When we talk about AI-powered attacks, most people picture machine-vs-machine warfare: DDoS, exploitation, RCE. But a survey Gartner published yesterday (Sept 22), covering 297 senior security leaders, moves the battlefield straight onto human senses: 41% of organizations have already experienced a deepfake voice-call fraud incident in the past 12 months, and 36% a deepfake video-call fraud incident. This is no longer a sci-fi scenario — it is the new normal for most mid-size and larger companies.
In the same survey, 79% of organizations faced phishing, spear-phishing or BEC (business email compromise) in the past year, and 58% reported vishing or smishing incidents. Gartner analyst Craig Porter put it plainly: attackers now combine phishing, BEC, synthetic media, and personal context aggregated across channels into one coordinated strike — and “most attacks will continue to rely on users, stolen credentials, weak recovery processes.”
The crueler fact is that the “detect it yourself” defense is collapsing. A Malwarebytes survey found nearly nine in ten adults say they can no longer tell real content from AI-generated content; in a Jumio survey, 69% of respondents believe AI-driven fraud now poses a greater personal risk than traditional identity theft. The most-cited case remains the 2024 incident where a finance employee, “seeing” the CFO and multiple executives on a video call, executed 15 wire transfers totaling over US$25 million into the scammers’ accounts — discovered only days later.
Research from the Vector Institute adds a colder note: treated as a standalone technical capability, deepfake detection is already losing ground — and will keep losing, because generative models keep getting stronger. You cannot build a defense on “telling real from fake.” That race is one we will likely keep losing.
Since human eyes can no longer be trusted, Gartner’s advice to CISOs is refreshingly practical:
That third point matters most and is most often ignored: any single signal looks plausible; only when you connect them does the fraud show its shape. A “manager” asking for a payment on a video call looks entirely normal in isolation — but if it coincides with a credential reset, a new device login, and a privilege change, it is an attack, not a coincidence.
From an operations perspective, the conclusion is clear: “people” as a defense layer have officially been downgraded to “bypassable.” When attackers can use AI to impersonate anyone with authority — from the CFO to the DevOps lead — every trust-based human action becomes a potential opening.
This is exactly why we keep pushing three things: first, automated edge defense that never sleeps — WAF, DDoS scrubbing, and bot filtering handling traffic-level attacks at machine speed, without waiting for anyone to see an alert; second, cross-signal anomaly detection — your API call patterns, privilege changes, login sources, and payment-adjacent actions all look normal in isolation, but only connected do they reveal “this person is not behaving like themselves right now”; third, MTTR compressed to the minute level — the few minutes a victim takes to notice are the attacker’s biggest window; automated triage and rollback are what actually stop the bleeding.
AI will not only attack your servers — it will attack the people who run them. Defense has to be built on both sides at once.
When 41% of companies have already been fooled on a phone call by AI, “trusting your team to be careful” is just a placebo. Lafa System’s approach is simple: move detection, blocking, and verification entirely to the machine layer, so threats are stopped before a human even gets a chance to hesitate — because humans hesitate, machines do not.