A Gartner survey of 297 CISOs and equivalent cybersecurity leaders found that 41% reported at least 1 social engineering incident involving a deepfake during an employee audio call in the previous 12 months. Another 36% reported one during a video call.
Conducted from March through May 2026, the survey found that familiar forms of social engineering remain prevalent.
Gartner says AI is making these attacks more credible and harder to identify using familiar detection cues.
Why It Matters: AI-generated impersonation can make existing social engineering techniques more convincing across workplace communications. Attackers can pair synthetic media with phishing or business email compromise and incorporate personal context into fraudulent requests. Gartner’s guidance centers on verification, identity protections, and response processes that do not depend on employees recognizing a fake.
- Social Engineering Remains Widespread: 79% of surveyed CISOs reported at least 1 email phishing, spear-phishing, or business email compromise incident in the previous 12 months, while 58% reported a vishing or smishing incident. The deepfake findings add another dimension to that threat, especially when synthetic audio or video can reinforce an impersonation attempt. Gartner expects many attacks to continue relying on stolen credentials and weaknesses in recovery processes.
- Verification Becomes More Important When Familiar Cues Are Unreliable: Gartner recommends moving security behavior programs away from simply teaching employees to “spot the fake.” Consequential requests should trigger a verification process regardless of how convincing the communication appears or which channel is used. Workforce simulations can then test whether employees follow those procedures when confronted with suspicious AI-related activity.
- Identity Protections Can Contain a Successful Impersonation Attempt: Gartner calls for stronger safeguards around sensitive workflows such as account recovery and privileged access. Phishing-resistant authentication and trusted verification channels can make impersonation alone less useful to an attacker. Monitoring should continue after authentication to detect identity abuse following a successful login or password reset.
- Detection Improves When Suspicious Communications Are Connected to Related Activity: An impersonation report may carry more meaning when it coincides with an account recovery event or a newly registered device. Gartner recommends correlating communications with identity and financial activity so security teams have more context when investigating a suspected attack.
- Response Plans Need to Cover Attacks Involving AI: Gartner recommends updating incident response playbooks for multimodal impersonation and manipulated AI recommendations. The guidance also accounts for AI agents that are compromised, misused, or operating outside their intended boundaries. These scenarios extend existing response requirements into systems where AI can influence actions or decisions.


