Arup Details

    Organization Logo

    Arup

    London, United Kingdom16000 employees • Construction and Engineering

    https://www.arup.com/
    United Kingdom

    Industry

    Construction and Engineering

    Security Incidents

    1

    Arup Group Limited is a multinational company providing engineering, design, and consulting services for the built environment. Founded in 1946 by Ove Arup, the organization has grown significantly, playing a pivotal role in some of the world's most iconic structures, such as the Sydney Opera House and the Centre Pompidou in Paris. Arup's primary purpose is to design sustainable and innovative solutions within multiple sectors, including transportation, buildings, energy, and water.

    Arup's notable achievements extend beyond traditional engineering; the firm is acclaimed for its commitment to ...
    Show more

    Security Incidents

    Arup Breach of May 2024
    Severity Score
    Significant to High

    Type

    Other

    Summary

    Arup, a British engineering group, experienced a significant financial fraud incident when cybercriminals used AI-generated deepfakes to impersonate the company's CFO and other employees. On May 17, 2024, it was reported that scammers contacted a staff member, posing as the CFO and requesting a series of confidential transactions. Following a video call with the deepfaked identities, the employee executed multiple transfers totaling approximately $25 million to five bank accounts in Hong Kong.

    The fraudulent activity was uncovered only after the staff member reached out to the company’s headq...
    Show more

    Severity

    The cyberattack on Arup, where cybercriminals used AI deepfakes to impersonate the CFO and other employees, resulted in the fraudulent transfer of $25 million to Hong Kong bank accounts. This incident highlights the sophisticated use of AI to create convincing false identities, manipulating trusted individuals within an organization to execute significant financial transactions. Given the substantial monetary loss, the advanced technology involved, and the potential for similar future attacks, this incident's severity is rated as 8, signifying a "Significant to High" level of concern for cyber...
    Show more

    Impact

    The recent cyber incident involving Arup was a sophisticated case where cybercriminals employed AI deepfakes to impersonate the company's CFO and other employees. The attackers successfully convinced a staff member to transfer approximately $25 million USD to bank accounts in Hong Kong. This technique of using AI-manipulated audio and video highlights a new level of sophistication in social engineering attacks.

    While no direct information suggests the breach of customer data or exposure of internal company data or intellectual property, the financial loss and the method used indicate a potent...
    Show more