WPP CEO Mark Read Was the Face of a Deepfake Scam
Fraudsters cloned the CEO of the world's largest advertising firm and put him in a Microsoft Teams meeting. The real Mark Read was nowhere near it. In May 2024, WPP confirmed that scammers used an AI voice clone of Read alongside YouTube footage of him to target a senior WPP agency leader for money and personal information.
August 25, 2026
Originally reported by The Guardian · Read the original article
- In May 2024, fraudsters used an AI voice clone and YouTube footage of WPP CEO Mark Read to impersonate him in a live Microsoft Teams meeting.
- Voice cloning requires as little as 20 to 30 seconds of audio, and any public-facing executive has that audio available online.
- The real vulnerability is not the executive being impersonated but the finance or operations leader who receives the request and has authority to act on it.
- Skepticism is not a repeatable control. Organizations need a structured verification step before any high-stakes authorization is completed.
- A rotating codeword protocol stops voice and video impersonation fraud because a cloned voice cannot know words that change every few hours.
The Attack on WPP's CEO
The setup was methodical. Scammers created a fake WhatsApp account using Mark Read's photo and used it to arrange a Microsoft Teams call with a WPP agency head. Once on the call, the fraud ran on two tracks at once: an AI-generated voice clone of Read spoke during the meeting while a separate chat window impersonated him in text.
The goal was to solicit money and extract personal details under the cover of launching a new business venture. The attack ultimately failed, but what was deployed here deserves a close look.
This was not a phishing email. It was a real-time, multi-channel impersonation of a sitting CEO, complete with his voice, his face, and a plausible business pretext.
Why This Attack Was Different
Most executive impersonation fraud involves email: a spoofed address, an urgent request, a wire transfer gone wrong. Those attacks succeed because email offers no way to verify who is actually on the other end.
This attack moved the deception into a live video call, which most people still treat as inherently trustworthy. Seeing and hearing someone on a screen carries weight. That instinct is now a liability.
Voice cloning requires as little as 20 to 30 seconds of audio to produce a convincing replica. Mark Read, as CEO of a major public company, has given countless interviews, recorded presentations, and appeared in media for years. That audio is public. Anyone with a laptop and the right tools can use it.
The WPP case stands out not because it succeeded, but because it shows how far the tools have advanced. A realistic voice, a face sourced from YouTube, a fake WhatsApp account, a Teams meeting invitation. None of these required insider access or technical expertise beyond what is now widely available.
Executives Are the Target, but Finance Teams Are the Vulnerability
Mark Read's identity was the weapon, but the target was a WPP agency leader who had the authority to act on a request. That distinction matters.
In most CEO fraud scenarios, the executive is impersonated, not targeted. The actual damage happens downstream, when a finance team member, a senior operations lead, or a regional director receives the request and acts on it. They are the ones who authorize the wire transfer, share the account details, or approve the vendor payment.
According to the FBI's Internet Crime Complaint Center, business email compromise and related executive impersonation fraud cost U.S. organizations $2.9 billion in 2023 alone. Voice and video-based variants are pushing that number higher.
The WPP agency leader on that Teams call had no mechanism to verify that the voice and face on screen were real. They had to rely on judgment, context, and instinct. That is not a reliable control.
What Stops a Deepfake in Real Time
The WPP attack succeeded in one respect: it got the target into the meeting. The deception held long enough to make a pitch. The failure came because the agency leader was skeptical and did not act on the request.
Skepticism is not a system. It is not repeatable, trainable, or scalable across an organization. Some employees will be skeptical. Others, under pressure from what appears to be their CEO, will not.
What organizations need is a verification layer that does not depend on whether a voice sounds right or a face looks real, something that works even when the sensory evidence is convincing.
Trust Onion gives finance teams and senior leaders exactly that. The system distributes three rotating codewords across an organization's verification chain. The words change every few hours, calculated locally on each device with no server required. When a caller claims to be the CEO authorizing an urgent transfer or a new business venture, the person on the receiving end asks one question: "What are the words?"
A real executive who is part of the organization knows the current codewords. A cloned voice does not. A deepfake on a Teams call does not. The call either clears verification or it does not.
If Mark Read's agency leader had been using a codeword protocol, the scam would have ended in the first thirty seconds. The AI voice, however convincing, could not have answered.
The Broader Pattern
WPP is not alone. In February 2024, engineering firm Arup lost $25 million when an employee authorized a wire transfer after joining a video call where every visible participant, including a colleague who looked and sounded familiar, was a deepfake.
In 2023, a finance worker at a multinational firm in Hong Kong transferred $200 million Hong Kong dollars after a video call featuring what appeared to be the company's CFO. The CFO was not on that call.
These are early examples of a fraud category that will grow as the tools become cheaper and easier to use. The barrier to cloning a voice or constructing a fake video meeting participant is lower today than it was twelve months ago.
What Organizations Should Do Now
Three steps apply immediately to any organization with financial authorization processes.
Establish a verbal verification standard for all high-stakes requests. Any call requesting a wire transfer, new vendor approval, or sensitive information disclosure should trigger a verification step. A codeword protocol makes that step simple and consistent.
Rotate the verification mechanism. Static passwords and fixed codes can be compromised and shared. Codewords that change every few hours expire automatically, so a word captured today is useless tomorrow.
Treat video calls with the same skepticism as email. The WPP attack succeeded in arranging a Teams meeting precisely because meetings feel more legitimate. They are not, by default, more secure. The verification standard should apply regardless of the communication channel.
The technology that powered the attack on Mark Read is not going away. Organizations that build simple, consistent verification into their authorization workflows stop waiting for the next attack to find out whether their people will catch it in time.
Three rotating codewords. One question asked before any high-stakes action is taken. That is the control.
Frequently Asked Questions
What happened in the WPP deepfake scam involving Mark Read?
In May 2024, fraudsters created a fake WhatsApp account using WPP CEO Mark Read's image, arranged a Microsoft Teams meeting, and deployed an AI voice clone of Read alongside YouTube footage to impersonate him. The goal was to solicit money and personal details from a WPP agency leader. The attack failed.
How do deepfake voice scams target businesses?
Attackers clone an executive's voice using publicly available audio, then call or join a meeting posing as that executive to request wire transfers, vendor approvals, or sensitive data. The impersonation happens in real time, making it difficult for employees to detect without a verification system.
How can companies verify a caller is really their CEO or CFO?
A rotating codeword protocol requires the caller to provide current codewords known only to verified personnel. The words change every few hours, so a compromised or cloned voice cannot pass verification. Tools like Trust Onion implement this at no cost to enterprise teams.
How much has executive impersonation fraud cost businesses?
The FBI's Internet Crime Complaint Center reported $2.9 billion in losses from business email compromise and executive impersonation fraud in 2023. Voice and video-based variants are increasingly common and represent a growing share of those losses.
Can you tell a deepfake voice from a real one on a call?
Human detection accuracy for AI-generated voices hovers around 55 to 60 percent, barely better than chance. Relying on whether a voice sounds right is not a reliable control. A structured verification step is required.
Verify your team's calls with three rotating codewords. Trust Onion is free for enterprise teams and requires no server or technical setup.
Protect Your Business Free