GoFirm
Back to Blog
Case Studies·4 min read

Attackers cloned senior executives' voices, forged their signatures, and walked away with three million euros from Capillary Technologies

By GoFirm

In late June 2026, one of Capillary Technologies' recently acquired step-down subsidiaries became the target of a cyber-enabled banking fraud that resulted in the loss of approximately three million euros. Capillary Technologies, the Bengaluru-headquartered SaaS provider known for its customer engagement and loyalty platforms serving retailers and consumer brands worldwide, disclosed the incident in a stock exchange filing on 6 July 2026. The exploit, according to the company, took place just prior to the first weekend of July. Attackers did not breach a firewall or exploit a software vulnerability. They used AI-generated deepfake audio to clone the voices of senior company executives, combined with forged signatures, to convince staff at the subsidiary that fund transfer instructions were coming from genuine internal authority.

The fraud unfolded through impersonation of the subsidiary's key managerial personnel, the individuals whose sign-off would ordinarily be required to authorise a payment of this size. Using cloned voice recordings and forged signatures layered together, the attackers built a convincing enough package of synthetic authority that staff processed instructions to move funds to unauthorised third-party bank accounts. No credentials were phished. No systems were hacked. The fraud relied entirely on convincing a human being that the executive asking for the transfer was real.

By the time the diversion was discovered, roughly three million euros had already left the subsidiary's accounts. Capillary Technologies has since recovered around €450,000, working with law enforcement, cybercrime authorities, and partner banks to freeze suspicious accounts and trace the remaining funds. Additional accounts linked to the fraud have since been placed on hold, which the company says has helped limit further losses. But the majority of the stolen amount, more than €2.5 million, remains outside the company's control.

The incident lands at an inconvenient moment for a company mid-expansion. Capillary Technologies has not named the affected subsidiary, but the timing falls squarely within its most active acquisition phase: its most recent deal, the customer loyalty platform SessionM, was purchased from Mastercard for twenty million dollars in February 2026 to strengthen the company's footprint across North America and Latin America. Newly acquired entities are precisely where authorisation workflows and reporting lines tend to be least mature, still being folded into a parent company's controls. Analysts tracking the fraud have pointed to a wider pattern: deepfake-enabled executive impersonation is becoming one of the fastest-growing categories of corporate financial fraud, exploiting trust in internal approval chains rather than any technical weakness in a company's infrastructure.

The defences that failed here were not weak by conventional standards. Capillary Technologies is a listed, financially healthy company, its most recent full-year profit having grown nearly fourfold, with a cyber and crime insurance policy already in place at the subsidiary level. None of that mattered at the moment the transfer instruction arrived. A voice that sounded right, a signature that looked right, and an internal process built to trust both were enough to move three million euros out the door. No firewall, endpoint tool, or insurance policy sits at that specific moment of decision.

A fund transfer authorised on the strength of an executive's voice and signature is an execution event. Before a subsidiary's finance team can release a payment of this size, a confirmation request should go to the named authority, the actual chief financial officer or managing director whose approval is being invoked, on their own registered device, through a channel the attacker has no access to. That authority then confirms with their own biometric signature, a fingerprint or face scan on a device already provisioned and verified, entirely separate from the phone call or the signed document the attackers fabricated.

It does not matter how convincing the cloned voice is or how precise the forged signature looks. The attacker is impersonating a person, not confirming with that person. GoFirm's out-of-band confirmation sits outside the channel the impersonation travels through altogether: no cloned voice, no forged signature, and no fabricated document can produce a biometric confirmation on the real executive's own registered device. A deepfake, however convincing, cannot make someone else's finger touch a sensor it was never near. The execution boundary holds regardless of how real the voice on the phone sounds.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. The420 Correspondent. 2026. Capillary Technologies subsidiary hit by ₹32.7 crore cyber fraud. The420.in, 6 July 2026.

2. Inc42 Staff. 2026. Capillary Technologies' subsidiary hit by €3 Mn cyber fraud. Inc42, 6 July 2026.

Share this article