REPORT

1 in 4 organizations hit by a deepfake lost $1 million or more

When a deepfake attack lands, the financial exposure can be significant.

Among organizations that experienced or suspected a deepfake attack, almost half reported total costs of $500,000 or more. Approximately 25% crossed the $1 million threshold.

Total cost of attack

Includes direct losses, remediation, and staff time.

What came next only added to the damage. 49% of affected organizations faced follow-on cyberattacks, like ransomware, a particularly troubling trend given the potential impact.

Consequences that followed

% of affected organizations reporting each consequence

In May 2026, the FBI published an alert on The Silent Ransom Group (SRG), which targets companies, particularly law firms, using social engineering. In some cases, SRG impersonates an IT professional and manipulates an employee into granting remote desktop access. From there, the group exfiltrates data and extorts the organization.

The consequences can be severe: data exfiltration, network intrusion, ransom payouts, and operational disruption. After hackers impersonated an employee on a call with MGM’s IT helpdesk, they launched a ransomware attack that disrupted operations for days. MGM projected a $100 million hit to quarterly earnings.When costly attacks are hitting channels once considered protected, it becomes difficult to know where to focus.

No one wants to buy insurance to use it, but you want to have it at your disposal when the time comes.Doug Innocenti, CISO, MoonPay

In May 2026, Pindrop published a report based on findings from the CISO Deepfake Defense Council, a group of security executives from seven Fortune 500 enterprises and other leading organizations. The Council is focused on delivering strategic guidance to help enterprises understand, prepare for, and defend against deepfakes—one of the fastest-emerging threats to trust and identity.

Of the six AI attacks impacting real-time channels, council members mapped six based on reputational and financial risk. Three of those attacks (fake job candidates, IT helpdesk attacks, and executive impersonation) landed as catastrophic or critical threats, reflecting high risk to both finances and reputation.1

That’s why the missing detection layer matters. The financial and reputational exposure from a deepfake attack can compound if it goes undetected. If security leaders understand the problem and know that the implications can be severe, why is the adoption of purpose-built tools so low?

Sources and methodology

75% agree deepfakes won't be a boardroom priority until it hits an executive

Continue reading

Move from understanding to action

Fight back against AI attacks with Pindrop.

Schedule a demo