A recent Gartner survey of chief information security officers reveals that deepfake technology has become a practical tool for cybercriminals targeting enterprises. According to the survey, 41% of CISOs said their organization experienced at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months. A further 36% reported the same for video calls, indicating that both audio and visual channels are being exploited.
The numbers highlight a shift from traditional phishing emails to more immersive, harder-to-detect attacks. Deepfakes allow attackers to impersonate executives or colleagues in real time, potentially bypassing security awareness training that focuses on text-based scams. The survey's findings give CISOs reason to reassess their incident response plans and invest in detection tools that can spot synthetic media.
While the source does not provide comparative data from previous years, the sheer scale of reported incidents suggests deepfake social engineering is no longer a niche concern. The report implies that organizations should treat deepfake attacks as a realistic scenario in their threat modeling, rather than a distant possibility. However, the source does not break down the severity or success rate of these incidents, so the full impact remains unclear.