When the Face on the Screen Isn't Real: Rethinking Trust in the Family Office
You're at a conference, and a call comes through, one you'd been expecting. A deal months in the making, worth $25 million, is ready to close. You join. On the other end, a familiar voice, a familiar face, familiar mannerisms. The tone is calm, the details are plausible, and the request fits the shape of dozens of legitimate transactions that came before it.
You authorize the transfer.
The video had been frame-by-frame synthetic. The audio, generated word for word, assembled into a real-time deepfake convincing enough to survive a live conversation.
This is no longer hypothetical. In January 2024, a finance employee at the engineering firm Arup authorized 15 wire transfers totaling $25.6 million after joining a video call where the other participants, including senior executives he recognized, were AI-generated. He had been suspicious of the initial request, sent by email. It was the video call that erased the doubt. He only discovered the fraud afterward, when he reached out to Arup's actual headquarters himself to follow up on the transaction. AI-enabled fraud is a growing threat category, and family offices and ultra-high-net-worth individuals (UHNWI) are increasingly the target.
A transfer of trust is a governance decision. Arup's finance team didn't think of that authorization as one. That's exactly why it worked.
Family offices are, if anything, a better target for this kind of fraud than corporations. They move large sums on the authority of concentrated trust. What looks like discretion is exposure.
Why Structure Alone Doesn't Protect You
Dual authorization on large transfers. Callback verification through a separate channel. These are common first controls for high-risk processes. But there's a blind spot they don't reach: the behavioral one.
Deepfake fraud attacks the person authorizing the transfer, not the process around it. It targets what the transaction depends on: trust itself. You don't stop to confirm your CFO is actually your CFO on a routine call. The Arup fraud was engineered specifically to make that instinct feel unnecessary.
The Behavioral Pattern
A few patterns recur in these cases, and they map directly onto vulnerabilities built into how family offices operate:
Trust transference. Leadership extends trust from a relationship to whatever channel that relationship happens to arrive through, including, now, AI. If a principal trusts his longtime CIO, he unconsciously extends that trust to a video call wearing that CIO's face.
Authority compresses scrutiny. Requests from someone senior, trusted, or urgent shorten the time spent evaluating them. Family offices are built around a small number of high-authority relationships, which means this compression is embedded into daily operations.
Confidentiality removes oversight. These frauds rely on a request for discretion as the reason not to loop in a second person. Family offices already run on confidentiality and closeness, which is exactly what makes them an easier target.
Would you second-guess your own father on a video call, authorizing a transfer? In the moment, questioning someone that trusted feels almost impossible, which is precisely what these frauds are built to exploit.
The Gap Between Knowing and Doing
The FBI's Internet Crime Complaint Center logged $893.3 million in AI-enabled fraud losses in 2025 alone, its first year tracking the category on its own. Separately, Deloitte's Center for Financial Services projects generative AI-enabled fraud losses in the US could reach $40 billion annually by 2027.
Neither figure is broken out for family offices specifically. But Deloitte's Family Office Cybersecurity Report, 2024, found that 43% of family offices had already experienced a cyberattack in the past two years, rising to 62% among offices managing over $1 billion in assets. Phishing was the entry point in 93% of cases.
Phishing already proves the entry point: a person, deceived. Deepfakes exploit the same opening, with far better production values.
Governing the Transfer, Not Just the Transaction
This is the problem The Trust Chain™, Eunomia's behavioral governance framework, was built to address. It starts with a principle: a transfer of trust is a governance decision, whether anyone treats it that way or not.
The first pillar is Verify, governing the transfer of trust from perception to proof. A familiar face and a familiar voice are perception. Proof is a protocol that confirms identity and authenticity, whether trust is placed in a face, a voice, a document, or a signature. Arup's CIO, Rob Greig, later described the incident as social engineering: no systems compromised, no data exposed. Cybercrime doesn't require a systems breach. Here, the failure was human. The systems held. The people didn't.
Verify is the first of four pillars in The Trust Chain™. We'll introduce the rest in the weeks ahead.
See Where Verify Fits
AI doesn't just change decisions. It changes how trust is transferred.