Deepfake social engineering is no longer a distant concern for security leaders. A new Gartner survey found that 41% of chief information security officers, or equivalent senior cybersecurity leaders, reported at least one employee audio-call incident involving a deepfake in the preceding 12 months. Another 36% reported one involving a video call.
The result does not measure the prevalence of successful fraud across all organizations, and it should not be read that way. It records what 297 cybersecurity leaders told Gartner in a survey conducted from March through May 2026. Even so, it is a useful operational signal: voice and video can no longer be treated as inherently stronger evidence of identity than a written message.
Why deepfake social engineering changes the verification problem
For years, staff training often emphasized suspicious email cues: an unfamiliar sender, a malformed link, a poorly written request, or a mismatch between a message and its claimed author. Those cues still matter. But a convincing synthetic voice or video call can move an urgent request into a channel that many people associate with a more direct form of proof.
That is where the survey’s finding matters. Gartner also reported that 79% of respondents had recorded at least one phishing, spear-phishing, or business-email-compromise incident in the prior 12 months, while 58% had reported a vishing or smishing incident. The point is not that every voice or video interaction is fake. It is that consequential requests—particularly those involving payments, account recovery, privileged access, or sensitive information—need a verification step that does not depend on the same communication channel that delivered the request.
A familiar executive voice asking for a fast transfer may create pressure, but it should not replace an established approval process. A video call that appears to show a colleague should not, by itself, authorize a password reset or a change to a supplier’s bank details. Independent confirmation through a known, trusted route is more durable than asking an employee to become a forensic-media expert in the moment.
Detection still matters, but process design matters more
The joint deepfake guidance published by the NSA, FBI, and Cybersecurity and Infrastructure Security Agency makes a similar distinction. It recommends real-time identity-verification procedures, including measures such as multi-factor authentication where appropriate, alongside preparation, response planning, and staff training. The guidance also advises organizations to preserve a copy of suspected media and assess its source before drawing conclusions.
Those measures support a practical shift in security culture. Instead of telling people only to “spot the fake,” organizations can make secure verification the normal response to high-risk requests, regardless of whether they arrive by email, voice, video, a collaboration tool, or an AI application. That approach is more resilient because it assumes that superficial signs of authenticity will continue to become less reliable.
The response workflow needs the same update. Gartner recommends correlating suspicious communications and impersonation reports with events such as account-recovery activity, new devices, privilege changes, and financial transactions. A security team investigating an impersonation report should be able to look beyond the call itself: Was a recovery request initiated? Did a new device appear? Did a payment instruction change? Were privileges modified? Connecting those signals can turn a vague report into a more testable incident record.
AI adds another place to define authority carefully
The concern is broader than synthetic media alone. As organizations add AI tools to communications and operations, they need clear rules for what a system may recommend, what it may do, and when a person must verify the action. This is particularly important when an AI agent can act through business systems rather than merely draft text. Unhyd’s guide to permission-first AI agent security explains why a distinct identity, narrowly scoped permissions, and meaningful approvals matter when software moves from analysis to action.
That principle also helps with impersonation defense. A request should not gain authority because it sounds like the right person, looks like the right person, or was summarized by a helpful system. Authority should come from an independently enforced process: verified identity, defined permissions, and approval tied to the exact action.
What security leaders should watch next
Gartner’s survey does not establish a universal incident rate, but it makes a clear case for reviewing where an organization still relies on familiar voices, faces, or urgency as a proxy for proof. The most exposed workflows are likely to be those where a plausible impersonation can trigger an irreversible outcome before someone checks a trusted system of record.
The next useful test is not whether an organization can detect every manipulated clip. It is whether a deceptive call, video, or message can bypass its controls. Teams that can answer that question with a documented verification path, an updated response playbook, and clear approval boundaries will be in a stronger position as synthetic media becomes a routine part of the social-engineering threat landscape.