Report: Social Engineering Attacks Are Increasingly Using Audio and Video Deepfakes

KnowBe4 Team | Sep 29, 2026

41% of CISOs said an audio deepfake targeted their organization within the last 12 months, according to a new survey by Gartner. Additionally, 36% of respondents said employees were targeted by deepfake video calls over the past year.

Craig Porter, Director Analyst at Gartner, noted that social engineering and human deception remain at the core of these AI-assisted attacks.

“Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels,” Porter said. “Most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods. CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”

Gartner recommends that organizations take the following steps to protect themselves:

  • “Evolve secure behavior and culture programs from teaching employees to ‘spot the fake,’ toward making secure verification the expected behavior for consequential requests. Train employees and approvers to pause, verify, and report high-risk requests regardless of whether the request arrives through e-mail, voice, video, collaboration tools, or an AI application. Use workforce simulations to test verification and reporting behavior of AI-related suspicious events.

  • Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, and trusted verification channels. In addition, implement controls to detect identity abuse, including after a successful login or password reset.

  • Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to improve threat detection. Update incident response playbooks for multimodal impersonation, manipulated AI recommendations, compromised or misused agents, and, where applicable, agents that operate beyond their intended boundaries.”

Gartner has the story: https://www.gartner.com/en/newsroom/press-releases/2026-09-22-gartner-survey-finds-41-percent-of-cisos-reported-at-least-one-social-engineering-incident-involving-a-deepfake-in-the-past-12-months

 

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.