THREE-QUARTERS of cybersecurity leaders surveyed say their organisation encountered a suspected deepfake attack in the past year, according to Pindrop’s 2026 Deepfake Readiness Index, published on 28 September 2026. The survey of more than 250 US security leaders found that 74% had encountered a suspected incident. Among those affected, one in four reported losses exceeding $1m from a single attack, while 49% reported losses of $500,000. The figures include direct losses, incident remediation and the staff time and resources spent responding.
Deepfakes use AI-generated audio or video to imitate real people, making it harder to distinguish fabricated content from genuine footage. Attackers can impersonate colleagues, executives or chief executives to persuade victims to disclose sensitive information or approve fraudulent transfers.
The report also highlights a readiness gap: 93% of respondents said they were concerned their organisation was not prepared for deepfake attacks, while three in four said it might take a company leader being impersonated or deceived before the issue received board-level attention. Pindrop’s Elie Khoury said deepfakes turn familiar faces and voices into an attack surface.
Suggested measures include staff training, phishing-resistant multi-factor authentication, and monitoring for suspicious communications and impersonation attempts.