witness
← All posts
cybersecurity·Sep 18, 2026·4 min read

41% of CISOs Report Deepfake Attacks on Employee Calls: What the Gartner Data Shows

Gartner survey of 297 security leaders finds 41% experienced deepfake social engineering on audio calls. Voice and video deepfakes are the fastest-growing attack vector.

WT
Witness Team
Editorial
𝕏in
41% of CISOs Report Deepfake Attacks on Employee Calls: What the Gartner Data Shows

Deepfake attacks on business communications have moved from theoretical risk to operational reality. A new survey from the Gartner Security & Risk Management Summit puts hard numbers on what security leaders are facing: 41% of organizations have already been targeted.

The Numbers

Gartner surveyed 297 senior cybersecurity leaders and released the findings at their 2026 Security & Risk Management Summit. The headline finding: 41% of respondents experienced at least one deepfake-based social engineering incident on an audio call in the past year. 36% reported the same on video calls.

For context, 79% reported phishing or business email compromise incidents during the same period. Email-based attacks are still more common, but voice and video deepfakes are the fastest-growing attack vector in the survey. The gap between email threats and deepfake threats is closing faster than most security teams expected.

How These Attacks Work

The typical deepfake social engineering attack follows a predictable pattern. An attacker uses AI-generated voice or video to impersonate a senior executive, a known vendor, or a trusted colleague during a live call. The impersonation creates urgency around a financial transaction, credential handoff, or data access request.

What makes these attacks effective is the trust layer that voice and video add. Most employees have been trained to scrutinize emails for phishing indicators. Few have been trained to question whether the person on a video call is real. The psychological barrier to challenging someone you can "see" and "hear" is significantly higher than questioning a text-based message.

The attacks are also getting cheaper to execute. Voice cloning requires only a few seconds of sample audio. Real-time face-swapping tools are commercially available. An attacker no longer needs advanced technical skills or expensive equipment to mount a convincing deepfake call.

What Security Teams Are Doing Wrong

The Gartner data reveals a gap between awareness and preparedness. Most organizations that experienced a deepfake attack had some form of security awareness training in place. The problem is that existing training programs were designed for text-based threats.

Common gaps include:

  • No verification protocol for unexpected financial requests made over voice or video calls
  • No secondary confirmation channel (calling back on a known number, using an internal messaging system)
  • No training on the specific indicators of real-time deepfake video (latency artifacts, lighting inconsistencies, unnatural blinking patterns)
  • Over-reliance on "I would know if it was fake" confidence, which the data contradicts

What This Means for You

If you work in any organization that handles financial transactions, sensitive data, or executive communications, this data applies to you. A 41% incidence rate means deepfake attacks are not a future risk. They are a current one.

The most effective immediate step is implementing a callback verification protocol. Any unexpected request for money, credentials, or sensitive data made over voice or video should be confirmed through a separate channel, regardless of who appears to be making the request. This single policy change blocks the majority of deepfake social engineering attempts.

For individuals, the same principle applies to personal calls. If someone you know calls with an urgent financial request, hang up and call them back on a number you already have saved.

Verify What You See

Deepfake detection is not just for images on social media. The same AI manipulation techniques used in business calls are used in fake videos, fraudulent profile photos, and synthetic media across the web. Check suspicious visual content at witness.vision/scan or install the Witness Chrome extension to scan images as you browse.

Scan now at witness.vision/scan

WT
Witness Team
Editorial at Witness. Building a second pair of eyes for everything you see online.
Try Witness →