
Identity fraud powered by deepfakes is about to get a lot worse, with one report projecting a 495% increase by the end of 2026. At that pace, deepfake attacks are on track to become the single biggest social engineering threat organizations have to deal with.
Here’s why the numbers are climbing so fast, what these attacks actually look like, and what organizations can do to stay ahead of them.
Why Deepfake Attacks Are Scaling So Quickly
A few years ago, faking a voice or a face convincingly took real skill and a lot of time. Now AI does most of the work. All attackers need is a bit of raw material to feed their model of choice, and a few minutes later they have a voice clone or a fake video good enough to fool most people.
Obtaining that raw material is also easier than ever. Public information is everywhere. LinkedIn profiles, company org charts, press releases, social media posts and even employee voices from webinars or podcasts – attackers can pull from all of it.
With the tools and data in place, running the same scheme against ten targets costs almost as little as running it against one. That’s exactly what’s behind the growth.
What a Modern Deepfake Attack Looks Like
From an attacker’s perspective, most deepfake attacks follow the same pattern. First comes researching the victim across all available public sources. Then it’s time to make the initial contact, which usually happens over email, social media, or a messaging app.
The attacker impersonates a colleague, vendor, or executive and sets up a reason for a call or a voice message. The initial request looks like a normal business ask, so as to not raise any suspicion.
The deepfake comes during the final stage to deliver the main blow of the scam. It’s either a cloned voice on a phone call, a recorded voice, or even a live Zoom call where the attacker uses the stolen identity to push the victim into transferring funds, sharing credentials, or handing over sensitive files.
This playbook is exactly how a Swiss entrepreneur lost several million francs in January, after a series of phone calls in which an AI-cloned voice impersonated a trusted business partner.
The Types of Deepfake Attacks Employees Face
While the general playbook is similar, deepfake attacks can come in several different forms.
Executive impersonation is the most common. Attackers clone the voice or likeness of a CEO, CFO or other senior leader and use it to pressure an employee into an urgent action, usually a wire transfer.
Voice cloning shows up on its own too. A short audio clip pulled from a podcast, webinar or earnings call is all it takes to generate a convincing clone. Attackers then use it in phone calls to vendors, partners or colleagues, not just leadership.
Synthetic video takes things to another level. Instead of a phone call, employees find themselves on a live video call with a fabricated version of someone they trust. These calls can involve multiple deepfaked participants at once.
In March 2025, a finance director at a multinational firm in Singapore authorized a $499,000 wire transfer after joining a Zoom call with what he thought was the CFO and several other executives. Every participant on that call was AI-generated, aside from the victim themselves.
Document deepfakes are also a growing category. AI can generate very convincing IDs, invoices, and contracts to bypass identity checks or approve fraudulent payments.
How Organizations Can Prevent Deepfake Attacks
The solution to deepfake attacks is the same as always when it comes to social engineering. It’s people.
Employees who are aware of these scams and know how to slow down under pressure will make any deepfake attempt fall flat, regardless of how sophisticated it is. Getting to that stage takes regular security awareness training that actually incorporates deepfakes, not just email phishing.
One of the main protocols that employees learn through that training is verification. Most organizations already have some kind of verification process on paper, whether that’s a callback policy, or a second approver. But a process that exists on paper rarely holds up in the moment unless employees actually practice using it. Training is what turns verification into a habit people fall back on under pressure.
Final Thoughts
The technologies that enable deepfakes are only getting cheaper and more advanced. 2026 is the year deepfake attacks are exploding to the point where organizations can’t afford to ignore the phenomenon anymore.
But one thing that will never change about this attack vector is that it will always require a human to fall for it. That puts the control back in the hands of organizations, who can prepare their employees to handle the threat accordingly.
Join our LinkedIn group Information Security Community!











