Nearly 32% of UK businesses have experienced a deepfake security incident in the last 12 months, ranking the second most common information security incident in the country, trailing only behind malware infections. This is according to research by ISMS.online.
ISMS.online’s ‘State of Information Security’ report surveyed 502 people in the UK who work in information security across 10 sectors including technology, manufacturing, education, energy and utilities, and healthcare.
The most likely scenario today for threat actors to use deepfakes is in business email compromise (BEC)-style attempts. Attackers use the AI-powered voice and video-cloning technology to trick recipients into making corporate fund transfers. However, there are possible use cases for information/credential theft, reputational damage or even to bypass facial and voice recognition authentication.
And with partner data (41%) being cited as the most compromised in the past 12 months by UK respondents, more businesses need to be vigilant when it comes to the risks posed by their third-party vendors and suppliers, especially in light of these new, sophisticated attacks.
To counteract these increasingly advanced attacks, enhancing training and awareness is crucial across both the supply chain and internally. Nearly half of the respondents (47%) acknowledged this by placing greater emphasis on employee education and awareness initiatives. In addition, nearly two-fifths (38%) said financial allocations for securing supply chain and third-party vendor connections are set to increase by up to 25% in the coming year – particularly as the research found that 79% of businesses have been impacted due to an information security incident caused by a third-party vendor or supply chain partner.
However, despite the heightened focus on training, the findings indicate that employee errors continue, with even well-trained employees facing challenges in identifying deepfakes. It was noted that employees continue to use their own devices (BYOD) without adequate security measures (34%), and 30% are not properly securing sensitive information. This deviation from best practices leaves businesses vulnerable to cybercriminals who may exploit these weaknesses with this increasingly sophisticated technology such as deepfakes.






