Security2 publishers2 min readPublished
Four in ten CISOs surveyed by Gartner logged a deepfaked voice call in the past year
Gartner surveyed 297 senior security leaders between March and May 2026 and found deepfaked video calls close behind at 36%. Its advice is to put a verification step in front of payment authorization, account recovery and privileged access.
The Watch · Security desk

What happened
- Gartner says 41% of the senior security leaders it surveyed reported at least one social engineering incident involving a deepfake on an employee audio call in the previous 12 months.
- A separate line in the same survey puts deepfakes during video calls at 36% of respondents over the same 12-month period.
- The numbers come from 297 senior cybersecurity leaders surveyed between March and May 2026 for Gartner's AI-driven Social Engineering Attacks report.
- Gartner released the findings as its Security & Risk Management Summit opened in London on September 22.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Helpdesk password resets, privileged access grants and wire approvals all end in a human deciding whether a caller is genuine, and a cloned voice is built to win that decision.
- constraint Awareness programs built on hearing the artifacts lose value as the cues degrade, so verification has to hold whether or not the caller sounds right to the person answering.
- contradiction The write-up's framing of almost half sits above tabulated figures whose highest deepfake number is 41%, so how big the problem looks depends on which line of the report a security team quotes to its board.
Gartner's high-value workflows are account recovery, privileged access and payment authorization [10], and each one finishes with a person judging whether the voice on the line belongs to the name it claims. Phishing-resistant authentication covers the login. The helpdesk agent who resets a password because the caller sounded like the CFO sits outside it.
41% of 297 respondents is about 122 security leaders reporting a deepfaked audio call; 79% is about 235 reporting email phishing, spearphishing or business email compromise [14]. Email-borne incidents were reported by roughly twice as many respondents as audio deepfakes [15]. Craig Porter, a director analyst at Gartner, said most attacks will keep relying on users, stolen credentials, weak recovery processes and familiar technical methods [8].
The figures count respondents who saw at least one incident in 12 months. They do not include losses or success rates [17]. Fieldwork closed in May 2026, so the window reaches back to roughly spring 2025 [16].
Infosecurity Magazine's write-up opens by saying almost half of CISOs reported at least one deepfake incident in the past year [13]. The highest deepfake figure in the findings it then cites is the 41% for audio calls [1], with video at 36% [2]. Adding the two channels would double-count anyone who saw both.
Porter said CISOs "must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats" [7]. In practice that means a trusted verification channel in front of consequential requests, because Gartner's own finding is that AI is eroding the familiar detection cues staff were trained to listen for [12][9]. Correlate impersonation reports with account recovery events, new devices, privilege changes and financial transactions, and add branches for multimodal impersonation, manipulated AI recommendations and compromised or out-of-bounds AI agents [11].
What to watch
- A breakdown of how many of the 41% involved payment or recovery requests, and how many ended in a transfer.
- Loss figures attached to deepfake-assisted approvals; until a cost is attached, this stays a training line item.
- Whether the 58% vishing and smishing figure and the 41% audio deepfake figure describe overlapping incidents.