Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.
“Nearly half of all alerts (53.83%) of executive impersonation threats stem from social platforms,” Outtake says. “Video and visual platforms follow at 35.05%, with open community forums (6.84%) and executive lookalike domains (3.57%) rounding out the remainder. Yet the per-executive risk profile varies sharply: most executives (76.2%) see nearly all activity concentrated on one surface, while others (23.8%) face attacks distributed thinly across social, lookalike domains, forums, and broker-site PII exposure simultaneously.”
Notably, threat actors are using AI tools to dramatically accelerate these attacks. AI can speed up reconnaissance to craft convincingly spoofed profiles, while deepfake technology can generate images and videos of executives that are indistinguishable from real life.
“Attackers use AI to skip your internal security tools completely,” the researchers explain. “There's less need to break through data, network, cloud, and endpoint security perimeters when adversaries can just impersonate an executive out on the open internet, where those tools don't watch. They target your most visible leaders on purpose because a trusted name gets them to the money faster than anything inside your network. And it lands on a handful of executives, not the whole team.”
Outtake has the story: Majority of Enterprises Hit by Executive Impersonation as C-Suite Becomes the Fastest-Growing Attack Surface
