41% of CISOs Hit by Deepfake Social Engineering: Gartner

A new Gartner survey finds that 41% of chief information security officers reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, with 36% reporting one during a video call. The findings come from a survey of 297 senior cybersecurity leaders conducted between March and May 2026.
Gartner says AI is increasing the volume, personalization, and credibility of social engineering attacks while eroding the reliability of the cues people traditionally use to spot a fake. "Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels," said Craig Porter, Director Analyst at Gartner. He added that most attacks still rely on users, stolen credentials, weak recovery processes, and familiar technical methods.
Traditional channels remain the biggest source of incidents: 79% of CISOs reported at least one phishing, spear-phishing, or business email compromise incident, and 58% reported a vishing or smishing incident.
Gartner recommends CISOs take three actions. First, evolve static "spot the fake" training into adaptive programs that make pausing and verifying the default behavior for high-risk requests, regardless of channel, and test that behavior through workforce simulations.
Second, harden identity and recovery processes against impersonation. This means protecting account recovery, privileged access, and payment authorization with phishing-resistant authentication and risk-based controls, and detecting identity abuse even after a successful login.
Third, prepare detection and response specifically for AI-mediated threats. Gartner advises correlating suspicious communications with account recovery events, new devices, privilege changes, and financial transactions, and updating incident response playbooks to cover multimodal impersonation and misused AI agents.
Porter's core message is that CISOs should apply the same rigor used for identity and access management to counter AI-driven social engineering, rather than treating deepfakes as a separate problem.