Phishing Remains Most Common Attack Vector

Gartner: 41 Percent of CISOs Report Deepfakes

Deepfake Shutterstock
Facebook
X
LinkedIn
Reddit
WhatsApp

According to a Gartner survey, 41 percent of CISOs reported social engineering incidents involving deepfakes during phone calls, and 36 percent during video calls.

A new survey by market research firm Gartner shows that deepfakes already play a significant role in social engineering attacks against companies. A total of 297 chief information security officers (CISOs or equivalent positions) were surveyed between March and May 2026.

Ad

Phishing Remains Most Common Attack Vector

41 percent of surveyed CISOs reported at least one social engineering incident involving the use of deepfakes during an audio call with an employee over the past twelve months, while 36 percent reported a corresponding incident during a video call. Despite this new form of attack, traditional phishing remains the most common attack vector: 79 percent of respondents reported at least one incident involving email phishing, spear phishing, or business email compromise, and 58 percent reported at least one vishing or smishing incident. According to Gartner, AI increases the volume, personalization, and credibility of social engineering attacks while simultaneously reducing the reliability of familiar detection indicators. Craig Porter, Director Analyst at Gartner, explained:

“Attackers can combine phishing, business email compromise, synthetic media, and merged personal context across multiple channels.”

— Craig Porter, Director Analyst at Gartner

Ad

According to Porter, however, most attacks still rely on users, stolen credentials, weak recovery processes, and known technical methods, which is why CISOs should address AI-powered social engineering threats with the same diligence as identity and access risks.

Three Recommended Measures for CISOs

Gartner outlines three key measures companies can take to counter AI-powered social engineering attacks. First, static training programs should be evolved into adaptive security programs that do not merely train employees to recognize fakes, but encourage them to consistently pause, verify, and report high-consequence requests regardless of the channel—whether email, voice, video, collaboration tools, or AI applications.

Second, identity and recovery processes must be safeguarded against identity abuse, for instance through phishing-resistant authentication and risk-based identity controls during sensitive workflows such as account recovery, privileged access, and payment approvals.

Third, detection and response processes should be prepared for AI-mediated threats by cross-referencing suspicious communications and identity abuse reports with account recoveries, new devices, permission changes, and financial transactions. Additionally, emergency plans should be expanded to include scenarios such as multichannel identity forgery, manipulated AI recommendations, and AI agents that are compromised or operating outside their intended boundaries.

(Editorial Team)

Ad

Weitere Artikel