Knowbe4 iconKnowbe4Sep 29, 2026 ~3 min source read

Gartner survey: audio and video deepfakes are increasingly used in social engineering attacks

A Gartner survey reported that 41% of CISOs saw audio deepfakes and 36% saw deepfake video calls targeting their organisations in the past year. Gartner says the attacks combine familiar social engineering techniques with synthetic media and recommends shifting verification practices and strengthening identity controls.

Report: Social Engineering Attacks Are Increasingly Using Audio and Video Deepfakes

Share this story

Send the public story page.

Useful takeaways from this story.

Gartner: AI boosts volume, personalization, and credibility of social engineering while reducing reliability of traditional detection cues.

Practical defenses include training employees to verify consequential requests, using phishing-resistant authentication, and updating incident response playbooks for multimodal impersonation.

Detect identity abuse by correlating suspicious communications with account recovery, new devices, privilege changes, and financial transactions.

# What happened

A Gartner survey of senior cybersecurity leaders found substantial use of synthetic audio and video in social engineering attacks during the previous 12 months. According to the survey summary cited by KnowBe4, 41% of CISOs reported at least one audio deepfake targeting their organisation, and 36% reported deepfake video calls aimed at employees.

Craig Porter, Director Analyst at Gartner, described how attackers now blend traditional social engineering with synthetic media and aggregated personal context across channels. He said most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods.

# Why it matters

Deepfakes raise two practical problems for defenders. First, synthetic audio and video increase the credibility of impersonation attacks and make cues people used to rely on less reliable. Second, these attacks are multimodal: they can arrive by e-mail, voice, video, collaboration apps, or even AI applications, making detection and response more complex.

# Gartner's recommended steps (actionable items)

  • Use workforce simulations to test how employees handle AI-related suspicious events and verification prompts.
  • Protect high-value workflows (account recovery, privileged access, payment authorization) with phishing-resistant authentication, risk-based identity controls, and trusted verification channels.
  • Implement controls to detect identity abuse even after a successful login or password reset.
  • Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to improve threat detection.
  • Update incident response playbooks to cover multimodal impersonation, manipulated AI recommendations, compromised or misused agents, and agents that operate beyond intended boundaries.

# Practical implications for security teams

Security teams should treat deepfake-enabled social engineering as an evolution of existing human-targeted attacks rather than a wholly new category. The core defensive focus remains identity, authentication, recovery processes, and user behavior — but executed with more discipline and broader coverage across channels.

  • Review account recovery and privileged-access processes for weak steps attackers can exploit.
  • Add verification steps for wire transfers and other financial authorizations that do not rely solely on e-mail or voice confirmation.
  • Expand monitoring to look for patterns linking impersonation attempts to account changes or unusual device activity.
  • Run simulations that include synthetic media scenarios so employees and approvers practice the pause-and-verify habit.

# What to watch next

Expect more incidents combining phishing, business email compromise, synthetic media, and aggregated personal data. Organisations that leave recovery processes, identity controls, or verification practices unchanged are more exposed to repeatable, high-impact fraud. Incident response playbooks should be revised to cover multimodal attacks and the possibility of manipulated AI agents.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app