A survey found that 41 percent of chief information security officers experienced at least one social engineering attack over the past 12 months that exploited deepfakes in employee voice calls. The share who said they experienced the same type of attack in video calls was 36 percent.
Gartner said in a survey of 297 CISOs or equivalent senior cybersecurity executives conducted from March to May that AI increases the frequency, level of personalisation and persuasiveness of social engineering attacks. It also found that AI reduces the reliability of traditional detection signals.
Craig Porter (크레이그 포터), a director analyst at Gartner, said, “Attackers are carrying out multi-channel attacks by combining phishing, business email compromise, synthetic media and collected personal information.” He added, “Most attacks will continue to rely on users, stolen credentials, weak recovery procedures and familiar technical tactics. CISOs must respond to AI-based social engineering threats systematically, as they do when assessing identity and access risks.”
In the survey, 79 percent of CISOs said they experienced at least one incident of email phishing, spear phishing or business email compromise over the past 12 months. Another 58 percent said there were incidents of vishing and smishing.
Gartner presented three key actions CISOs should prioritise to respond effectively to evolving AI-based social engineering attacks.
Under Gartner's guidance, companies should shift from standardised training to adaptive security behaviour and culture programmes. Rather than teaching employees how to spot fakes, companies should establish safe verification procedures for important requests as a basic behavioural rule.
Employees and approvers should be trained to pause, verify and then report high-risk requests regardless of the channel, including email, voice, video, collaboration tools or AI applications. Companies also need to use simulations to check whether procedures for verifying and reporting suspicious AI-related signs work smoothly.
Companies should strengthen employee identity and recovery systems to prepare for impersonation attacks. High-importance processes such as account recovery, privileged access and payment approvals should be protected through phishing-resistant authentication, risk-based identity controls and trusted channels. Controls should also be put in place to detect misuse of identity information even after normal logins or password resets.
Companies should overhaul detection and response systems to prepare for AI-mediated threats. They should improve threat detection by analysing suspicious contacts and impersonation reports in connection with account recovery histories, new device access, permission changes and financial transaction information. Incident response manuals should be updated to address multimodal impersonation, manipulated AI recommendations, compromised or misused AI agents, and agents operating outside defined boundaries.