Nearly Half of CISOs Report Deepfake Attacks: Time to Update Your Response Plan
New research from Gartner has found that almost half of cybersecurity leaders have dealt with at least one deepfake incident in the past year, a sign that AI-powered scams are becoming mainstream rather than rare. The findings, released at the Gartner Security & Risk Management Summit in London, come from a survey of 297 senior security leaders conducted between March and May 2026.
The study found that 41% of respondents had experienced a social engineering incident involving a deepfake during an audio call with an employee, while 36% reported one during a video call. More broadly, 79% had faced email phishing, spearphishing or business email compromise in the last year, and 58% had dealt with voice phishing or SMS phishing attempts. Gartner's Craig Porter noted that most attacks still rely on tricking users, stolen credentials and weak account recovery processes, meaning the fundamentals of identity and access security remain central to defence even as AI raises the sophistication of scams.
Gartner's analysts recommend that security leaders treat AI-driven impersonation with the same rigour applied to identity and access risk management, updating incident response playbooks so staff know how to verify unusual requests made by voice or video before acting on them.