Infosecurity Magazine iconInfosecurity MagazineSep 28, 2026 ~5 min source read

Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns

A Pindrop survey finds most security leaders saw suspected deepfake incidents in the past year; a quarter of victims reported losses above $1 million and most CISOs doubt boards grasp the risk.

Share this story

Send the public story page.

Useful takeaways from this story.

74% of surveyed US security leaders reported a suspected deepfake incident in the past 12 months.

93% of security leaders said their organization is not prepared to face deepfake attacks, and many expect board attention only after a high-profile impersonation.

Practical defences include staff training to spot impersonations, phishing-resistant controls like MFA, and updated incident response playbooks.

The useful part

The 2026 Pindrop Deepfake Readiness Index, published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them. The technology has become increasingly sophisticated, making it difficult for anyone watching or listening to the deepfake to tell that it isn't footage of a real person. Cybercriminals have turned to deepfakes as part of hacking and fraud campaigns.

How it works

  • It has even been known for North Korean nation-state hackers to use deepfakes to pose as fake IT workers looking for jobs to get hired by technology and software companies.
  • The financial cost of deepfake attacks included direct losses, as well as the costs associated with remediating the incident, as well as the time and resources it took staff to work in response to the attack.
  • Deepfakes turn our most instinctive signals of identity, a familiar face and voice, into an attack surface," said Elie Khoury, SVP of research at Pindrop.
  • Opinion 12 November 2025 1 Japanese Railway Operators Hit with Weekend Cyber Attacks News 29 September 2026 2 Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk News 25 September...
  • Enforcing AI Authority Before the Action Webinar 15:00 — 16:00, 8 October 2026 1 Experts Alarmed Over Gyazo's Breach of 490 Million Metadata Records News 21 September 2026 2 US:

What to take from it

Pindrop's survey of over 250 US security leaders found that 74% said they have encountered a suspected deepfake attack in the last 12 months. Of those, one in four reported losses of over $1m because of a single incident, while nearly half (49%) of those hit by deepfake attacks reported losses of $500,000. Meanwhile, 93% of security leaders expressed concern that their organization is not currently prepared to face the threat posed by deepfake attacks.

Example or evidence

  • They are used to pose as someone like a colleague, their boss or their CEO and trick victims into sharing sensitive information or making a fraudulent financial transfer.
  • "Attackers have figured out that one of the easiest ways around sophisticated security controls is to impersonate the human those controls are designed to trust.
  • "Enterprises need to bring the same rigor used to secure systems and devices to the live human interactions where critical decisions are being made," he added.
  • How to Secure AI at Enterprise Scale Webinar 11:00 — 12:00, 17 September 2026 2 Frontier AI:

Details worth keeping

Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns. Deepfakes are AI generated audio and videos of people. According to the report, three in four respondents said that it would take a company leader being impersonated in – or fooled by – a deepfake attack before the deepfake cybersecurity challenge deepfakes becomes a board level or leadership issue.

Related coverage

  • Theguardian: Influencers aren't just battling competitors for brand deals.
  • Hrdive: As technology evolves, employers must consider new issues when conducting harassment investigations, writes Tracey Diamond, a partner at Troutman Pepper Locke.
  • Scotsman: Deception has been industrialised by the use of AI deepfakes to defraud businesses on a grand scale, warns ​​James McGachie
  • Wired: An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app