and how an employee can challenge a request without broadening disclosure.
Train with hierarchy, not only with artifacts
A useful exercise does not merely show a bad video. It places employees under realistic pressure from an apparent senior leader and tests whether they pause, verify and report. Include executive assistants, finance, legal, public affairs and technology teams, since attackers often target people who understand leadership routines.
Reduce the executive attack surface
Public leadership is part of the job, and executives should not disappear from legitimate communication. Organizations should nevertheless inventory high-quality voice and video, remove obsolete material they control, limit unnecessary personal detail and brief families and assistants. Reduction will not eliminate cloning; it raises the preparation cost.
Reward the interruption
When an employee challenges a legitimate instruction, the leader should visibly thank them for following the process. That moment defines culture more powerfully than annual training. If verification produces irritation or retaliation, the organization has announced which behavior it truly values.
The balanced risk: security without organizational paralysis
A badly designed response can make ordinary leadership unworkable. Requiring multiple authentication rituals for every conversation creates friction, workarounds and cynicism. Employees may begin treating all executive communication as suspect; leaders may migrate to informal channels to recover speed.
The answer is proportionality. Routine instructions can rely on authenticated corporate tools. Sensitive requests need independent confirmation. High-consequence actions require structural approvals that no individual can waive. The control attaches to the requested action, not to a generalized belief that all media is fake.
Technology also has a role. Content provenance, liveness detection, secure identity systems and anomaly monitoring can help. None should become a new single point of trust. Detection tools can generate false positives and may lag behind new methods. The system should remain safe even when a synthetic face is not detected.
There is a further leadership danger: the “liar’s dividend.” As manipulated content proliferates, a person can dismiss authentic evidence as fake. NIST notes that synthetic media can erode trust in valid information as well as create false content. [10] Organizations therefore need protected records of genuine decisions—authenticated minutes, signed approvals and reliable audit trails—not only tools for identifying false media.
Conclusion: authority must become verifiable
The Arup fraud succeeded because criminals reproduced not only executives but the experience of collective authority. The WPP, LastPass and Ferrari attempts failed because someone noticed that the apparent leader did not fit the expected channel, behavior or shared context—and had permission to stop.
That permission is the heart of the leadership response. Employees should never have to decide between respecting hierarchy and protecting the organization. A legitimate executive can wait for verification. An urgent transaction can survive dual approval. A genuinely confidential project can use a confidential control process.
The face on the screen still matters. Voice, relationship and human judgment still matter. They simply cannot carry the full burden of proof.
In the synthetic-media era, credible leaders will be recognized not by their ability to command immediate obedience, but by the systems they build so that even their own apparent instructions can be safely questioned.
References and further reading
Official and institutional sources
- INTERPOL, “INTERPOL–UNODC global summit ends with call to action against fraud surge,” March 17, 2026. Direct link.
- Federal Bureau of Investigation, 2025 Internet Crime Report, published 2026. Direct PDF.
- FBI Internet Crime Complaint Center, “Senior U.S. Officials Impersonated in Malicious Messaging Campaign,” May 15, 2025. Direct link.
- Financial Crimes Enforcement Network, “FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions,” November 13, 2024. Direct link.
- National Institute of Standards and Technology, Scott Rose et al., Zero Trust Architecture, NIST SP 800-207, August 2020. Direct link.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, July 2024. Direct PDF.
- UK National Cyber Security Centre, “The future of digital identity,” NCSC Annual Review 2025, October 14, 2025. Direct link.
Corporate primary material and documented cases
- LastPass, Mike Kosak, “Attempted Audio Deepfake Call Targets LastPass Employee,” April 10, 2024. Direct link.
- World Economic Forum, “Cybercrime: Lessons learned from a $25m deepfake attack,” including Arup CIO Rob Greig, February 4, 2025. Direct link.
- South China Morning Post, “Multinational firm’s Hong Kong office loses HK$200 million after scammers stage deepfake video conference,” February 4, 2024. Direct link.
- Financial Times, “WPP boss targeted by deepfake scammers using voice clone,” May 10, 2024. Direct link.
- Daniele Lepido, “Ferrari Narrowly Dodges Deepfake Scam Simulating Deal-Hungry CEO,” Bloomberg News, July 26, 2024. Direct link.
Glossary
Business email compromise (BEC): A fraud in which criminals impersonate or compromise a trusted business identity to induce a payment, data disclosure, or account change. The method now extends beyond email.
Deepfake: Synthetic or manipulated audio, image or video generated to make a person appear to say or do something they did not.
Out-of-band verificationConfirmation through a separate, independently selected and trusted channel rather than the channel carrying the request.
Segregation of duties A control dividing initiation, approval and execution so that one person cannot complete a high-risk action alone.
Zero trust: A security principle under which trust is not granted implicitly from location, ownership or appearance; identity and authorization are evaluated explicitly.
Source and methodology note
Established facts include reported loss amounts, transfer counts, disclosed attack channels and dates, and the outcomes reported by the companies or law-enforcement sources. Analysis applies those cases to leadership, culture and decision rights. The term “zero-trust leadership” is an analytical adaptation of a cybersecurity principle, not a NIST leadership standard.
Public evidence does not permit a complete technical reconstruction of every incident. Arup’s internal control environment and final recovery position are not inferred. WPP and Ferrari case details rely partly on reporting from internal communications or people familiar with the incidents. The 2025 IC3 total covers all reported cyber-enabled crime and must not be presented as a deepfake-loss statistic. Reported crime data understate unreported events and should not be treated as prevalence estimates.
Suggested internal links
- The Right to Stop: Why Real Leaders Build Systems That Can Overrule Them
- The Apology Is Not the Repair: What Leaders Must Rebuild After Institutional Failure
- Trust: The Key Asset in Public Affairs
- How to Build a Defensible Public Policy Position
#Leadership #DeepfakeRisk #CorporateGovernance
Discover more from Responsible Public Affairs
Subscribe to get the latest posts sent to your email.