Executive Summary

Deepfake and AI-driven impersonation threats are rapidly emerging as a top concern for financial institutions. During a recent webinar, Deepfakes and The Future of Security Awareness, we polled 85 financial institution professionals about the threats deepfakes pose. Based on the survey responses, the data reveals clear results:

    • Deepfake threats are already impacting institutions, with roughly 1 in 4 reporting suspected or confirmed incidents.
    • Organizations are more concerned about AI-driven fraud and impersonation like social engineering and voice cloning rather than reputational-related deepfake threats. Despite strong training adoption, both employee readiness and organizational preparedness for deepfake threats remain areas of concern, with low confidence in detecting deepfakes and persistent gaps in testing and response exercises.

Overall, organizations recognize the risk, but many have not set up systems and processes to mitigate the growing risk of deepfakes.

Sections in this Report

 

Respondent Profile

2026 Deepfakes Report Chart_Institution type 2026 Deepfakes Report Chart_Asset size

 

Deepfake Incidents Are Already a Reality

Bar chart titled "Has your organization experienced a suspected or confirmed deepfake, voice cloning, or AI impersonation attempt?" showing survey results: Yes 25%, No 52%, Don't know 21%, Prefer not to say 2%.

Key Insights

Deepfake attacks are actively happening at organizations. Nearly 25% of respondents reported a known deepfake or AI impersonation incident, and another 21% were unsure. This aligns with the assumption that roughly 1 in 4 organizations reported a suspected or confirmed incident, and it suggests that not only are deepfakes occurring, but some are likely going unrecognized.

This uncertainty is consistent with the nature of AI-driven attacks, which are designed to blend into normal business communication and take advantage of our natural reactions. We are less likely to question something when it feels real, comes from someone familiar, creates a sense of urgency, and feels overwhelming.

Deepfake attacks don’t succeed by hacking systems; they succeed by hacking us.

These attacks can look like:

    • A fraudulent call using the cloned voice of a known executive
    • A realistic email requesting urgent action
    • A convincing impersonation during routine operational workflows
Takeaways

Financial Institutions should assume attempts are already occurring, regardless of whether they’ve been formally detected. To address this gap, financial institutions should focus on strengthening both employee awareness and organizational responses by:

1. Strengthen Detection and Reporting
Train employees to recognize common tactics including messages that convey urgency, authority, emotional pressure and unexpected requests. Employees should know when to pause, verify the request through a trusted channel, and report suspicious communications.

2. Formalize Response Procedures
Include deepfakes and AI impersonation attempts in existing incident response procedure. Clearly define how employees should report a suspected incident, who should be notified, and how the institution will investigate and respond.

3. Validate Your Readiness
Many organizations assume they would recognize an impersonation attack, but without testing, that confidence may be misplaced. Use tabletop exercises and realistic simulations to identify gaps and give employees practice responding to these situations.

 

Most Concerning Deepfake Scenario Threat

2026 Deepfakes Report Chart_Deepfake concerns

Key Insights

Social engineering (38%) and voice cloning (36%) are the top concerns for financial institutions. It’s still important to educate on high-profile scenarios, such as fake videos or vendor impersonation. However, respondents are most concerned about everyday interactions, during which an attacker could take advantage of an existing relationship or familiar voice.

Unlike traditional phishing, deepfake social engineering attacks are becoming more personalized, and are difficult to distinguish from legitimate requests.

Voice cloning introduces another layer of risk because organizations have traditionally trusted a familiar voice as a means to confirm someone’s identity. What was once considered a strong authentication method can now be replicated with alarming accuracy.

Employee Training and Verification Tactics

2026 Deepfakes Report Chart_Deepfake training 2026 Deepfakes Report Chart_Verification

 

Takeaways

Deepfakes pose as an emerging fraud and access threat that is directly tied to core operational risks such as wire transfer fraud, account takeover, help desk exploitation, and other social engineering attacks. The following are ways to increase awareness within your organization:

1. Focus on High-Risk Interaction Points
Organizations should prioritize controls around areas where trust-based decisions are made, including financial transactions, account changes, internal approvals, and help desk requests.

2. Enforce Verification and Call Backs
Processes that rely heavily on caller identity, recognized voices, and familiar communication patterns may no longer be sufficient on their own. Additional verification steps should be considered for high-risk requests like only using trusted channels, calling back using a previously established contact method, and, finally, no exceptions. Verifications apply to everyone, even if they are an executive or an important vendor.

3. Align Training with Real-World Attack Scenarios
Employees should be trained not just to recognize suspicious messages, but to question the context, the story being presented, and any sense of urgency.

 

Employee Confidence and Readiness

Lastly, we wanted to understand how confident institutions were in their employees’ ability to recognize deepfake attacks and whether they are actively preparing through exercises and testing.

2026 Deepfakes Report Chart_Employee confidence 2026 Deepfakes Report Chart_Tabletop exercise
Key Insights

Based on this feedback, roughly 8% of respondents reported high confidence in their employees’ ability to detect AI-driven threats, while the majority reported only moderate or low confidence.

