# What happened
A Gartner survey of senior cybersecurity leaders found substantial use of synthetic audio and video in social engineering attacks during the previous 12 months. According to the survey summary cited by KnowBe4, 41% of CISOs reported at least one audio deepfake targeting their organisation, and 36% reported deepfake video calls aimed at employees.
Craig Porter, Director Analyst at Gartner, described how attackers now blend traditional social engineering with synthetic media and aggregated personal context across channels. He said most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods.
# Why it matters
Deepfakes raise two practical problems for defenders. First, synthetic audio and video increase the credibility of impersonation attacks and make cues people used to rely on less reliable. Second, these attacks are multimodal: they can arrive by e-mail, voice, video, collaboration apps, or even AI applications, making detection and response more complex.
# Gartner's recommended steps (actionable items)
- Use workforce simulations to test how employees handle AI-related suspicious events and verification prompts.
- Protect high-value workflows (account recovery, privileged access, payment authorization) with phishing-resistant authentication, risk-based identity controls, and trusted verification channels.
- Implement controls to detect identity abuse even after a successful login or password reset.
- Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to improve threat detection.
- Update incident response playbooks to cover multimodal impersonation, manipulated AI recommendations, compromised or misused agents, and agents that operate beyond intended boundaries.
# Practical implications for security teams
Security teams should treat deepfake-enabled social engineering as an evolution of existing human-targeted attacks rather than a wholly new category. The core defensive focus remains identity, authentication, recovery processes, and user behavior — but executed with more discipline and broader coverage across channels.
- Review account recovery and privileged-access processes for weak steps attackers can exploit.
- Add verification steps for wire transfers and other financial authorizations that do not rely solely on e-mail or voice confirmation.
- Expand monitoring to look for patterns linking impersonation attempts to account changes or unusual device activity.
- Run simulations that include synthetic media scenarios so employees and approvers practice the pause-and-verify habit.
# What to watch next
Expect more incidents combining phishing, business email compromise, synthetic media, and aggregated personal data. Organisations that leave recovery processes, identity controls, or verification practices unchanged are more exposed to repeatable, high-impact fraud. Incident response playbooks should be revised to cover multimodal attacks and the possibility of manipulated AI agents.