{"id":50645,"date":"2025-09-24T21:47:00","date_gmt":"2025-09-24T18:47:00","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=50645"},"modified":"2025-09-24T21:36:07","modified_gmt":"2025-09-24T18:36:07","slug":"two-thirds-of-firms-hit-by-deepfake-attacks","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/artificial-intelligence\/50645\/two-thirds-of-firms-hit-by-deepfake-attacks\/","title":{"rendered":"Two-Thirds of Firms Hit by Deepfake Attacks"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; 62% of organizations experienced a deepfake attack in the past year, primarily through social engineering or by exploiting automated verification systems.<br>&#8211; A senior Gartner director warns that deepfake threats are growing due to continuous technological improvements.<br>&#8211; Organizations are urged to integrate emerging deepfake detection tools into platforms like Microsoft Teams or Zoom, though their effectiveness is still being evaluated.<br>&#8211; Effective defenses include employee awareness training with simulated deepfakes and implementing application-level authorization, like phishing-resistant MFA, for financial transactions.<br>&#8211; 32% of organizations have also faced attacks on AI applications, including prompt injection attacks that manipulate AI into generating malicious outputs.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">A<\/mark> startling new survey reveals that <strong>a majority of organizations, 62%, have fallen victim to a <a href=\"https:\/\/digitrendz.blog\/z\/topic\/deepfake-attacks\/\" class=\"acp-topic-link\" data-topic-id=\"95794\" title=\"Explore: deepfake attacks\" target=\"_blank\" rel=\"noopener noreferrer\">deepfake attack<\/a> within the last year<\/strong>. These sophisticated assaults typically involve <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/210360\/callback-phishing-attacks-abuse-shop-order-tracking-app\/\" class=\"acp-article-link\" data-article-id=\"210360\" title=\"Callback phishing attacks abuse Shop order-tracking app\" target=\"_blank\" rel=\"noopener noreferrer\">social engineering<\/a>, where attackers impersonate company leaders through fabricated video or audio during calls with staff. Another common method is the manipulation of automated verification systems, such as those relying on face or voice recognition.<\/p>\n\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/digitrendz.blog\/z\/entity\/akif-khan\/\" class=\"acp-entity-link\" data-entity-id=\"115000\" data-entity-category=\"Person\" title=\"Learn more about Akif Khan\" target=\"_blank\" rel=\"noopener noreferrer\">Akif Khan<\/a>, a senior director at <a href=\"https:\/\/digitrendz.blog\/z\/entity\/gartner-research\/\" class=\"acp-entity-link\" data-entity-id=\"50844\" data-entity-category=\"Organization\" title=\"Learn more about Gartner Research\" target=\"_blank\" rel=\"noopener noreferrer\">Gartner Research<\/a>, the threat landscape is rapidly evolving. He warns that as the underlying technology becomes more accessible and convincing, the frequency and severity of these attacks are poised to increase significantly. The most widespread danger currently stems from <strong>the fusion of <a href=\"https:\/\/digitrendz.blog\/z\/newswire\/technology\/213336\/ctrlaltpwn-review-a-deep-dive\/\" class=\"acp-article-link\" data-article-id=\"213336\" title=\"CTRL+ALT+PWN Review: A Deep Dive\" target=\"_blank\" rel=\"noopener noreferrer\">deepfakes<\/a> with classic social engineering tactics<\/strong>. A typical scenario might involve a deepfake of a CEO urgently instructing an employee to wire funds to a fraudulent account.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/khan\/\" class=\"acp-entity-link\" data-entity-id=\"115001\" data-entity-category=\"Person\" title=\"Learn more about Khan\" target=\"_blank\" rel=\"noopener noreferrer\">Khan<\/a> emphasizes that this combination is particularly insidious. &#8220;Social engineering has always been a reliable tool for attackers. Adding a highly realistic deepfake to the mix puts immense pressure on employees, who become the first line of defense,&#8221; he explained. Relying solely on automated systems is no longer sufficient; human vigilance is critical.<\/p>\n\n<p class=\"wp-block-paragraph\">To combat this rising threat, Khan points to emerging technical solutions. He suggests that organizations evaluate vendors who are integrating <strong><a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/229981\/deel-buys-deepfake-detection-firm-clarity-amid-fake-hire-surge\/\" class=\"acp-article-link\" data-article-id=\"229981\" title=\"Deel buys deepfake-detection firm Clarity amid fake hire surge\" target=\"_blank\" rel=\"noopener noreferrer\">deepfake detection<\/a> capabilities directly into everyday communication platforms<\/strong> like <a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft-teams\/\" class=\"acp-entity-link\" data-entity-id=\"6667\" data-entity-category=\"Technology\" title=\"Learn more about Microsoft Teams\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Teams<\/a> and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/zoom\/\" class=\"acp-entity-link\" data-entity-id=\"1393\" data-entity-category=\"Organization\" title=\"Learn more about Zoom\" target=\"_blank\" rel=\"noopener noreferrer\">Zoom<\/a>. However, he offers a note of caution, stating that these integrations are still novel. &#8220;There aren&#8217;t many large-scale deployments yet, so their real-world effectiveness in a live environment remains to be fully proven,&#8221; Khan noted.