Gartner found that AI-enabled deepfake impersonation is making social-engineering attacks more convincing across phone calls, video conferences, email, and text messages. Of 297 senior cybersecurity leaders surveyed, 41% reported a deepfake-related employee audio-call incident and 36% reported a video-call incident in the preceding 12 months; 79% encountered phishing, spear-phishing, or business-email-compromise activity. A prominent example was the 2024 fraud against engineering firm Arup, where video-call impersonations of colleagues persuaded an employee to transfer more than $25 million to criminal-controlled accounts.
Gartner urged organizations to replace training focused on spotting fakes with mandatory, out-of-band verification for sensitive requests. CISOs should apply phishing-resistant and risk-based identity controls to high-value workflows, correlate suspicious communications with identity, device, privilege, and payment activity, and extend incident-response plans to cover multimodal impersonation and compromised AI agents.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Gartner surveyed 297 senior cybersecurity leaders between March and May 2026 on social-engineering incidents and related defenses.
A Ferrari executive reportedly thwarted a deepfake voice attack by asking the caller about a book recommendation known to the genuine executive.
A finance employee at a multinational firm's Hong Kong branch was induced by a fraudulent video call impersonating the CFO and colleagues to transfer more than $25 million to scammer-controlled accounts. IT Pro identified the company as British engineering firm Arup.
A separate incident involved deepfake voice notes impersonating an executive to convince an employee to download malware.
Gartner reported that 41% of surveyed CISOs had seen a deepfake-related employee audio or phone-call social-engineering incident and 36% had seen one involving video calls during the prior 12 months. It advised independent verification for risky requests and stronger identity, payment, and incident-response controls.
Google warned that criminal groups were abusing Gemini and other large language models to research and target victims.
The FBI warned of a campaign in which attackers used text and voice communications to impersonate senior U.S. officials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.