Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

AI Video Tool Synthesia Accused of Lacking Oversight: Avatar Abuse Fuels BEC Scams

Victims are primarily corporate financial officers, cashiers, multinational business executives, and general employees. Accustomed to video conferencing as an authoritative source for executive directives, they often lack the awareness to verify the faces and voices of 'bosses' on screen. Their psychological vulnerabilities include a tendency to obey authority, fear of being held accountable for delaying orders, and mistaking technical glitches for authentic signals, leading them to skip secondary verification before urgent wire transfers.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal(欧美为主,全球蔓延)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are primarily corporate financial officers, cashiers, multinational business executives, and general employees. Accustomed to video conferencing as an authoritative source for executive directives, they often lack the awareness to verify the faces and voices of 'bosses' on screen. Their psychological vulnerabilities include a tendency to obey authority, fear of being held accountable for delaying orders, and mistaking technical glitches for authentic signals, leading them to skip secondary verification before urgent wire transfers.

骗局怎么运作

  • Criminal groups purchase or subscribe to AI video synthesis services like Synthesia, using publicly available board photos and meeting recordings to generate digital avatars of executives. These tools allow users to upload templates and audio to automatically generate lip-synced videos, with high-fidelity content producible even during free trials. Platform customer service often uses marketing language like 'Create your digital employee with just one video and one audio clip,' misleading users about the boundaries of legal use.
  • Attackers collect facial data, voiceprints, and speech patterns of target executives via LinkedIn, corporate websites, and earnings call videos to train personalized AI models. Such public data can be scraped without authorization, and platforms like Synthesia do not mandate that uploaders prove portrait rights in their user agreements. Dark web forums openly discuss the technical path of 'cloning a CEO in 30 minutes using public videos.'
  • Attackers forge video conference invitations, sending meeting links to finance departments via spoofed domains or compromised corporate emails. In the video, the 'CEO' issues instructions for an 'urgent acquisition' or 'confidential project' from a meeting room. This step uses deepfake visuals overlaid on real Zoom or Teams interfaces to bypass visual scrutiny, while emails replicate internal corporate jargon and emphasize that 'this transaction has been approved by the board and must remain confidential.'
  • During the video call, attackers play pre-recorded content or provide simple responses, pressuring finance staff to transfer funds to designated accounts within hours. By leveraging time pressure and the 'executive presence' scenario, they force employees to bypass standard approval processes. The avatars even respond to challenges like 'Why are we changing the payee?' to increase credibility. Common scripts include 'I'm on vacation, but this deal can't wait; please use the emergency payment channel immediately.'
  • Once successful, the funds are immediately split into multiple small cross-border transfers, and meeting records and email traces are deleted. Some banks lack AI-based risk control for cross-border remittances, allowing funds to flow into money-laundering accounts within 30 minutes. Criminals instruct finance staff to use generic descriptions like 'investment' or 'consulting fees' in payment notes to evade transaction monitoring and subsequent audits.

红旗信号(看到这些快跑)

  • 🚩 Flickering edges around the person's face, abnormal blinking frequency, or lip-syncing that does not match the audio—these are the most common flaws in deepfakes, identifiable by the naked eye or slow-motion playback.
  • 🚩 Meeting links originating from strange domains that do not match the sender's name, or corporate email domains with an extra letter (e.g., 'company.co' instead of 'company.com').
  • 🚩 The caller demands 'absolute confidentiality' and 'immediate execution,' while refusing to confirm with a second colleague, using urgent scripts to suppress rational thinking.
  • 🚩 The receiving account is a personal account or a newly registered overseas company rather than the supplier account on file, and the payee name does not match the business nature.
  • 🚩 After the video call, the person refuses to take phone calls or cannot be reached through other channels, yet continues to urge payment via email or chat tools, creating an anomaly of 'hearing the person but never getting a callback.'

真实案例

  • According to 2024 reports, a criminal group of about 70 operators used industrial methods to impersonate the CEO of a multinational corporation, forging executive identities in video calls to orchestrate a fraudulent transaction involving 140 million euros. Victims included several European manufacturing companies, and funds were split into hundreds of transfers to overseas accounts within three weeks.
  • In 2023, a criminal group spliced old videos of an overseas political figure to forge footage of them attending a Zoom meeting. Using this identity, they sent urgent funding requests to politicians and businesses in multiple countries, stealing nearly 5 million RMB. The case showed that attackers do not need real-time synthesis; they can create an 'online presence' illusion simply by editing old footage.
  • In 2026, a university student in China used AI face-forgery technology to impersonate others and complete facial recognition verification on a financial platform, stealing over 50,000 yuan. Police investigations into the black market revealed that video synthesis tools were being sold with clear price tags, with some sellers offering customized 'meeting avatar' services, mirroring BEC scam techniques.
  • In March 2024, Southern Metropolis Daily reported that Hong Kong police disclosed the city's first multi-person AI face-swap scam. An employee at a multinational company's Hong Kong branch was invited to a multi-person video conference initiated by the headquarters' CFO. Following instructions, they transferred 200 million HKD in 15 installments to 5 local bank accounts. They only realized they had been scammed after checking with headquarters. The scammers downloaded videos from YouTube and used Deepfakes to forge the meeting footage. (Source: https://m.mp.oeeee.com/a/BAAFRD000020240301916066.html)
  • In May 2023, the Baotou Public Security Bureau's Cybercrime Investigation Division released details of an AI-powered telecom scam. On April 20, a tech company executive in Fuzhou was contacted by a 'friend' via WeChat video, who requested a 4.3 million yuan deposit for a bid. The scammer used AI face-swapping and voice-mimicry technology to pose as the friend, stealing 4.3 million yuan in 10 minutes. Police in Fuzhou and Baotou successfully intercepted 3.3684 million yuan. (Source: https://www.fjdaily.com/app/content/2023-05/23/content_1893368.html)

Official Stance

  • On June 22, 2026, Xinhua News Agency published a special report titled 'Xinhua Investigation: Unveiling the Black Market of AI Face-Swap Scams,' systematically exposing how criminal groups use deepfake tools to mass-produce scam materials and warning businesses and individuals to remain vigilant regarding wire transfer instructions during video calls.
  • In 2026, Xi'an police announced the dismantling of a criminal group that used AI to mass-generate fake videos to attack companies. Four people were criminally detained, and all involved accounts were deactivated. Police warned that using AI synthesis for extortion and commercial fraud has entered an industrialized stage, and companies should establish counter-measures.
  • On September 2, 2026, Sina Finance cited regulatory authorities in naming a series of AI application irregularities, including the 'malicious modification' of classics and the impersonation of public figures. Regulators demanded that relevant platforms implement deep synthesis content labeling and user real-name verification, or face legal consequences.

How to Protect Yourself

  • ✅ Establish a dual-verification system: Any wire transfer instruction during a video conference must be confirmed via an independent phone call or in-person, using a 'passphrase' known only to internal executives for identity verification.
  • ✅ Deploy deepfake detection tools, such as Microsoft's video authenticator or Intel's FakeCatcher, to automatically analyze facial pixel changes and blood flow signals, scanning participants before meetings begin.
  • ✅ Strengthen email security: Enable domain verification (SPF, DKIM, DMARC) and mandatory two-factor authentication. Regularly monitor for spoofed domains and add red external warning labels to emails from channel partners and suppliers.
  • ✅ Conduct quarterly anti-scam drills simulating 'AI executive video conference' attacks. Allow finance staff to identify forgery characteristics in practical scenarios and incorporate drill results into departmental performance evaluations.