Watch out – even small businesses are now facing threats from deepfake attacks

  • Three in five businesses have experienced deepfake attacks recently, Gartner finds
  • Audio and video deepfakes are becoming more accessible to attackers
  • Prompt injection is also giving criminals access to sensitive company information

Gartner says even small businesses are facing a spike in cybercrime, and AI could be to blame – more than three-fifths (62%) of organizations reporting AI-driven attacks in the past year.

The firm’s study found three in five (62%, again) experienced deepfake attacks, with 44% experiencing deepfake audio attacks, making this the most common attack vector compared with video deepfakes (36%).

Prompt-injection attacks against AI tools (32%) and attacks on enterprise generative AI application infrastructure (29%) were also noted, showing how AI isn’t just being used to strengthen crime, but it’s also serving as a useful vulnerability for many criminals.

Is AI causing more cybercrime?

“As adoption accelerates, attacks leveraging GenAI for phishing, deepfakes and social engineering have become mainstream, while other threats – such as attacks on GenAI application infrastructure and prompt-based manipulations – are emerging and gaining traction,” Gartner VP Analyst Akif Khan explained.

The report details how rapid AI development has seen deepfakes go from complex to instant, with audio deepfakes now being generated in real time to make them highly convincing and personalized.

Although real-time, person-specific deepfakes remain very expensive, only time stands between limited use and widespread use.

On the field, cybersecurity firms and analysts are seeing deepfakes being used as an initial attack vector, before attackers revert to simpler and cheaper methods. For example, scammers sometimes fake a CEO on a call before switching to text-only social engineering methods.

When it comes to exploiting companies’ AI systems, attackers are frequently observed tricking systems into revealing sensitive information or abusing integrations to execute code by giving malicious prompts.

Looking ahead, companies of all sizes – not just multinational enterprises – are being advised to up their game, with the zero-trust approach emerging as a firm favorite to block out unwarranted activity.

You might also like

Read more @ TechRadar

Latest posts

Netgear Orbi 373: affordable and easy-to-use mesh Wi-Fi system for larger homes

Netgear Orbi 373: One-minute reviewNetgear’s new management continues its quest to provide more affordable options for home users who want to upgrade their Wi-Fi....

Hackers are exploiting OAuth loophole for persistent access – and resetting your password won’t save you

Researchers have observed attackers weaponizing OAuth apps Attackers gain access that persists even through password changes and MFAThis isn't just a proof of concept...

Get $100 off the near-perfect OnePlus 13 with this code for a limited time

With the imminent release of the OnePlus 15, we're being treated to a super sweet discount on the phone that it'll supersede. That means...

Oracle Red Bull is securing the win with 1Password – a credential halo balancing speed and security on and off the track

Formula 1 is a notoriously high-stakes sport, but the danger doesn’t stop when the chequered flag waves at the end of the race weekend.Engineering,...

“A first step in Europe” – Proton slams Switzerland’s new surveillance bill at the United Nations Forum

Proton Mail has reiterated its opposition to Switzerland's new surveillance billThe bill will force VPN and messaging apps to identify and retain user dataProton...

Settlers, herd your sheep – Netflix reveals Catan movies and TV series, and I know just how they should start

Think you've mastered the Catan board game? Well, Netflix is about take the experience to the small screen, having secured global rights to multiple...

Smart bed owners experience AWS outage nightmare as they’re left sweating and stuck in upright position

Smart bed owners were hit by this week's big AWS outageOwners of the Eight Sleep Pod reported overheating and being stuck uprightEight Sleep tells...

Panasonic just launched a cheaper big-screen OLED TV, but still with the high-end sound and processing of its flagship Z95B

Integrated Fire TV and ATSC 3.0 supportTons of gamer-friendly features including 144Hz, G-SYNC, Freesync v2 Premium and VRR$2,499, orders live from 27 OctoberPanasonic's excellent...

NYT Connections hints and answers for Thursday, October 23 (game #865)

Looking for a different day?A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people...

NYT Strands hints and answers for Thursday, October 23 (game #599)

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people...