In 2024, scammers impersonated the chief executives of Ferrari and WPP with a cloned voice and a deepfake video to authorize a secret deal and move money. Both attempts failed. Both were caught by a person on the other side asking for something only the real executive could provide. No automated authenticity control was in the loop. That is the point.
The Ferrari call
In July 2024, a senior Ferrari executive received WhatsApp messages that appeared to come from chief executive Benedetto Vigna, sent from an unfamiliar number. As Bloomberg reported, the messages described a confidential acquisition, pressed the executive to sign a nondisclosure agreement at once, and claimed that Italy's market regulator and stock exchange had already been briefed.
A phone call followed, using an AI voice clone of Vigna that reproduced his southern-Italian accent closely. The executive noticed slight artificial intonations and grew suspicious. As MIT Sloan Management Review recounts, the executive ended the attack with one question: he asked the caller to name the book Vigna had recommended to him days earlier. The caller could not, and the call ended.
The WPP meeting
Two months earlier, in May 2024, the CEO of the advertising group WPP, Mark Read, was the target of a similar attempt. Read described it in an internal email, first reported by The Guardian and logged in the OECD AI Incidents registry. Fraudsters set up a WhatsApp account using a publicly available image of Read, then arranged a Microsoft Teams meeting that appeared to include him and another senior executive.
During the meeting the impostors deployed a voice clone and YouTube footage of the executive, and impersonated Read off camera through the meeting chat window. The target was an agency leader, asked to set up a new business as a pretext to solicit money and personal details. The attempt did not succeed. Read wrote to staff that the attackers were not successful and that everyone needed to be alert to techniques that go beyond email to exploit virtual meetings, AI, and deepfakes.
Why both were caught
Neither of these was stopped by technology that flagged a fake. There was no deepfake detector in the loop and no automated authenticity check on the call. In both cases a person on the other side verified something the impostor could not produce: at Ferrari, a private detail only the real CEO would know; at WPP, enough suspicion about an out-of-character request to refuse it.
File these correctly. They are social engineering, high-fidelity impersonation aimed at a human decision, not a defeated automated control. That distinction is not pedantry. It tells you where the defense lives. When the attack targets a person's judgment on a live call, the defense is process: out-of-band verification, a callback to a known number, a second approver, a shared secret. It is not a detector.
The counterexample proves the rule. In early 2024, a finance employee at the engineering firm Arup wired about 25 million US dollars after a video call with deepfaked executives, an attack of the same class that succeeded because no such verification step stood between the request and the transfer. We walk through that case, and the line between a defeated control and a deceived person, in the deepfake that opened real bank accounts.
What this means for enterprise security
For live-call executive impersonation, the primary control is procedure, and the Ferrari and WPP cases are the training material: a documented out-of-band verification step, applied without exception to any urgent, confidential, or unusual payment or access request, regardless of how convincing the voice or face is. The question is never whether the CEO on the call looks and sounds real. It is whether the person or system on the other side verifies something the impostor cannot supply.
Where an organization does place an automated control in the loop, a deepfake or liveness check gating onboarding, payments, or meeting access, a different question applies: does that control actually hold against current attacks? That is measurable, and it does not survive on a vendor's clean-benchmark number, as our detector benchmark shows. The only honest answer is a measured one.
Margen does not sell detection, identity verification, or fraud prevention. We are an independent third party that red-teams the automated controls organizations rely on, under adversarial, platform-realistic conditions, and reports where they hold and where they break.
Sources
- Bloomberg: Ferrari narrowly dodges deepfake scam simulating deal-hungry CEO
- MIT Sloan Management Review: How Ferrari hit the brakes on a deepfake CEO
- OECD AI Incidents (reporting The Guardian): WPP executives targeted by deepfake voice-cloning scam
- AI Incident Database: Ferrari executive targeted by AI deepfake impersonating CEO Benedetto Vigna