· 3 min read

🎭 The $25M Deepfake

A Hong Kong finance worker wired $25M after a video call with deepfake executives — and verified everything first. The same AI-fabrication wave is hitting insurance claims one photo at a time, and mid-market carriers have no answer yet.

🎭 The $25M Deepfake

In February 2024, a finance worker at Arup's Hong Kong office got a message from his CFO in London asking him to handle a confidential transaction. He flagged it as suspicious, so the CFO followed up with a video call to clear the air. The CFO was on screen, alongside several senior colleagues the worker recognized. Voices and faces all checked out. He came away convinced and wired $25 million across 15 transfers to five different bank accounts.

Every person on that call was a deepfake. He only caught it later, when he happened to check in with the actual London office.

London-based company Arup — victim of a deepfake scam in Hong Kong.

The wild part is how cleanly the verification worked. Escalate the request, hop on a video call, confirm with people you know. The process held. The evidence just wasn't real.

Insurance carriers sit in the same chair, except their version of the problem doesn't make a $25 million headline. Earlier this year, three Los Angeles residents staged fake bear attacks on a Rolls-Royce, a Mercedes G63, and another Mercedes, filing about $142,000 in claims across multiple carriers. The case — nicknamed Operation Bear Claw — collapsed when a California Department of Fish and Wildlife biologist reviewed the footage and concluded the bear was clearly a guy in a suit.

The next wave looks nothing like that. It runs on a phone and a free app, and Verisk's 2026 study found:

The play is a lightweight verification layer for mid-market P&C carriers that scores submitted media at intake, before any payout decision. Verisk and Guidewire will eat the top of the market. The other 3,800 US carriers can't absorb an 18-month platform transformation just to answer one operational question. The buyer is the SIU leader, the person who gets burned when bad evidence sneaks through. Hybrid pricing at $2K to $12K per month plus per-scan, 60-day pilots at $7.5K to $20K, ten carriers gets you to $720K ARR, and a credible path to $3M to $10M before the category gets crowded.

Read the full playbook here:

AI-fabricated claim photos are hitting carrier queues at scale — and 99% of insurers say they've already seen manipulated evidence. The mid-market has a gap, and a focused intake layer can fill it.

Full Playbook

From the Vault:

The government just reauthorized SBIR with a new $30M award tier and caps on volume filers — and the workflow layer between technical founders and federal funding still doesn't exist as a real product.

Full Playbook

Half of Gen Z shoppers wait two-plus days before buying. Standard cart abandonment flows treat that as a problem. It's actually an opening.

Full Playbook

Read next

📋 The Two Weeks Notice Myth

📋 The Two Weeks Notice Myth

Two weeks’ notice has never been required by law — and HR has been happy to let you believe otherwise. Today’s idea packages that information gap into a resignation compliance kit built specifically for healthcare workers.

Startup Heist | Briefings
Startup Heist | Briefings
· 3 min read
🧪 One Lab Test

🧪 One Lab Test

In 2019, one online pharmacy ran Zantac through a mass spec and triggered a billion-dollar recall. That playbook repeats across twelve OTC categories — and someone is building the intelligence layer to catch it first.

Startup Heist | Briefings
Startup Heist | Briefings
· 3 min read
New startup opportunities, ideas and insights right in your inbox.