41% of CISOs Report Deepfake AI Attacks in Corporate Communications

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A Gartner survey found that 41% of Chief Information Security Officers (CISOs) experienced AI-driven deepfake voice attacks in employee calls over the past year, with 36% facing similar attacks in video calls. These AI-enabled social engineering attacks have compromised corporate security, highlighting the growing threat of synthetic media in cybercrime.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event clearly involves AI systems (deepfake voice generation) used maliciously in social engineering attacks against corporate employees, causing realized harm such as security breaches and fraud risks. The article describes actual incidents experienced by security officers, not just potential risks. Hence, it meets the criteria for an AI Incident because the AI system's use has directly led to harm (security compromise through social engineering).[AI generated]
AI principles
Robustness & digital securityTransparency & explainability

Industries
Digital security

Affected stakeholders
WorkersBusiness

Harm types
Economic/PropertyReputational

Business function:
ICT management and information security

AI system task:
Content generation


Articles about this incident or hazard