Pindrop's 2026 Deepfake Readiness Index shows that real-time communications have become a primary target for AI impersonation. Attackers are using deepfakes in phone calls to IT help desks, remote job interviews, and video meetings to pose as trusted people. The report found that nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, but only 10% say their organizations have purpose-built defenses.
The financial impact can be severe. Among organizations that experienced or suspected an attack, nearly half reported total costs of $500,000 or more, and about a quarter reported costs of at least $1 million. Forty-nine percent said the attack led to follow-on cyberattacks such as ransomware, and respondents also cited data breaches, lost revenue, exposure of sensitive information, and stolen funds.
Despite the threat, investment lags. Three-quarters of respondents said deepfakes would become a boardroom priority only after a leader at their organization was personally fooled or impersonated. Treating deepfakes mainly as a reputational risk for public figures can delay enterprise defenses. Thirty-seven percent said a single deepfake attack could put their company out of business, including 17% who called that outcome extremely likely or certain. Still, 74% of security leaders believe defenses will improve faster than attack quality.