Almost half of CISOs have reported at least one deepfake incident in the past 12 months, highlighting the need to update incident response playbooks to address multimodal deepfake threats.
As the opening of the Gartner Security & Risk Management Summit in London on September 22, the global consulting firm published findings from its AI-driven Social Engineering Attacks report, which surveyed 297 senior cybersecurity leaders.
The study, conducted between survey conducted in March and May 2026, found that AI is increasing the volume, personalization and credibility of social engineering while reducing the reliability of familiar detection cues.
More than four in ten respondents (41%) reported at least one social engineering incident involving a deepfake during an employee audio call in the previous 12 months and 36% reported one during a video call.
Additionally, 79% of CISOs surveyed reported at least one email phishing, spearphishing, or business email compromise (BEC) incident in the last 12 months, while 58% reported one vidoe phishing (vishing) or SMS phishing (smishing) incident.
Craig Porter, director analyst at Gartner, said that as most attacks will continue to rely on users, stolen credentials, weak recovery processes and familiar technical methods, CISOs “must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”
How CISOs Can Mitigate Deepfake Phishing Threats
To effectively counter evolving AI social engineering attacks, Porter’s team shared three measures CISOs should take:
- Shift secure behavior and culture programs from teaching employees to “spot the fake” toward making secure verification the standard for consequential requests, with training, simulations, and clear expectations to pause, verify, and report suspicious activity across all communication channels
- Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, trusted verification channels, and measures that detect identity abuse after login or password resets
- Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions, while updating incident response playbooks to address multimodal impersonation, manipulated AI recommendations, and compromised, misused, or out-of-bounds AI agents