
Euler Hermes / UK Energy Firm
AI Voice Clone of a Parent-Company CEO Talks an Exec Into Wiring EUR 220,000
The chief executive of a UK energy firm took an urgent phone call from a man he believed was the head of the company's German parent.
- 01TRIGGERThe chief executive of a UK energy firm took an urgent phone call from a man he believed was the head of the company's…
- 02MACHINE ACTIONFraud enabler
- 03MISSING GATEIdentity verification and dual control
- 04IMPACTFinancial harm
The short version
The chief executive of a UK energy firm took an urgent phone call from a man he believed was the head of the company's German parent.
Case telemetry
- INCIDENT
- SS-IR-016
- DATE
- September 2019
- SYSTEM
- Euler Hermes / UK Energy Firm
- LOCATION / SCOPE
- United Kingdom (parent company in Germany)
- EVIDENCE
- Documented
- AI ROLE
- Fraud enabler
- HARM
- Financial harm
- SOURCES
- 2 cited records
The event
The chief executive of a UK energy firm took an urgent phone call from a man he believed was the head of the company's German parent. The caller asked him to wire EUR 220,000 (about US$243,000) within the hour to a Hungarian supplier to close a deal. Recognizing what sounded exactly like his boss - the same German accent and the same vocal "melody" - the UK executive authorized the transfer. The caller phoned back twice more, claiming the firm had been reimbursed and asking for a second payment, the third call coming from an Austrian number. The voice on the line was not the CEO. It was an AI-generated clone. The money was wired to the Hungarian account, then immediately funneled onward to Mexico and other locations, and was never recovered. The case, widely reported as the first known AI voice-clone CEO fraud, surfaced only because the parent firm's insurer, Euler Hermes Group SA, disclosed it (with the companies anonymized) to the Wall Street Journal.
What the machine did
Attackers used AI voice-synthesis software to clone the German CEO's voice, almost certainly training it on publicly available audio such as conference talks and media interviews. The clone reproduced his accent, cadence, and intonation convincingly enough that a senior executive who knew the man personally never doubted it. There was no out-of-band identity check and no second-approver gate on the payment: a single familiar-sounding voice on a single phone call was treated as sufficient authorization to move a quarter of a million dollars. Voice alone became the credential, and AI forged that credential at machine quality with zero human verification standing behind it.
Where the failure landed
EUR 220,000 (about US$243,000) stolen and never recovered after being laundered through Hungary, Mexico, and onward accounts. Euler Hermes covered the claim. The case became the first publicly reported instance of AI voice cloning used for CEO fraud, putting boards and insurers on notice that "I recognized his voice" was no longer a control. It set the template for a now-thriving category of synthetic-media business fraud, culminating in cases like the 2024 Arup deepfake video-call theft of US$25.6 million.
Documented
Supported by a first-party disclosure, technical research, or corroborated reporting cited below.
SOURCE RECORD UPDATED 2026-07-09
2 cited records
- 01
- 02
Identity verification and dual control
The failure pattern in this case: Unverified identity or synthetic media.
The moment the path could change
A named reviewer verifies identity through a separate trusted channel before money, access, or public claims can move.
Autonomy is a design choice.
See the operating model that keeps AI useful while preserving human authority at consequential moments.
Compare AgenticAI and AugmentedAI →