HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

AI‑Generated Deepfake Phishing Campaigns Drive 84% of Attacks on Finance Firms

A KnowBe4 webinar revealed that AI‑crafted deepfake emails and voice calls now power the majority of phishing attacks, illustrated by a case study at a 4,000‑employee finance firm. The rise of AI‑enabled social engineering stresses the need for continuous security‑awareness controls and audit‑ready evidence.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 databreachtoday.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

AI‑Generated Deepfake Phishing Campaigns Drive 84% of Attacks on Finance Firms

What Happened — A recent KnowBe4 webinar detailed how generative AI is being weaponized to create deepfake phishing attacks. The presenter walked through a multi‑stage APT playbook that targeted a 4,000‑employee financial services firm, including AI‑crafted credential‑harvesting alerts and voice‑based social engineering. The session notes that AI now underpins roughly 84 % of phishing attempts, lowering the technical barrier for attackers.

Why It Matters for Trust & Control Assurance

  • Continuous security‑awareness training and realistic phishing simulations are core controls designed to detect and deter AI‑enhanced social engineering.
  • Mapping awareness‑program metrics to a control‑assurance framework provides defensible evidence for auditors and demonstrates due‑diligence in a high‑risk vector.

Who Is Affected – Financial services firms, large enterprises with remote workforces, and any organization that relies on email and voice communications for credential handling.

Recommended Actions

  • Integrate deep‑fake detection modules into your email gateway and voice‑call verification processes.
  • Refresh your security‑awareness curriculum to include AI‑generated phishing scenarios and conduct quarterly simulated attacks.
  • Capture training completion, test results, and remediation evidence as continuous control‑monitoring artifacts.

Technical Notes – Attack vector: AI‑generated deepfake emails and voice calls used for credential harvesting and escalation. No specific CVE; the threat leverages publicly available generative models and social‑engineering tactics.

Source: DataBreachToday Webinar

📰 Original Source
https://www.databreachtoday.com/webinars/webinar-when-reality-lies-deepfakes-evolution-phishing-ap-w-7355

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →