Capillary's $3.4 Million Lesson in Executive Impersonation

Key takeaways
- Capillary Technologies disclosed on July 6 that attackers used a cloned executive voice, a forged signature, and social engineering to impersonate Key Management Personnel and trick a recently acquired overseas subsidiary into transferring about €3 million ($3.48 million) to unfamiliar accounts.
- Banks quickly froze part of the trail and Capillary recovered €450,000 ($522,000) within days; the company said no customer data, employee data, or technology systems were affected, brought in KPMG for a forensic audit, notified its insurer, and continued working with law enforcement.
- Columbia professor Asaf Cidon warned that freely available tools can create convincing audio and video deepfakes from a short clip, specifically highlighting the risk of a finance officer receiving what appears to be a message from their boss.
- The article links Capillary to a March 2025 Singapore case where a finance director joined a fake Zoom call featuring fabricated senior leaders and a fake lawyer, leading to a $499,000 transfer to Hong Kong accounts before HSBC and police froze the funds.
- The FBI’s Internet Crime Complaint Center has tracked business email and executive impersonation fraud since 2013 and reported $55.5 billion in exposed losses through the end of 2023, including a 9% increase in the final year cited.
- The main control recommended is an independent second-channel verification step for wire transfers: dual approval only works if the second approver verifies via a separate callback or system, supported by leadership messaging and simulations that rehearse cloned-executive and forged-urgency scenarios.
On a weekend before July 3, 2026, employees at a recently acquired overseas subsidiary of Capillary Technologies received a series of urgent requests. The voice sounded like a senior executive. A signature backed up the paperwork. Convinced, the finance team authorized transfers totaling roughly €3 million (about $3.48 million) to accounts the company had never used before.
None of it came from that executive. Capillary disclosed on July 6 that attackers had combined a cloned voice, a forged signature, and old-fashioned social engineering to impersonate senior company personnel, known formally as Key Management Personnel, and talk employees into moving the money. Banks froze part of the trail quickly enough to recover €450,000 (about $522,000) within days, and additional funds remain traced and on hold while investigators work out the rest.Producing a voice convincing enough for this takes little effort today.
Asaf Cidon, a professor of electrical engineering and computer science at Columbia University, has described how little raw material a convincing clone now needs: “Today, using freely available technology, I can take a short video clip of you speaking and feed it into an AI model that will generate a deepfake video that looks and sounds almost exactly like you.” Cidon has pointed to this scenario, a financial officer receiving a message that appears to come from their boss, as one of the clearest paths for the technology to cause serious damage. “This is what worries me and everyone else in my field,” he said.
A Rare Public Confirmation
Most companies that get hit this way never say so publicly. Capillary did, naming voice cloning directly in a filing required under securities law. That confirmation matters on its own. It moves this attack method from an assumption security teams make to a fact one board has put on the record.
The company also confirmed what didn’t happen: no customer data, employee data, or technology systems were touched. The damage stayed contained to a single financial transaction. Capillary brought in KPMG for a forensic audit within weeks, its insurer was notified under the subsidiary’s existing cyber and crime coverage, and the company kept working with law enforcement to trace the remaining funds. Its stock closed a fraction of a percent higher the day the disclosure went public.
The Same Playbook, Twice
Capillary’s finance team is not the only one that has faced this exact combination. In March 2025, a finance director at a firm in Singapore joined what looked like a routine Zoom call with the CEO and several other senior leaders. Every executive on that call was fabricated. The pretext was a regional restructuring, complete with a fake lawyer requesting a signed non-disclosure agreement before the transfer went through. Roughly $499,000 moved to accounts in Hong Kong before HSBC flagged the activity. The Singapore Police Force, working with Hong Kong’s Anti-Deception Coordination Centre, traced and froze the funds within days.
Two incidents, thirteen months apart, on two continents, share the same shape: a cloned voice or video, a document that looks official, and a request timed to feel too urgent to question. The FBI’s Internet Crime Complaint Center has tracked this broader category, business email and executive impersonation fraud, since 2013, and reported $55.5 billion in exposed losses through the end of 2023, with a 9 percent jump in that final year alone. This pattern is not confined to one company or one industry, which is exactly why the response has to be built into how a business operates, and not left to any single employee’s instincts in the moment.
What an Expert in the Field Adds
Siwei Lyu, a SUNY Empire Innovation Professor at the University at Buffalo who co-directs its Center for Information Integrity, has spent years studying how manipulated audio and video shape decisions long before anyone realizes something is wrong. “We rely so much on audiovisual information... to tell us what happened,” Lyu has said, describing how much of modern business runs on trusting a voice or a face on a screen. He has also cautioned that the small visual tells researchers once relied on to catch a fake, an odd blink, a mismatched shadow, are fading as the technology improves. That is precisely why verification needs to live in a company’s process, and not in any one person’s eyes or ears.
What Individuals Can Do
A few habits change the outcome of a call like this.
- A request to move money tied to urgency or secrecy is worth a pause, regardless of who appears to be asking. Documents attached to that request deserve the same pause. A forged signature can look convincing on a screen, and the fastest way to check it is a phone call to the person whose name is on it.
- Verifying through a second, independently confirmed channel, a callback to a known number or a message through an established system, takes minutes and closes a gap that a convincing voice or video cannot close on its own. Asking for something spontaneous during a video call, a specific unscripted action, still trips up most fabricated video today.
- None of this works if a junior employee feels they can’t pause a request from someone who looks and sounds like the CEO. That’s the part leadership has to build, explicitly and out loud: a standing message that verifying a transfer request is expected of everyone, regardless of who appears to be asking, and that no one will face pushback for making the call.
What Organizations Can Build In
Individual habits help. What protects an entire finance team is a written policy, one specific enough to survive what happened in Singapore: several executives were faked on the same call, so a second approver sitting in that same meeting would have been fooled just as easily.
- A dual-approval policy only closes the gap if the second approval runs through a separate channel entirely, a callback, a different system, a conversation that never touches the call in question.
- A standing policy that no wire authorization proceeds without that independent step, no matter how senior the requester appears, protects the employees who would otherwise carry that judgment call alone.
- Practiced simulations, run against these same tactics, help a finance team recognize the pattern well before an attacker tests it under pressure. Some awareness platforms, Adaptive included, now build these exact scenarios, cloned executives and forged urgency together, into training that finance and executive teams can rehearse ahead of time.
The Encouraging Part
Both of these cases ended the same way: banks and law enforcement traced the money fast enough to claw back a meaningful share of it after the transfer had already gone through. That’s a genuine second line of defense, and it’s worth having relationships with a bank’s fraud team established well before an incident, since building them from scratch during one costs precious time. The first line of defense is the one this piece has focused on: the independent verification step that stops the transfer from happening in the first place. A cloned voice can sound convincing. A forged signature can look official. Neither survives a second channel built into the process ahead of time, and that second channel costs a company nothing until the day it’s needed.
Get started with Adaptive Security