Here’s what AI attacks actually look like
Discussions about AI-powered attacks happen behind closed doors, tucked away in internal incident reports and confined to candid exchanges between peers at industry conferences. This secrecy leaves security leaders with an near-impossible task: responding to threats they can’t see.
That’s why we’re breaking down the anatomy of AI attacks: what they look like, how they work, and why they’re able to slip past traditional defenses.
Here are the stakes: A multi-million dollar wire transfer after a deepfake video call.1 A North Korean operative moving through your hiring pipeline.2 An IT helpdesk handing over SSO credentials to someone posing as an employee.3
Attacks like this are playing out at companies everywhere, everyday. And with AI-driven attacks growing by nearly 14x in six quarters,4 organizations can’t afford to treat this as low-risk threat.
The scams are here. Is your security strategy ready for them?
- Fake job candidates
- Executive impersonation
- IT helpdesk attacks
- Contact center attacks
- Vendor or partner impersonation
- Wealth management scams
AI has forced security leaders to doubt the channels they trust
Talk to a CISO right now and one word keeps coming up: uncertainty. Uncertainty about how AI attacks will reshape security strategies. Uncertainty about where to invest. Uncertainty about where the real risk even lives.
That’s exactly why we created the CISO Deepfake Defense Council.The Council brings together a select group of highly regarded security executives from seven Fortune 500 enterprises and other category-leading organizations across a broad cross-section of industries, including technology, financial services, healthcare, life sciences, defense, enterprise software, cryptocurrency, and cybersecurity. The Council is focused on delivering strategic guidance to help enterprises understand, prepare for, and defend against deepfakes—one of the fastest-emerging threats to trust and identity.
We interviewed these leaders individually and as a group, probing to understand how they’re thinking about the new enterprise threat landscape.
Takeaways from the CISO Deepfake Defense Council
- Unauthorized access is just one step in a longer attack chain
Impersonation (deepfakes or otherwise) opens the door. Once a bad actor gets in, they become an insider threat, often with the access they need to cause system-wide damage. - Telling the difference between a good bot and bad bot is about to be critical
As companies incorporate AI into their workflows and authorized agents begin handling tasks, companies will need a way to discern what is an approved use of AI and what is suspicious, unauthorized activity. - Attackers are playing in blindspots
It’s nearly impossible to defend against what you can’t see. That’s why bad actors attack the channels that seem low-risk or protected (e.g., hiring or vendor comms). Without visibility, leaders can struggle to calculate exposure. - Perceived weak points vary across industries
One security leader points to helpdesk impersonation as a critical risk, another points to contact center attacks. This variation seems to be driven by industry-specific priorities. For example, financial services may prioritize high-risk customer or client interactions that can end in direct financial losses. Leaders from other industries may perceive different interactions as more vulnerable. - Companies need detection that works with them, not against them
Adoption of deepfake detection needs to integrate seamlessly into existing workflows. Roadblocks will directly impact whether people utilize the tool when its needed.
“A healthy immune system needs to be proactive, anticipating threats before they attack. In the age of deepfakes, enterprises need to approach defense in the same way: building their cybersecurity strategy for resilience and adaptability.”Jim Routh, Chairman of The CISO Deepfake Defense Council and former 6X CSO/CISO in financial services and healthcare
How CISOs think about the new threat landscape
Council members mapped AI attacks by reputational and financial risk. Answers varied, but six threats rose to the top.5 This briefing covers those six.

Text
1%
Text
Text
1%
Text
Text
1%
Text
Text
Lorem ipsum dolor sit amet consectetur. Sit convallis ullamcorper et varius venenatis blandit vitae hendrerit blandit. Hac aenean tellus consectetur elit orci aenean ipsum arcu. Turpis a laoreet sit rhoncus eros penatibus facilisis dolor tempus. Vitae gravida fames nunc dui scelerisque porta nulla ut. Sit mi volutpat ipsum odio nulla sociis.
Lorem Ipsum is simply dummy
Vitae eleifend mi lorem iaculis malesuada sit adipiscing vel. Sit massa ut etiam eu.
1 CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’,” February 2024.
2 Pindrop, “From Interview to Intel Drop: The Moment We Exposed a Coordinated Hiring Scheme,” July 2025
3 Pindrop, “How Pindrop Technology Could’ve Prevented the MGM Breach,” September 2023.
4 Based on Pindrop customer data from Q4 2024-Q1 2026. Derived from a study of over 700M calls.
5 Compiled based on five anonymous mapping exercises with security leaders from the CISO Deepfake Defense Council.




