Your mind is not fully yours unless you can direct your attention, test your beliefs and choose your response.

The enduring lesson is not that nobody can trust video anymore. It is that video should no longer function as an identity credential.
What is confirmed, and what remains uncertain
Confirmed
- Arup was the victim.
- The event occurred in January 2024.
- Fake voices and images were used.
- A Hong Kong employee was deceived.
- Approximately HK$200 million was transferred.
- There were 15 transfers to five accounts.
- Arup said its internal systems were not compromised.
- The incident was investigated as obtaining property by deception.
Not publicly established
- The exact AI software used.
- Whether every participant was generated live or partly prerecorded.
- Whether the attackers had compromised email accounts or merely spoofed them.
- Precisely how the criminals obtained internal organisational knowledge.
- Whether any employee credentials or internal documents were previously stolen.
- How much of the stolen money was eventually recovered.
- Who ultimately organised the operation.
Claims that the attackers definitely trained their models from particular Arup meetings or public videos are plausible, but not firmly established by the available police or company statements.
This is often presented as a story about extraordinary AI. That is only partly correct.
The larger failure was that one persuasive communication event could trigger HK$200 million in payments.
Even a perfect deepfake should not defeat a properly separated financial-authorisation system. The incident indicates that some combination of the following controls was absent, bypassed or ineffective:
- independent approval by another authorised person;
- verification through an established telephone number;
- transaction limits;
- bank callback procedures;
- cooling-off periods for exceptional payments;
- confirmation through an internal finance platform;
- recipient-account verification;
- escalation of unusual confidential transactions;
- prohibition against authorising payments solely from video, voice or email instructions.
The deepfake defeated human perception. The financial-control architecture allowed that perceptual error to become a massive loss.
Arup later stated that the incident prompted a thorough review of its governance and processes. Its annual reporting also indicated that the fraud and related investigation had a material financial impact, although the company said its networks, project delivery and overall financial stability were not compromised.
Why the employee was vulnerable despite initial scepticism
The attackers used several established social-engineering mechanisms simultaneously:
Authority: the request apparently came from the CFO.
Social proof: several recognised colleagues appeared to endorse the request.
Confidentiality: secrecy prevented the employee from checking widely.
Urgency: rapid execution reduced analytical thinking.
Visual confirmation: the employee believed they had independently verified the email through video.
Fear of obstructing leadership: questioning an apparent executive group can feel professionally risky.
The attack did not merely manufacture a face. It manufactured an entire social environment of authority and consensus.
Worthwhile sources:
1. Chi, Feltovich & Glaser — “Categorization and Representation of Physics Problems by Experts and Novices” (1981)
Why read it: This is probably the strongest empirical foundation for the claim that experts “see” problems differently. Novices group problems by surface features—ramps, pulleys, springs—whereas experts organise them according to underlying principles such as conservation of energy or Newton’s laws.
Central implication: Better problem solving is not primarily about knowing more formulas. It depends on representing the problem at the correct structural level.
Priority: Essential.
2. Gick & Holyoak — “Analogical Problem Solving” (1980)
Why read it: This tests whether people can transfer a solution from one problem to another structurally similar but superficially different problem. Most people fail to notice the analogy spontaneously, even when the earlier example contains the solution.
Central implication: Merely encountering useful knowledge does not mean you will recognise when to apply it. Feynman’s habit of continually testing new ideas against standing problems directly addresses this weakness.
Priority: Essential.
3. Gick & Holyoak — “Schema Induction and Analogical Transfer” (1983)
Why read it: This extends the earlier work and shows that comparing multiple analogous examples can help a person extract a general schema, making later transfer more likely.
Central implication: One example teaches an answer; several contrasting examples can teach the deeper pattern.
Priority: Essential, especially after the 1980 paper.
4. Larkin, McDermott, Simon & Simon — “Expert and Novice Performance in Solving Physics Problems” (1980)
Why read it: This examines the actual sequences of thought used by expert and novice problem-solvers. Experts tend to construct a qualitative representation first and then derive equations from it. Novices more often work backwards from the requested quantity and hunt for formulas containing the listed variables.
