A Gartner survey of 297 CISOs reveals that 41% experienced deepfake-related social engineering incidents on audio calls and 36% on video calls in the past year. The findings underscore how AI is amplifying social engineering attacks through synthetic media, forcing enterprise security leaders to rethink detection methods and implement hardened identity verification protocols.

Deepfake Risk Escalates as CISOs Report Widespread Incidents

A Gartner survey conducted between March and May 2026 has exposed the alarming scale of deepfake risk facing enterprise security teams. Among 297 senior cybersecurity leaders surveyed, 41% of CISOs reported at least one deepfake-related social engineering incident during employee audio calls in the previous 12 months, while 36% encountered incidents during deepfake video calls

1

2

. These figures signal a fundamental shift in how attackers exploit AI to bypass traditional security measures.

The Gartner survey reveals that traditional phishing remains pervasive, with 79% of CISOs reporting at least one email phishing, spear-phishing, or business email compromise incident in the last 12 months. Additionally, 58% reported vishing or smishing incidents

1

2

. What distinguishes current threats is AI's ability to increase the volume, personalization, and credibility of social engineering attacks while simultaneously reducing the reliability of familiar detection cues that security teams have relied upon for years.

AI Amplifies Social Engineering Attacks Through Synthetic Media

Craig Porter, Director Analyst at Gartner, explains the evolving threat landscape: "Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels"

1

2

. This multimodal approach represents a significant escalation in cybersecurity risks, as attackers leverage AI-mediated threats to orchestrate sophisticated impersonation schemes that span email, voice, video, and collaboration platforms.

The implications extend beyond individual incidents. Porter emphasizes that most attacks will continue exploiting users, stolen credentials, weak recovery processes, and familiar technical methods. CISOs must apply the same rigorous discipline used to assess identity and access risks when combating AI-driven social engineering threats

1

. The convergence of deepfake audio calls and deepfake video calls with traditional attack vectors creates a threat environment where verification becomes paramount.

Transform Static Training Into Adaptive Security Training Programs

Gartner recommends CISOs shift from teaching employees to "spot the fake" toward establishing secure verification as the expected behavior for consequential requests. This adaptive security training approach requires organizations to train employees and approvers to pause, verify, and report high-risk requests regardless of delivery channel—whether through email, voice, video, collaboration tools, or AI applications

1

2

.

Workforce simulations become critical tools for testing verification and reporting behavior related to AI-related suspicious events. As deepfake technology becomes more sophisticated, static training modules that focus on identifying fake content will prove insufficient. Enterprise security strategies must evolve toward building organizational cultures where verification protocols are automatic responses rather than exceptional procedures.

Implement Hardened Identity Verification Against Impersonation

Protecting high-value workflows demands robust controls. Gartner advises CISOs to secure account recovery, privileged access, and payment authorization processes with phishing-resistant authentication, risk-based identity controls, and trusted verification channels

1

2

. Hardened identity verification extends beyond initial authentication to include detection controls for identity abuse, even after successful logins or password resets.

This layered approach acknowledges that impersonation attacks leveraging synthetic media can compromise even authenticated sessions. Organizations must monitor for anomalous behavior patterns that suggest account takeover or credential misuse, particularly when combined with deepfake-enabled social engineering tactics.

Prepare Detection and Response for Emerging AI-Mediated Threats

CISOs must update incident response playbooks to address multimodal impersonation scenarios, manipulated AI recommendations, and compromised or misused agents. Gartner emphasizes correlating suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to strengthen detection and response capabilities

1

.

The future threat landscape will likely include agents operating beyond intended boundaries, requiring security teams to establish monitoring frameworks that can identify when AI systems deviate from authorized parameters. As attackers refine their use of synthetic media and AI-driven personalization, organizations that fail to adapt their detection mechanisms will face mounting cybersecurity risks. The Gartner survey data suggests that deepfake incidents are no longer hypothetical concerns but present realities demanding immediate strategic response from enterprise security leadership.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved