Rethinking Trust in a World of Deepfakes.
A finance worker in Arup’s Hong Kong office was tricked by a deepfaked video call and email chain impersonating the CFO and colleagues, making 15 transfers totaling about HK$200 million (US$25M) to five accounts; the fraud was discovered only after a casual check with headquarters, and two years later no funds were recovered and no one charged.
This week's bulletin argues detection is structurally doomed because GAN-style generators adapt to evade discriminators, lab-grade detectors fail in real conditions, and deepfakes create a “liar’s dividend” that undermines evidence, with studies and legal cases showing denials can preserve support and raise doubt.
It advocates redesigning processes via out-of-band verification, safe words, meeting needs through secure channels, bank controls and liability shifts, passkeys that prevent phishing, provenance standards like C2PA Content Credentials, and zero-trust principles that reduce reliance on human judgment.