Central implication: The Feynman-style demand to understand the physical mechanism before calculating is experimentally supported.
Priority: Essential.
5. Alan Schoenfeld — “Learning to Think Mathematically: Problem Solving, Metacognition, and Sense Making in Mathematics” (1992)
Why read it: This is one of the best broad treatments of why technically capable people still fail at unfamiliar problems. Schoenfeld separates:
- factual knowledge;
- problem-solving strategies;
- monitoring and control;
- beliefs about what mathematics and reasoning are.
A solver may possess the necessary knowledge but continue down an unproductive path because they fail to stop, reassess and change strategy.
Central implication: Reasoning requires an executive layer that repeatedly asks, “Is this approach working?”
Priority: Essential, although longer than the others.
6. Manu Kapur & Katerine Bielaczyc — “Designing for Productive Failure” (2012)
Why read it: This explores the value of attempting difficult problems before being shown the approved method. Learners may initially fail, but the struggle exposes structural features, activates prior knowledge and makes subsequent instruction more meaningful.
Central implication: Immediate explanation can sometimes produce shallow competence. Carefully structured failure can produce stronger conceptual understanding and transfer.
Caution: “Productive failure” does not mean abandoning guidance. It normally requires a deliberate consolidation phase afterward.
Priority: High.
7. Manu Kapur — “Learning from Productive Failure” (2015)
This is a shorter conceptual overview of the productive-failure research program. It explains the two-stage structure:
- generation and exploration;
- consolidation and formal instruction.
The evidence reviewed indicates that this can improve conceptual understanding and transfer relative to direct instruction alone under appropriate conditions.
Priority: Read this first if the 2012 paper appears too technical.
8. Richard Feynman — “Cargo Cult Science” (1974)
This is not an experimental paper, but it is the clearest primary source for Feynman’s epistemic method: do not merely seek evidence supporting your conclusion; disclose everything that could weaken it.
Its real subject is scientific integrity, particularly the obligation to avoid misleading oneself before worrying about misleading others.
Priority: Essential and very short.
Broader synthesis worth keeping
9. National Research Council — How People Learn, Chapter 3: “Learning and Transfer”
This is a synthesis rather than a single experiment. It examines when knowledge transfers to unfamiliar situations and why transfer often fails. The chapter treats transfer as an active process requiring sufficiently deep understanding, varied practice and recognition of underlying structure.
Priority: High. It connects most of the papers above into a coherent framework.
10. Fleur et al. — “Metacognition: Ideas and Insights from Neuro- and Educational Sciences” (2021)
A modern review of metacognition—the capacity to monitor and regulate one’s own thinking. It covers confidence calibration, error monitoring, strategy selection and the distinction between performing a task and accurately judging one’s performance.
Central implication: Intelligence without accurate self-monitoring can merely generate more elaborate errors.
Priority: Useful modern overview.
A compact reading sequence
For the best return on time:
- Feynman — Cargo Cult Science
- Chi, Feltovich & Glaser — Experts and Novices
- Gick & Holyoak — Analogical Problem Solving
- Gick & Holyoak — Schema Induction
- Schoenfeld — Learning to Think Mathematically
- Kapur & Bielaczyc — Designing for Productive Failure
- How People Learn — Learning and Transfer
| Research Area | Relevant research |
|---|---|
| Experts see beneath surface appearances | Chi; Larkin et al. |
| New knowledge should be tested against old problems | Gick & Holyoak |
| Understanding requires monitoring your own approach | Schoenfeld; metacognition literature |
| Struggling before instruction can deepen learning | Kapur |
| You must attack your own conclusion | Feynman |
| Transfer is difficult and must be deliberately cultivated | How People Learn |
The three most important downloads are Chi et al. 1981, Gick and Holyoak 1983, and Schoenfeld 1992. Those three explain the real cognitive machinery.