Security News

Deepfake Scams Are Hitting Businesses Hard, New Report Finds

Infosecurity Magazine · 28 Sept 2026
Key Takeaway Australian SMBs should train staff to verify unusual requests for money or sensitive data through a second, trusted communication channel, especially when the request appears to come from a senior leader.

A new report from Pindrop, the 2026 Deepfake Readiness Index, has found that 74% of surveyed US security leaders experienced a suspected deepfake incident in the last 12 months. Of those affected, one in four reported losses exceeding $1 million from a single attack, while nearly half reported losses of at least $500,000. These costs include direct financial theft as well as the time and resources spent responding to and recovering from the incident.

Deepfakes are AI-generated audio or video that convincingly imitate a real person, making them a powerful tool for scammers. Criminals have used them to impersonate colleagues, executives or bosses to trick employees into transferring funds or sharing sensitive data. In some cases, nation-state hackers have even used deepfakes to pose as job applicants and gain employment inside technology companies.

Despite these risks, the report found a worrying gap between the scale of the threat and business preparedness. Three in four respondents believe it would take a senior leader actually being impersonated or fooled before deepfakes are taken seriously at board level, and 93% of security leaders said their organisation is not currently ready to handle the threat.

deepfakes fraud AI security business email compromise cybersecurity awareness
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.