Deepfake Incidents Surge, Challenging CISOs with AI-Driven Social Engineering
A Gartner survey reveals a significant increase in deepfake incidents targeting employees via audio and video calls, prompting urgent calls for enhanced verification and incident response strategies.

Artificial intelligence is empowering cybercriminals to bypass traditional security measures and infiltrate organizations with unprecedented sophistication. A recent Gartner survey highlights a stark reality for Chief Information Security Officers (CISOs): deepfake technology is no longer a theoretical threat but a present danger.
The survey found that a substantial 41% of CISOs reported at least one social engineering incident involving a deepfake during employee audio calls within the past year. The threat extends to visual mediums as well, with 36% of CISOs experiencing similar incidents during video calls. These figures underscore the growing effectiveness of AI-powered impersonation tactics in compromising organizational security.
These AI-driven attacks are often integrated into broader social engineering campaigns. The Gartner survey also indicated that 79% of CISOs encountered phishing, spear-phishing, or business email compromise (BEC) incidents in the same period, while 58% reported instances of vishing or smishing. This multimodal approach allows attackers to combine various deceptive techniques, including deepfakes, phishing, BEC, and the exploitation of aggregated personal data, to create highly convincing and effective attacks.
"Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels," noted Craig Porter, Director Analyst at Gartner. He emphasized that while traditional attack vectors like user reliance, stolen credentials, and weak recovery processes remain prevalent, the integration of AI amplifies their impact. CISOs are urged to apply the same rigor used for assessing identity and access risks to combat these evolving AI-driven social engineering threats.
The effectiveness of these attacks is amplified by the increasing difficulty in distinguishing real from AI-generated content. A Malwarebytes report suggests that nearly nine in ten adults now struggle to differentiate between authentic and AI-generated media. A prominent example cited is a 2024 incident in Hong Kong where a finance employee, deceived by a deepfake video call featuring impersonated executives, transferred over $25 million to fraudulent accounts.
To combat this escalating threat, Gartner recommends a three-pronged approach. Firstly, verification must become the default response for any high-risk request, regardless of the communication channel. This means moving beyond employee training to implement robust, automated verification processes for sensitive actions like account recovery, privileged access, and payment authorizations. Secondly, organizations need to deploy phishing-resistant authentication methods and risk-based identity controls that attackers cannot easily spoof.
Finally, effective detection requires connecting disparate pieces of information. Incident response playbooks must be updated to account for multimodal impersonation, manipulated AI recommendations, and compromised AI agents. By correlating suspicious communications and impersonation reports with account recovery events, new device authentications, privilege changes, and financial transactions, security teams can better identify and respond to sophisticated AI-driven attacks.
The challenge is compounded by the rapid advancement of generative AI models, which are making detection increasingly difficult. Researchers at the Vector Institute note that detection capabilities, when treated as a standalone technical solution, are losing ground to improving generative models. This arms race necessitates a proactive and adaptive security posture, integrating advanced verification, resilient authentication, and comprehensive threat intelligence to stay ahead of AI-powered adversaries.
The Gartner report further details the specific attack vectors, noting that 41% of CISOs experienced deepfake incidents via audio calls and 36% via video calls in the past year. It also highlights that traditional phishing and smishing/vishing remain prevalent, with 79% and 58% of CISOs reporting such incidents, respectively. Gartner analysts emphasize the need for organizations to shift from 'spot the fake' training to robust verification processes for critical actions and to implement stronger identity controls.