Logo
FrontierNews.ai

Nearly Half of CISOs Report Deepfake Incidents as AI-Driven Social Engineering Surges

Nearly half of chief information security officers (CISOs) have encountered at least one deepfake incident in the past 12 months, signaling a critical shift in how organizations must defend against AI-powered social engineering attacks. A new Gartner study of 297 senior cybersecurity leaders reveals that AI is fundamentally changing the threat landscape, making attacks more personalized, credible, and difficult to detect using traditional methods.

What's Driving the Surge in AI-Powered Social Engineering?

The research, conducted between March and May 2026, found that AI is amplifying social engineering threats across multiple communication channels. Specifically, 41% of CISOs reported at least one deepfake incident during an employee audio call in the previous 12 months, while 36% reported one during a video call. Beyond deepfakes, the study uncovered a broader pattern of AI-driven attacks: 79% of CISOs experienced at least one email phishing, spearphishing, or business email compromise incident, and 58% reported voice phishing or SMS phishing attacks.

The threat extends beyond traditional deepfakes. In Singapore, 79% of organizations experienced at least one AI-related cyber threat in the past year, according to a separate study by ESET commissioned in partnership with Blackbox Research. Among those threats, AI-generated phishing and impersonation attacks were the most commonly reported at 46%, followed by exploitation of AI-powered tools such as prompt injection at 41% and AI-enabled deepfake or voice cloning attacks at 39%.

Why Are Traditional Detection Methods Failing?

The core problem is that AI is eroding the reliability of familiar detection cues that employees have been trained to recognize. Rather than teaching staff to "spot the fake," security experts now argue that organizations must shift their approach entirely. Craig Porter, director analyst at Gartner, emphasized that CISOs "must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats".

The challenge is particularly acute in financial services and technology sectors. In Singapore, 62% of financial services organizations and 55% of technology companies reported the highest levels of AI-generated phishing and impersonation attacks. This concentration suggests that attackers are targeting high-value sectors where successful breaches yield the greatest payoff.

How to Strengthen Your Organization Against AI-Driven Social Engineering

Gartner recommends three concrete measures that CISOs should implement immediately:

  • Shift Security Culture: Move away from teaching employees to "spot the fake" toward making secure verification the standard for consequential requests, with training, simulations, and clear expectations to pause, verify, and report suspicious activity across all communication channels
  • Protect High-Value Workflows: Secure account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, trusted verification channels, and measures that detect identity abuse after login or password resets
  • Update Incident Response Plans: Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions, while updating incident response playbooks to address multimodal impersonation, manipulated AI recommendations, and compromised or out-of-bounds AI agents

"Phishing remains effective because it targets people, and AI is making those attacks significantly more convincing. Deepfakes, impersonation and highly personalised messages are increasingly difficult to distinguish from legitimate communication," said Parvinder Walia, president of the APAC region at ESET.

Parvinder Walia, President of APAC Region at ESET

The Broader Cybersecurity Picture in 2026

AI-related threats are not occurring in isolation. Beyond AI-specific attacks, more than seven in ten organizations in Singapore (71%) experienced at least one major cybersecurity incident during the past year, with one in four experiencing three or more incidents. Cloud environment breaches, insider threats, and data exfiltration were the most common incidents reported.

The response challenge is equally daunting. While 76% of organizations said they could detect and respond to threats within 24 hours, delayed detection remained a top challenge cited by 55% of respondents. Nearly half (49%) cited a lack of visibility across environments, while 41% reported shortages of skilled cybersecurity professionals. These gaps suggest that organizations are struggling not just with new AI threats, but with fundamental visibility and resource constraints.

Phishing and social engineering attacks were the leading cause of incidents at 36%, followed by lack of visibility across IT environments at 34%, limited cybersecurity resources or skills shortages at 34%, and user actions or human error at 32%. This pattern underscores that cyber incidents are rarely the result of a single weakness, but rather a combination of people, process, and technology gaps.

What's Next for Enterprise AI Security?

Organizations are responding by expanding their cybersecurity investments. Managed Detection and Response (MDR), a service that provides continuous monitoring and threat response, was the most widely planned cybersecurity capability over the next 12 months, with 43% of organizations planning to adopt it. Cyber insurance is also gaining attention, with 36% planning to obtain coverage, though 97% of organizations reported challenges in obtaining or maintaining cyber insurance, with 43% citing stricter security requirements as a barrier.

The message from security leaders is clear: the era of annual awareness training and static defenses is over. As AI continues to evolve, organizations must adopt continuous learning, rapid response capabilities, and human-centered verification processes to stay ahead of increasingly sophisticated social engineering attacks.