Summary
- Forty-one per cent of surveyed CISOs reported a deepfake-related social engineering incident involving an employee audio call.
- Thirty-six per cent reported one involving video, although the survey does not show how many attacks succeeded.
- Verification procedures and identity controls provide more durable protection than expecting employees to recognise synthetic media unaided.
Video calls and familiar voices are becoming weaker evidence that the person on the other end is who they claim to be, with new Gartner research suggesting that deepfake-assisted social engineering has already entered ordinary corporate communications.
Among 297 senior cybersecurity leaders surveyed between March and May 2026, 41% reported at least one social-engineering incident involving a deepfake during an employee audio call in the previous 12 months, while 36% reported an incident during a video call.
The figures describe reported incidents rather than successful compromises and do not establish how many resulted in financial loss or unauthorised access. Conventional attacks also remained more common, with phishing, spear phishing, and business-email compromise appearing more frequently in the survey.
Synthetic media nevertheless weakens several cues employees have traditionally used when judging whether a request is authentic. A convincing cloned voice or generated video can reproduce the authority of the person an attacker wants to impersonate rather than relying solely on a fraudulent email address or poorly written message.
Detection gives way to verification
Security-awareness programmes have often trained employees to look for anomalies in wording, domains, links, or behaviour. Deepfakes weaken that approach because attackers can reproduce more of the signals people associate with trust.
Independent verification therefore becomes more dependable than attempting to identify synthetic media by sight or sound. Requests involving payment details, privileged access, sensitive information, or unusual exceptions can be checked through another trusted channel regardless of how convincing the caller appears.
That shifts part of the defence into business-process design. If a finance employee can release a large payment solely because a senior executive appears on video, the vulnerability sits partly inside the approval process. A second authorised person, a known callback mechanism, transaction limits, or another identity factor can stop the action even when the deepfake itself is difficult to recognise.
Old attacks gain new channels
The underlying fraud is not new. Business-email compromise has long relied on impersonating executives, suppliers, lawyers, or customers, while criminals have manipulated helpdesks and finance teams by phone for decades.
Generative AI allows those attacks to move more easily across email, messaging, voice, and video. Publicly available information, previous data breaches, social networks, and stolen communications can make the impersonation more specific to the employee being targeted.
A single attack can consequently build context over several channels: an email establishes the request, a message reinforces urgency, and a cloned voice or video provides apparent confirmation when the employee hesitates.
Identity controls outlast individual detectors
No organisation can assume that one technical deepfake detector will remain reliable as generation systems improve. Detection models and synthetic-media tools will continue to evolve against one another, while ordinary employees cannot reasonably be expected to know which visual or audio artefacts still indicate manipulation.
More durable controls sit around the transaction. Phishing-resistant authentication can reduce the usefulness of stolen credentials, trusted callback procedures can separate a request from its verification, and approval controls can prevent one impersonated executive from authorising a consequential action.
Those measures also work against attacks using no deepfake at all, which is important because Gartner’s own figures show conventional phishing and business-email compromise remain more prevalent.
The survey does not demonstrate that two-fifths of all companies have lost money to deepfakes. It records the experiences of 297 senior security leaders and measures incidents rather than successful fraud. Even with that limitation, synthetic audio and video appearing so frequently indicates that organisations can no longer sensibly treat them as an exotic threat.
A voice can be copied and a face can be generated, which makes the process used to establish authority increasingly more valuable than the realism of the person making the request.