<\/p>\n\n<p class=\"wp-block-paragraph\">For more immediate protection, some companies are finding success with specialized awareness training. These programs often involve creating their own deepfakes of executives and using them in simulated attack exercises to educate employees on what to look for. Another crucial defensive measure is <strong>a thorough review of internal <a href=\"https:\/\/digitrendz.blog\/z\/topic\/business-processes\/\" class=\"acp-topic-link\" data-topic-id=\"95795\" title=\"Explore: business processes\" target=\"_blank\" rel=\"noopener noreferrer\">business processes<\/a><\/strong>, especially concerning financial transactions.<\/p>\n\n<p class=\"wp-block-paragraph\">Khan advises implementing authorization checks at the application level. &#8220;A process could be designed so that even if the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cfo\/\" class=\"acp-entity-link\" data-entity-id=\"42396\" data-entity-category=\"Person\" title=\"Learn more about CFO\" target=\"_blank\" rel=\"noopener noreferrer\">CFO<\/a> calls to request a payment, the transaction must still be formally approved within the finance application itself,&#8221; he said. This secondary step should ideally require the executive to log in using <strong>phishing-resistant <a href=\"https:\/\/digitrendz.blog\/z\/entity\/multi-factor-authentication\/\" class=\"acp-entity-link\" data-entity-id=\"22672\" data-entity-category=\"Technology\" title=\"Learn more about multi-factor authentication\" target=\"_blank\" rel=\"noopener noreferrer\">multi-factor authentication<\/a> (<a href=\"https:\/\/digitrendz.blog\/z\/entity\/mfa\/\" class=\"acp-entity-link\" data-entity-id=\"33307\" data-entity-category=\"Technology\" title=\"Learn more about MFA\" target=\"_blank\" rel=\"noopener noreferrer\">MFA<\/a>)<\/strong> to authorize the transfer, creating a vital barrier.<\/p>\n\n<p class=\"wp-block-paragraph\">The same <a href=\"https:\/\/digitrendz.blog\/z\/entity\/gartner\/\" class=\"acp-entity-link\" data-entity-id=\"1840\" data-entity-category=\"Organization\" title=\"Learn more about Gartner\" target=\"_blank\" rel=\"noopener noreferrer\">Gartner<\/a> report, presented at the Gartner Security &amp; Risk Management Summit 2025, highlighted another concerning trend: attacks targeting artificial intelligence applications. It found that <strong>32% of organizations have experienced an attack on their AI systems<\/strong> over the past twelve months. These incidents often involve <strong>prompt injection attacks<\/strong>, a technique where malicious inputs are crafted to manipulate <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/244539\/why-businesses-need-clear-limits-before-authorizing-ai-agents\/\" class=\"acp-article-link\" data-article-id=\"244539\" title=\"Why Businesses Need Clear Limits Before Authorizing AI Agents\" target=\"_blank\" rel=\"noopener noreferrer\">large language models<\/a> (LLMs) into producing biased, incorrect, or harmful outputs.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/deepfake-attacks-hit-twothirds-of\/\" target=\"_blank\">Info Security<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>A majority of organizations (62%) experienced a deepfake attack in the past year, often using social engineering to impersonate leaders or manipulate automated verification systems. The threat is growing as deepfake technology becomes more accessible, with the combination of deepfakes and social &#8230;<\/p>\n","protected":false},"author":1,"featured_media":50644,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3247,3253,3297,3327],"tags":[8195,79874,10315,14391,22533],"entities":[80194,30209,1369,35177,79638,61451,80193,80197,24005,4113,80196,80195,800],"class_list":["post-50645","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-business","category-cybersecurity","category-newswire","tag-ai-security","tag-deepfake-attacks","tag-deepfake-detection","tag-multi-factor-authentication","tag-social-engineering","entity-akif-khan","entity-cfo","entity-gartner","entity-gartner-research","entity-gartner-security-risk-management-summit-2025","entity-infosecurity-2","entity-khan","entity-large-sum-of-money","entity-mfa","entity-microsoft-teams","entity-multi-factor-authentication-2","entity-past-12-months","entity-zoom"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/50645","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=50645"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/50645\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/50644"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=50645"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=50645"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=50645"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=50645"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}