Wednesday, 30 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Deepfake fraud: fix the approval chain before buying a detector

Pindrop’s survey of 250 US security leaders finds deepfake attacks costing some firms $1m or more from a single incident. Its answer is detection. For UK boards, the faster fix sits in payment, help-desk and executive approval rules

Elie Khoury, senior vice-president of research at Pindrop
Image: Elie Khoury/LinkedIn
In brief
  • The risk sits wherever a familiar voice or face can approve a payment, a password reset or an urgent request on its own.
  • The UK government’s own survey found 47% of large businesses faced impersonation of their organization or staff, in emails or online, in the previous 12 months.
  • Boards should require second-channel confirmation for payments, voice-proof help-desk resets and a standing rule that no executive asks staff to skip a control.

On 28 September Pindrop published its 2026 Deepfake Readiness Index, and the headline number is stark: 74% of the security leaders it surveyed said they had encountered or suspected a deepfake attack in the past year. Pindrop sells deepfake detection for phone calls and video meetings, and its release says only 10% of respondents have purpose-built tools to deal with the threat.

The research is Pindrop’s own. Wakefield Research surveyed 250 US security leaders at organizations with 1,000 or more employees between 11 and 22 June 2026, with a margin of error of 6.2 percentage points. Among those that had experienced or suspected an attack, nearly half reported costs of $500,000 (£376,000) or more, counting direct losses, remediation and staff time, and one in four reported $1m (£753,000) or more from a single incident. None of it is UK data.

Elie Khoury, senior vice-president of research at Pindrop, described the mechanism in the release: “Attackers have figured out that one of the easiest ways around sophisticated security controls is to impersonate the human those controls are designed to trust.”

Pindrop’s answer is more detection. For UK CISOs and boards, the more urgent reading is that deepfakes attack decisions, not systems. The risk sits wherever an organization lets a familiar voice or face approve something on its own: a payment, a password reset, an urgent instruction from the top. Those rules belong to finance, the service desk and the board, and they can be rewritten this quarter.

The UK evidence points the same way

The Cyber Security Breaches Survey 2025/2026, commissioned by the Department for Science, Innovation and Technology (DSIT) and the Home Office and published on 30 April 2026, surveyed 2,112 UK businesses between August and December 2025. Its list of attack types does not include deepfakes. It does ask about impersonation: 47% of large businesses and 38% of medium-sized ones had seen people impersonating the organization or its staff in emails or online in the previous 12 months, against 12% of businesses overall. Among large businesses that identified a breach or attack, 31% said impersonation had caused them the most disruption of any attack type.

Voice already features. One large travel and tourism business told the survey’s researchers about a vishing attack – fraud by phone call or voice message – built on 12 months of background research into the person targeted. In its words, “they nearly got away with half a million pounds”.

A UK company also supplies the clearest precedent. Early in 2024 an employee of Arup, the UK engineering firm, was tricked into sending $25m (£18.8m) to criminals after a video call with what appeared to be senior managers but were deepfakes, according to a World Economic Forum interview published in February 2025. Rob Greig, then Arup’s chief information officer, told the Forum: “None of our systems were compromised and there was no data affected.” The money left through a person and a payment process.

Three places a familiar voice gets through

Payment approvals are the obvious one. Any process in which a senior voice on a call can release money, or change a supplier’s bank details, has the same shape as the Arup transfer.

Help desks are the second. In May 2025, responding to attacks on UK retailers, the National Cyber Security Centre (NCSC) noted discussion of whether social engineering had been used against IT help desks to reset passwords and multi-factor authentication (MFA). It told organizations to review how help desks authenticate staff before resetting passwords, especially for accounts with escalated privileges. Pindrop’s release also lists calls into IT help desks among the interactions attackers exploit.

Executive requests are the third, and the one boards control directly. A Gartner survey of CISOs, reported by ITPro on 25 September, found 41% had seen social engineering attempts involving an employee phone call in the past year and 36% in a video call. Gartner advised moving beyond training staff to spot fakes, toward making verification routine on every channel, with harder protection around account recovery and payment authorization, according to ITPro.

What to change before buying anything

Pindrop’s data holds a warning for boards. Three in four respondents said it would take a company leader being personally fooled or impersonated before deepfakes became a genuine boardroom priority. UK boards have fewer excuses to wait: the government survey found 68% of large businesses have a board member responsible for cybersecurity. Four changes need no new product:

  • No payment, new payee or change to supplier bank details is approved on the strength of a call or video meeting alone. Confirm it through a second channel, using contact details already on file.
  • Help-desk resets for privileged accounts, and any MFA re-enrollment, need proof of identity that does not depend on how the caller sounds or looks.
  • Executives state in writing that they will never ask staff to bypass a control, so refusing an urgent request from the top is safe.
  • Rehearse it. Run an impersonation test against finance and the service desk, and report the result to the board.

Jim Routh, chairman of the Pindrop CISO Deepfake Defense Council, said in the release that security leaders prioritizing deepfake detection now “are the only ones who’ll have a real answer when their board starts to ask questions”. Detection may earn a place. But the first answer a UK board needs is simpler: which decisions in this organization can a convincing voice still make on its own? Until that list is empty, no detector will close the gap.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Pindrop, “Deepfakes Are Hitting the Enterprise, but 90% Lack Purpose-Built Defenses”, press release, 28 September 2026. https://www.pindrop.com/company-news/deepfakes-are-hitting-the-enterprise-but-90-lack-purpose-built-defenses
  2. Department for Science, Innovation and Technology and Home Office, “Cyber security breaches survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
  3. National Cyber Security Centre, “Incidents impacting retailers – recommendations from the NCSC”, blog post, 4 May 2025 (updated 29 July 2025). https://www.ncsc.gov.uk/blog-post/incidents-impacting-retailers
  4. ITPro, “Nearly half of CISOs have been hit by AI deepfake voice calls – here’s how to spot the tell-tale signs you’re being scammed”, news, 25 September 2026. https://www.itpro.com/security/cyber-crime/nearly-half-of-cisos-have-been-hit-by-ai-deepfake-voice-calls-heres-how-to-spot-the-tell-tale-signs-youre-being-scammed
  5. World Economic Forum, “‘This happens more frequently than people realize’: Arup chief on the lessons learned from a $25m deepfake crime”, interview, 4 February 2025. https://www.weforum.org/stories/emerging-technologies/deepfake-ai-cybercrime-arup/
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →