Deepfakes become a board priority once an executive falls for one
Pindrop's 2026 Deepfake Readiness Index finds nearly three-quarters of security leaders encountered or suspect deepfake attacks, but only 10% have purpose-built defenses.
Pindrop's 2026 Deepfake Readiness Index reports 74% of security leaders encountered or suspect a deepfake attack in the past year, targeting phone calls to IT help desks, remote interviews, and video meetings. Nearly half of affected organizations reported costs of $500,000 or more, a quarter reported at least $1 million, and 49% experienced follow-on attacks including ransomware and data breaches. Three-quarters say deepfakes only become a board priority after an executive is personally fooled, and 37% believe a single attack could put their company out of business.
- 74% of security leaders encountered or suspect deepfake attacks within a year
- Only 10% of organizations have purpose-built deepfake defenses
- Nearly half of victims reported costs of $500,000 or more per incident
- 49% saw follow-on attacks like ransomware and data breaches after deepfake incidents
Full article322 words · extracted from helpnetsecurity.com · click to collapse
Nearly three-quarters of security leaders have encountered or suspect a deepfake attack in the past year, while just 10% say their organizations have purpose-built defenses, according to Pindrop’s 2026 Deepfake Readiness Index.
Real-time communications have become a target for deepfake and AI impersonation attacks. Phone calls to IT help desks, remote job interviews, and video meetings give attackers opportunities to pose as people an organization trusts. Identity controls were not designed to determine whether the person speaking or appearing in a live interaction is genuine.
“Attackers have figured out that one of the easiest ways around sophisticated security controls is to impersonate the human those controls are designed to trust. Deepfakes turn our most instinctive signals of identity, a familiar face and voice, into an attack surface. Enterprises need to bring the same rigor used to secure systems and devices to the live human interactions where critical decisions are being made,” said Elie Khoury, SVP of Research at Pindrop.
Despite low adoption of purpose-built defenses, 74% of security leaders believe defenses will improve faster than attack quality.
More than a third fear a company-ending attack
Of the organizations that experienced or suspected a deepfake attack, nearly half reported total costs of $500,000 or more, including direct losses, remediation, and staff time. About a quarter reported costs of at least $1 million. Forty-nine percent reported follow-on cyberattacks, including ransomware. Respondents also reported data breaches, lost revenue, exposure of sensitive information, and stolen funds.

Consequences that followed (Source: Pindrop)
Three-quarters of respondents said deepfakes would become a boardroom priority only after a leader at their organization was personally fooled or impersonated. Viewing deepfakes primarily as a reputational risk for public figures and celebrities can delay investment in enterprise defenses.
Thirty-seven percent of respondents said the damage from a single deepfake attack could put a company like theirs out of business. That includes 17% who considered this outcome extremely likely or certain.