Artificial intelligence is making social engineering attacks harder for companies to detect. A new Gartner survey found that 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months.
The survey also found that 36% of CISOs reported a deepfake incident during a video call. Gartner surveyed 297 senior cybersecurity leaders between March and May 2026.
Quick Fact
| Detail | Information |
|---|---|
| What Happened | Gartner reported rising AI driven social engineering and deepfake incidents. |
| Key Finding | 41% of CISOs reported at least one deepfake incident during an employee audio call. |
| Video Calls | 36% reported at least one deepfake incident during a video call. |
| Phishing and BEC | 79% reported at least one phishing, spear phishing, or business email compromise incident. |
| Vishing or Smishing | 58% reported at least one vishing or smishing incident. |
| Survey Period | March to May 2026 |
| Survey Participants | 297 senior cybersecurity leaders |
| Location | London, United Kingdom |
| Announcement Date | September 22, 2026 |
AI Fuels Social Engineering Attacks
Gartner says AI is changing how attackers conduct social engineering. Criminals can now combine phishing, stolen information, synthetic media, and personal details.
These methods can make an attack appear more believable. They can also make familiar warning signs less reliable.
Another 58% reported at least one vishing or smishing incident.
Deepfakes Are Changing Impersonation Attacks
Deepfake technology can imitate a person’s voice or appearance. Attackers can use these tools during calls and online meetings.
Gartner has separately warned about deepfake identity impersonation in voice channels and online meetings. The company says organizations should not rely on deepfake detection alone.
The growing risk means employees may need to verify sensitive requests through trusted channels. This matters most when a request involves money, account access, passwords, or other important business actions.
Three Steps Gartner Recommends
1. Build Better Security Habits
Gartner recommends moving beyond training that simply asks employees to identify fake content.
Organizations should make verification a normal part of high risk requests. Employees should pause and verify unusual requests, even when the message comes from a familiar voice or face.
Companies can also use security simulations to test how employees respond to suspicious AI related activity.
Gartner recommends moving beyond training that simply asks employees to identify fake content.
Organizations should make verification a normal part of high risk requests. Employees should pause and verify unusual requests, even when the message comes from a familiar voice or face.
Account recovery and privileged access need strong security controls.
Gartner recommends phishing resistant authentication and risk based identity controls. Organizations should also use trusted verification channels for sensitive actions.
These measures can help limit damage when attackers successfully impersonate an employee or executive.
3. Improve Detection and Response
Security teams should connect different warning signs.
For example, they can compare suspicious communications with account recovery activity, new devices, privilege changes, and financial transactions.
Gartner Survey Findings
Gartner conducted the survey between March and May 2026. It included 297 senior cybersecurity leaders who served as CISOs or held equivalent roles.
The results show that deepfake incidents now appear across both audio and video communications.
Gartner analysts are also discussing AI driven social engineering and agentic threats at the Gartner Security and Risk Management Summit in London from September 22 to September 24, 2026.
Security Teams Prepare for AI Threats
Organizations are likely to review their security training and identity controls as AI generated impersonation becomes more common.
Gartner recommends focusing on verification, identity assurance, and security operations that can identify AI mediated attacks.
The survey found that 41% of CISOs reported a deepfake incident during an employee audio call. Another 36% reported one during a video call.
At the same time, traditional phishing remains widespread. The findings point to a broader need for strong identity security, employee verification habits, and updated incident response plans.
