Gartner CISOs Report Surge in Deepfake Social Engineering Incidents
Article Content
- •41% of CISOs reported deepfake incidents in audio calls over the past year.
- •79% experienced email phishing incidents, indicating a broader trend in social engineering.
- •Gartner recommends updating incident response playbooks to address AI-driven threats.
A Gartner survey reveals that 41% of CISOs experienced social engineering incidents involving deepfakes during audio calls, while 36% reported similar incidents in video calls over the past year. The survey, conducted with 297 cybersecurity leaders, highlights that AI is enhancing the volume and credibility of these attacks, making traditional detection methods less effective. Additionally, 79% of CISOs reported email phishing incidents, and 58% noted vishing or smishing incidents. To combat these threats, Gartner recommends that CISOs update their incident response playbooks and shift training towards secure verification practices. The findings were presented at the Gartner Security & Risk Management Summit in London on September 22, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Clop, ShinyHunters and RatHat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
PaperCut NG/MF Vulnerability Under Active Exploitation On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code remotely, compromising server configurations. Emergency patches have been released for versions 25 and…