At the same time, most organizations have not tested their response capabilities in realistic scenarios, which could factor into why the confidence in identifying deepfakes is low.

Together, this information highlights a critical disconnect:

    • Employees and organizations are not highly confident in their ability to identify deepfake threats, and
    • Organizations are not regularly validating how those threats would be handled in practice
Takeaways

A significant risk exists that goes beyond awareness and affects employees' ability to recognize, verify, and respond appropriately to threats. To address this gap, here is what financial institutions should focus on.

1. Conduct Scenario-Based Exercises
Use realistic simulations to test how employees make decisions during a deepfake or AI impersonation attempt. These exercises can uncover gaps in procedures, communication, and coordination across the institution.

2. Reinforce Through Repetition
Regular testing and reinforcement help ensure that employee confidence is backed by practical experience and proven processes, not just theoretical understanding.

3. Create a Strong Security Culture
Establish an environment where employees feel comfortable to report suspected attacks and do not hesitate to report due to feeling embarrassed or ashamed.

 

How Tandem Can Help

Financial institutions need documented processes, consistent verification procedures, regular testing, and the ability to demonstrate those efforts to regulators and auditors.

Tandem helps organizations move from awareness to operational readiness by providing tools to document, manage, and validate security and compliance activities across the organization.

Document and Standardize Response Procedures

Tandem Incident Management provides pre-built incident response workflows that help organizations:

    • Standardize deepfake and impersonation response procedures
    • Establish clear escalation paths and workflows
    • Document incidents from initial report to resolution
Strengthen Employee Awareness

Tandem Phishing and Training enables organizations to:

    • Deliver ongoing security awareness training
    • Help employees recognize AI-generated phishing and impersonation threats
    • Reinforce reporting and escalation best practices
Define and Validate Security Controls

Tandem Risk Assessment helps teams document:

    • Ownership of risk assessments
    • Monitoring of control effectiveness over time
    • Improved visibility into impersonation and fraud risk mitigation
Demonstrate Readiness During Audits and Examinations

Tandem Audit Management provides a centralized system for:

    • Tracking audit evidence and control documentation
    • Demonstrating preparedness for emerging AI threats
    • Simplifying exams, audits, and regulatory reviews

 

Frequently Asked Questions (FAQs)

1. What are deepfakes in banking and financial institutions?

Deepfakes in banking refer to the use of artificial intelligence to create realistic audio, video, or written content that impersonates real people. In financial institutions, this is used in fraud schemes where attackers pose as executives, employees, or customers. These impersonation attempts are designed to appear legitimate, making them difficult to detect and highly effective in gaining access to systems, data, or funds.

2. How are deepfakes used in financial fraud and cyberattacks?

Deepfakes are most often used to support social engineering attacks, during which individuals are manipulated into taking action. In financial environments, this typically involves fraudulent requests related to payments, account access, or sensitive information. Attackers may use AI-generated emails or cloned voices to create urgency and trust, increasing the likelihood that employees will follow instructions without verifying the request.

3. Why are banks and credit unions at risk from deepfake attacks?

Banks and credit unions are especially at risk because their operations depend heavily on trusted communications and quick decisions. Employees regularly handle transactions, make account changes, and respond to requests that often seem normal and expected.

Deepfake attacks exploit these normal workflows by making fraudulent requests look legitimate, which increases the chance of human error and successful fraud.

4. What are the most common types of deepfake attacks in financial institutions?

The most common deepfake attacks in financial institutions are not video manipulations but rather subtle impersonation attempts embedded in everyday communication. These include AI-generated phishing emails, voice cloning used in phone calls, and fake executive requests. These attack types are effective because they align closely with how employees already communicate and conduct business.

5. How can employees detect deepfake scams and AI impersonation attempts?

Employees can detect potential deepfake scams by focusing on context rather than just content. Many attacks include signs such as urgency, requests that bypass standard procedures, or situations that do not match normal business practices. The most effective response is to pause and verify requests involving sensitive actions, especially when they involve financial transactions or access to confidential information.

6. What are the best ways to prevent deepfake fraud in financial institutions?

Preventing deepfake fraud requires strengthening verification processes and reducing reliance on trust alone. Financial institutions should ensure that high-risk actions require multiple forms of validation and cannot be completed based solely on a single communication channel. Enforce employee use of trusted channels, callback using a previously established contact method, and establish that there are no exceptions. Verifications apply to everyone, even if they are an executive or an important vendor

7. How can financial institutions prepare for deepfake and AI-driven threats?

Preparation requires more than awareness. Financial institutions need to ensure their teams can respond effectively in real-world situations. This includes training employees on realistic attack scenarios, validating response procedures through exercises, improving how incidents are reported and analyzed, and creating a strong security culture that makes employees comfortable to report. Organizations that regularly test their readiness are better equipped to identify gaps and respond quickly when an actual attack occurs.