Skip to content

Security2 publishers2 min readPublished

Pindrop survey finds purpose-built deepfake defenses at 10% of US organizations

Pindrop's survey of more than 250 US security leaders found 74% faced or suspected a deepfake attack in the past year. The targets are live channels such as help-desk calls, job interviews and video meetings, and identity controls were not designed to verify who is on them.

The Watch · Security desk

Illustration accompanying Pindrop survey finds purpose-built deepfake defenses at 10% of US organizations

What happened

  • Among organizations that experienced or suspected an attack, nearly half put total costs at $500,000 or more and about a quarter at $1 million or more.
  • Forty-nine percent of those organizations reported follow-on cyberattacks, ransomware among them, according to Help Net Security's account of the index.
  • Three in four respondents said deepfakes will become a board issue only after a leader at their own organization is fooled or impersonated.
  • Thirty-seven percent said one deepfake attack could put a company like theirs out of business, and 17% rated that outcome extremely likely or certain.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure At the 90% of surveyed organizations without purpose-built defenses, help-desk agents, recruiters and staff approving requests on video are the only check on whether a live caller is real.
  • contradiction Seventy-four percent expect defenses to improve faster than attacks while 93% call their own organizations unprepared, so the optimism rests on tools most respondents have not bought.
  • precedent If boards move only after a leader is fooled or impersonated, budget for live-channel defenses will tend to arrive after an organization's first loss.
  • decision Responders who close a successful deepfake call as a fraud case risk missing the follow-on intrusion that respondents say often came next.

"Attackers have figured out that one of the easiest ways around sophisticated security controls is to impersonate the human those controls are designed to trust," said Elie Khoury, SVP of research at Pindrop [6]. "Enterprises need to bring the same rigor used to secure systems and devices to the live human interactions where critical decisions are being made," he said [7].

The remote-interview channel already has a known operator. North Korean nation-state hackers have used deepfakes to pose as IT workers applying for jobs at technology and software companies, Infosecurity Magazine reported [15]. The more familiar pattern is an attacker posing as a colleague, a boss or the CEO to get sensitive information or a fraudulent transfer [16]. Neither published account breaks the survey's incidents down by channel. The data counts organizations hit. It does not show whether the help desk, the interview or the meeting was the way in.

The index was published on 28 September and rests on a small pool of self-reported answers [3][2]. Seventy-four percent of just over 250 respondents is about 185 organizations [1]. The quarter of those reporting $1 million or more in costs is roughly 46 organizations [2]. The cost figures also include organizations that only suspected an attack [9].

The two write-ups of the index do not agree on what the money measures. Help Net Security describes the figures as total costs, including direct losses, remediation and staff time [9]. Infosecurity Magazine ties the $1 million tier to "a single incident" and attaches its 49% figure to the $500,000 tier [17]. In Help Net Security's version, 49% is the share of hit organizations reporting follow-on attacks [10].

Infosecurity Magazine's recommended countermeasures are staff training, phishing-resistant controls such as MFA across systems, and watching for suspicious communications and impersonation events [18]. MFA is an identity control. According to the report, identity controls were not designed to determine whether the person speaking or appearing in a live interaction is genuine [5].

What to watch

  • A channel-level breakdown from Pindrop showing whether help-desk calls, interviews or video meetings account for most incidents, and how many were confirmed versus suspected.
  • Public incident reports that tie a deepfake help-desk call or video meeting to a later ransomware deployment.
  • New advisories or indictments on North Korean IT-worker schemes that describe deepfakes used in live job interviews.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories