Gartner Survey Finds 41% of CISOs Reported At Least One Social Engineering Incident Involving a Deepfake in the Past 12 Months

Gartner: AI Is Reshaping Social Engineering Threats Gartner: AI Is Reshaping Social Engineering Threats

LONDON, U.K., September 28, 2026 – Forty-one percent of chief information security officers (CISOs) reported at least one social engineering incident involving a deepfake during an employee audio call in the previous 12 months, and 36% reported one during a video call, according to a survey by Gartner, Inc., a business and technology insights company.

The survey conducted in March-May 2026 on 297 senior leaders of the cybersecurity function (CISO or equivalent) found that AI is increasing the volume, personalization, and credibility of social engineering while reducing the reliability of familiar detection cues.

“Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels,” said Craig Porter, Director Analyst at Gartner. “Most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods. CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”

Seventy-nine percent of CISOs surveyed reported at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months, while 58% reported one vishing or smishing incident.

To effectively counter evolving AI social engineering attacks, CISOs must focus on three critical actions:

  1. Transform Static Training into Adaptive Security Behavior and Culture Programs
  • Evolve secure behavior and culture programs from teaching employees to “spot the fake,” toward making secure verification the expected behavior for consequential requests. Train employees and approvers to pause, verify, and report high-risk requests regardless of whether the request arrives through e-mail, voice, video, collaboration tools, or an AI application. Use workforce simulations to test verification and reporting behavior of AI-related suspicious events.
  1. Harden Workforce Identity and Recovery Against Impersonation
  • Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, and trusted verification channels. In addition, implement controls to detect identity abuse, including after a successful login or password reset.
  1. Prepare Detection and Response for AI-Mediated Threats
  • Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to improve threat detection. Update incident response playbooks for multimodal impersonation, manipulated AI recommendations, compromised or misused agents, and where applicable, agents that operate beyond their intended boundaries.

Additional Insights Available

Gartner clients can learn more in 3 Actions CISOs Must Take to Combat AI-Driven Social Engineering and Agentic Threats.

Assess your AI governance against leading frameworks and benchmark maturity against peers using the Gartner AI Controls Assessment.

Gartner is the World Authority on AI

Gartner is the indispensable partner to C-Level executives and technology providers as they implement AI strategies to achieve their mission-critical priorities. The independence and objectivity of Gartner insights provide clients with the confidence to make informed decisions and unlock the full potential of AI. Clients across the C-Level are using Gartner’s proprietary AskGartner AI tool to determine how to leverage AI in their business. With more than 2,500 business and technology experts, 6,000 written insights, as well as more than 4,000 AI use cases and case studies, Gartner is the world authority on AI. More information can be found here.

Gartner IT Symposium/Xpo

At Gartner IT Symposium/Xpo, CIOs and IT executives will learn how to become agents of change in their organizations and harness AI for successful digital transformation. Follow news and updates from the conferences on X and LinkedIn using #GartnerSYM, and on the Gartner Newsroom. 

About Gartner for Cybersecurity Leaders

Gartner for Cybersecurity Leaders equips security leaders with the insights to help reframe roles, align security strategy to business objectives and build programs to balance protection with the needs of the organization. Additional information is available at https://www.gartner.com/en/cybersecurity/products/gartner-for-cisos.

Follow news and updates from Gartner for Cybersecurity Leaders on X and LinkedIn using #GartnerSEC. Visit the Gartner Newsroom for more information and insights.

About Gartner

Gartner (NYSE: IT) delivers actionable, objective business and technology insights that drive smarter decisions and stronger performance on an organization’s mission-critical priorities. To learn more visit gartner.com.

Explore how innovative AI technologies and intelligent automation solutions are helping organizations accelerate digital transformation and operational efficiency.

Written by

TechEdge AI

Techedge AI is a niche publication dedicated to keeping its audience at the forefront of the rapidly evolving AI technology landscape. With a sharp focus on emerging trends, groundbreaking innovations, and expert insights, we cover everything from C-suite interviews and industry news to in-depth articles, podcasts, press releases, and guest posts. Join us as we explore the AI technologies shaping tomorrow's world.

View all posts by TechEdge AI →

Grow Your
Brand Visibility

Looking to publish a press release, guest article, interview or podcast? Connect with us.

GET FEATURED
Subscribe

Sign up today for exclusive insights and updates.

Newsletter Signup