Deepfake Threats: CISOs Face Rising Cybersecurity Risks
AI is enabling cybercriminals to penetrate organizational structures more effectively than traditional phishing methods.
Gartner Survey Reveals Alarming Deepfake Threats
A Gartner survey reveals that 41% of chief information security officers (CISOs) encountered at least one social engineering incident involving deepfake audio during employee calls within the past year. Additionally, 36% reported similar incidents during video conferences. The same study found that 79% of CISOs experienced at least one phishing, spear-phishing, or business email compromise incident, while 58% faced voice phishing (vishing) or SMS phishing (smishing) attacks.
Threat Actors Leverage Advanced Tactics
Threat actors are leveraging a combination of phishing tactics, business compromise strategies, synthetic media, and aggregated personal data across multiple communication channels, according to Craig Porter, a director analyst at Gartner. Most attacks continue to exploit human vulnerabilities, stolen credentials, and outdated recovery processes, alongside conventional technical methods.
CISOs must apply the same rigorous risk assessment frameworks used for identity and access management to address AI-driven social engineering threats, Porter emphasized.
Gartner’s Three Critical Mitigation Steps
- Shifting from employee training to institutionalizing verification as the default response for high-risk requests, regardless of communication channel.
- Implementing phishing-resistant authentication mechanisms, risk-based identity controls, and secure verification channels for critical workflows such as account recovery, privileged access, and payment authorization.
- Enhancing threat detection by correlating suspicious communications with account recovery patterns and updating incident response protocols to address multimodal impersonation, AI-generated recommendations, and compromised or misused agents.
AI Fraud Becomes Harder to Detect
AI fraud is increasingly difficult to detect as generative technologies advance. A Malwarebytes report indicates that 90% of adults struggle to distinguish AI-generated content from authentic material. A 2024 case in Hong Kong exemplifies this challenge: a finance employee at a multinational corporation’s branch participated in a video call believing it included the company’s CFO and colleagues, only to transfer $25 million to accounts controlled by attackers.
Global Concerns Over AI-Powered Fraud
A Jumio survey highlights growing concerns, with 69% of global respondents asserting that AI-powered fraud now poses a greater personal security risk than traditional identity theft. North Korean operatives are reportedly using deepfake technology to infiltrate Western companies as remote IT workers. Researchers at the Vector Institute warn that standalone deepfake detection tools are becoming obsolete as generative models evolve, making proactive mitigation strategies essential.
Adapting to an Evolving Threat Landscape
The report underscores the need for enterprises to adapt to an evolving threat landscape where AI amplifies existing attack vectors. CISOs are advised to prioritize layered defenses, continuous monitoring, and updated response protocols to counteract the sophistication of AI-driven deception techniques.
