€3 Million Gone: How Deepfakes Fooled a Company's Own Bank
Capillary Technologies thought the voice on the call was their own executive. It wasn't. In June 2026, the Bengaluru-based SaaS company disclosed that an overseas subsidiary lost approximately €3 million after attackers used voice cloning, forged signatures, and social engineering to impersonate key company personnel. By the time anyone realized what had happened, the money was already moving to unauthorized accounts.
July 12, 2026
Originally reported by Moneycontrol · Read the original article
- Deepfake fraud is an active business threat, with Capillary Technologies losing €3 million through voice cloning and forged signatures alone.
- Voice cloning requires as little as 20 to 30 seconds of audio, and public sources like earnings calls or LinkedIn videos are enough to create a convincing fake.
- Deepfake fraud attempts increased 500% in 2024, meaning no company size or funding level makes a business immune.
- The core vulnerability in these attacks is identity verification, since phone numbers, emails, voices, and signatures can all be faked by a prepared attacker.
- Shared secrets that are private and frequently rotated are currently one of the most reliable defenses against voice cloning fraud.
The Call Sounded Real. That Was the Point.
Deepfake fraud is no longer theoretical. It's a documented business risk with a growing list of corporate victims.
In February 2024, engineering firm Arup lost $25 million when an employee joined a video call where every other participant was a deepfake. In the Capillary case, attackers didn't even need video. Voice cloning and forged signatures were enough to authorize €3 million in fraudulent transfers.
As of the disclosure, the company had recovered €0.45 million, leaving roughly €2.55 million still missing.
How the Fraud Worked
The attackers combined several techniques. None were especially novel on their own. Together, they were devastating.
Voice cloning produced audio that sounded like Capillary's key managerial personnel. Modern voice cloning requires as little as 20 to 30 seconds of audio to produce a convincing replica, and earnings calls, conference presentations, YouTube videos, and LinkedIn posts all work as source material.
Forged signatures added a paper trail that looked legitimate. When a voice call says "transfer the funds" and a document arrives with a matching signature, the pressure to comply is real.
Social engineering tied it together. The attackers knew enough about the company, its personnel, and its subsidiary structure to make the requests feel routine. That's not luck. That's research.
The result: an overseas subsidiary processed fraudulent transfers to third-party accounts, believing the instructions came from the top.
This Is a People Problem, Not a Tech Problem.
It's tempting to read stories like this and assume they only happen to companies with weak security. That framing misses the point.
Capillary Technologies is a funded SaaS company with institutional backing and professional finance teams. Their overseas subsidiary had processes in place. And still, a cloned voice and some paperwork moved €3 million out the door.
The reason isn't negligence. Humans are wired to trust familiar voices. When your CFO calls and tells you to wire funds urgently, questioning that instruction feels wrong. The attackers knew this and exploited it precisely.
According to the World Economic Forum, deepfake fraud attempts increased 500% in 2024. The technology is getting cheaper, faster, and more accessible, and the gap between what's real and what sounds real keeps narrowing.
The Verification Problem
Every fraud like this comes down to the same core failure: someone couldn't verify they were actually talking to who they thought they were talking to.
This is harder than it sounds. Phone numbers can be spoofed. Email accounts can be compromised. Voices can be cloned. Signatures can be forged. The usual signals of identity don't hold up against a well-resourced attacker.
What does hold up? Shared secrets. Information that only the real person would know, that isn't publicly available, and that changes often enough to be useless if stolen.
Businesses have used callback procedures and verification codes for decades. Families haven't had a reliable equivalent. Until now.
Three Words the Clone Can't Know
Trust Onion gives families a simple verification system: three rotating codewords, calculated locally on your phone, that change every few hours. When someone calls claiming to be a family member, you ask: "What are the words?"
If they can't answer, the call is over.
The words are never sent to a server. They work offline. They expire on a schedule, so even if someone overheard yesterday's words, those words are already gone. Because the words come from a shared secret known only to your group, no amount of voice cloning, social engineering, or signature forging can produce them.
The Capillary fraud succeeded because the people who received those calls had no quick, reliable way to confirm they were talking to the real executive. A shared verification word changes that entirely. "Hey, before I process this transfer, what are the words?" is a sentence that stops a cloned voice cold.
Trust Onion was built for families, not corporations. But the logic is identical. Shared knowledge that rotates and can't be guessed is the simplest defense against impersonation.
The Capillary case shows this isn't a future problem. It's happening now, to real organizations, with real financial consequences. Families face the same risk on a personal scale. A parent gets a call from their "child" in a crisis. A grandparent hears their "grandchild" asking for help. A spouse receives what sounds like an urgent message from their partner.
The voice is convincing. The urgency is manufactured. The window to think clearly is short.
Three words close that window on the attacker, not the family.
Trust Onion is free. Setup takes minutes. The words rotate automatically. There's no app account to hack, no server to breach, no password to reset.
The question is simple. The answer proves everything.
Frequently Asked Questions
How did deepfake fraud steal 3 million euros from Capillary Technologies?
Attackers used cloned voices of company executives and forged signatures to trick an overseas subsidiary into authorizing fraudulent transfers. The combination of familiar-sounding audio and legitimate-looking paperwork made the requests appear routine. As of disclosure, only €0.45 million was recovered.
How little audio does someone need to clone a voice?
Modern voice cloning tools can produce convincing replicas from as little as 20 to 30 seconds of audio. Public sources like earnings calls, conference presentations, YouTube videos, and LinkedIn posts all provide enough usable material for attackers.
How common is deepfake fraud against businesses?
According to the World Economic Forum, deepfake fraud attempts increased 500% in 2024. The technology is becoming cheaper and more accessible, making businesses of all sizes potential targets, including well-funded companies with professional finance teams.
What is the best way for businesses to verify identity and prevent voice cloning fraud?
Shared secrets are currently one of the most reliable defenses. These are pieces of private information only the real person would know, not available publicly, and changed frequently enough to be useless if stolen. Callback procedures through verified numbers add another layer of protection.
Why do employees fall for deepfake voice scams even with security processes in place?
Humans are wired to trust familiar voices. When a call sounds like a known executive and arrives with supporting documents, questioning it feels unnatural. Attackers research company structures and personnel in advance to make fraudulent requests feel completely routine.
Protect your family with three rotating codewords that even the most convincing cloned voice can't fake. Trust Onion is free at trustonion.io.
Protect Your Family FreeJuly 18, 2026
A Couple Lost $800,000 to an AI Scam. Here's How.
A metro Atlanta couple lost $800,000 to an AI-powered scam. CBS News reports AI scam losses hit $900...
July 15, 2026
AI Cloned Her Son's Voice in 10 Seconds. Then It Called Her.
AI voice cloning scams are hitting San Diego families hard. Learn how criminals fake emergencies wit...
July 9, 2026
Her Son's Voice Asked for Help. It Wasn't Her Son.
A Canadian mother heard her son's voice begging for help. It was AI. How scammers clone voices from ...


