This page was machine-translated and may differ from the original. View original
AI Proliferation Drives Sophistication of Social Engineering Attacks; Calls for Strengthening Identity Protection and Account Recovery Systems
As AI technology spreads, social engineering attacks exploiting deepfakes are extending to voice and video calls. According to Gartner research, nearly half of Chief Information Security Officers (CISOs) have directly experienced deepfake-based attacks, with analysis indicating that AI increases the frequency, personalization level, and persuasiveness of attacks while reducing the reliability of existing detection methods.
Gartner released on the 28th the results of a survey conducted from March to May this year targeting 297 CISOs or equivalent senior cybersecurity executives.
According to the survey, 41% of respondents reported experiencing at least one social engineering attack using deepfakes in employee voice calls over the past 12 months.
The percentage of respondents who experienced the same type of attack in video calls was 36%.
The rate of experiencing email phishing, spear phishing, and business email compromise incidents was 79%, while vishing and smishing accounted for 58%.
Craig Potter, Gartner Director Analyst, stated "Attackers are conducting multi-channel attacks by combining phishing, business email compromise, synthetic media, and collected personal information" and "CISOs must respond systematically to AI-based social engineering threats in the same manner as when assessing identity and access risks."
Gartner presented three key measures that CISOs should prioritize to counter AI-based social engineering threats.
First, standardized security training should be converted into adaptive security behavior programs.
The explanation is that establishing verification and reporting as basic behavior in response to high-risk requests is more effective than training on 'how to identify fakes'.
Second, identity and account recovery systems to prepare for impersonation attacks should be strengthened.
Phishing-resistant authentication and risk-based identity controls should be applied to critical business processes such as account recovery, privileged access, and payment authorization, and mechanisms are needed to detect unauthorized use of identity information even after normal login.
Third, detection and response systems for AI-mediated threats should be updated.
Impersonation reports should be analyzed in correlation with account recovery history, new device access, permission changes, and financial transaction data, and incident response manuals should be updated to include compromised or misused AI agents.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.













