AI Governance Institute
← News
Research2026-10-02

74% of Security Leaders Hit by Deepfake Attacks, a Quarter Lost Over $1M

Source

2026 Pindrop Deepfake Readiness Index

Pindrop

Via Pindrop

What happened

The 2026 Pindrop Deepfake Readiness Index found that 74 percent of surveyed security leaders had encountered a suspected deepfake attack in the preceding twelve months. One in four affected organizations reported losses of more than one million dollars from a single incident. The report identifies the core governance gap as overreliance on human recognition of voices and faces, without independent verification or dual-approval requirements for high-risk requests. Affected workflows include wire transfers, account recovery, and privileged access changes -- areas that compliance and finance teams own, not only security teams. The findings follow a pattern of escalating deepfake fraud events, including a nearly $4M Singapore deepfake scam and a report that 41% of CISOs suffered deepfake voice attacks.

Why it matters

  • ·Payment and account approval workflows built around recognizing a colleague's voice or face are now a documented liability. Organizations without out-of-band verification, such as a separate channel confirmation or a pre-shared code, are exposed to losses that the Pindrop data show regularly exceed one million dollars.
  • ·Access governance programs that allow account recovery or privileged access changes based on a voice or video call need redesign. A caller who sounds or looks authentic is no longer meaningful evidence of identity, and any policy that treats it as such creates audit exposure.
  • ·Finance, treasury, and legal teams should treat this as a process-design problem, not a technology problem. Dual-approval requirements and out-of-band verification are procedural controls that sit within compliance program scope, not solely within IT security.

Governance controls affected

What to do now

  • ☐Review every payment approval and wire transfer workflow to confirm that voice or video call recognition is not the sole verification step, and add a second channel or pre-shared code requirement where it is.
  • ☐Audit account recovery procedures for privileged and financial accounts to confirm they require more than a caller's voice or a video image to authenticate the requestor.
  • ☐Ask your finance and treasury teams whether any standing instruction exists to approve requests received by phone or video without a callback to a known, pre-registered number.
  • ☐Confirm that your vendor and third-party payment instructions cannot be changed by a single email or call claiming to be from a known contact, and add dual-approval for any instruction change.
  • ☐Run a tabletop exercise with finance, legal, and IT teams in which a known executive's voice or face is assumed to be synthetic, and document whether your current controls would have stopped the transaction.

What to watch next

Regulatory attention to deepfake-enabled fraud is growing. The Australian Securities and Investments Commission has already declared AI impersonation scams an emergency for the financial sector. Further enforcement signals are likely from financial regulators in 2026 and 2027. Compliance teams should monitor whether payment fraud guidance from bodies such as the Financial Stability Board explicitly names synthetic-media impersonation as a covered risk category. They should also track whether the Financial Services AI Risk Management Framework is updated to require out-of-band verification as a baseline control.

Related Coverage

Research2026-09-29

AI Deepfake Investment Fraud Costs Northern Ireland Resident £250,000

A Northern Ireland resident lost £250,000 to fraudsters who used an AI-generated video of a financial-sector figure to impersonate a credible investment source. Police issued a public warning about the incident. The case illustrates how synthetic video can defeat visual identity checks when firms lack out-of-band confirmation procedures.

Research2026-09-23

41% of CISOs Suffered Deepfake Voice Attacks: Approval Controls Must Adapt

A Help Net Security survey found that 41 percent of CISOs reported at least one deepfake voice-cloning social engineering incident on employee audio calls in the past year. The findings show that identity verification and call-back procedures commonly used to authorize high-value transactions are failing against real-time voice fraud. Compliance programs built on voice-as-authentication assumptions face an immediate control gap.

Research2026-10-02

PwC: AI Attacks Top Threat List, But Only 22% Back Autonomous Cyber Defense

PwC's 2027 Global Digital Trust Insights report is based on nearly 4,000 leaders across 70-plus countries. It finds that attacks targeting AI systems rank as the threat enterprises feel least prepared to handle. Only 22% of respondents would deploy fully autonomous AI agents for cyber defense without human oversight, with governance skill gaps cited as a barrier. A parallel readiness failure appears in quantum-resistant security, where just 21% of organizations have begun adopting protections against future decryption attacks.