25% of Financial Institutions Report Suspected or Confirmed Deepfake Incidents, New Survey Finds
Wednesday, September 16th, 2026
A new survey of financial institutions reveals that nearly one in four organizations reported deepfake or AI-driven impersonation incidents, and many more are uncertain whether they have already been targeted.
The survey, conducted by Tandem, gathered responses from banks, credit unions, and other financial institutions across a range of asset sizes.
Among the findings:
- 25% reported a known deepfake, voice cloning, or AI impersonation incident.
- 21% were unsure whether they had experienced such an incident.
- AI-generated phishing and social engineering attacks were identified as leading concerns.
- Voice cloning ranked among respondents' most significant AI-related threats.
- Only 8% of respondents expressed high confidence in employees' ability to identify AI-generated scams.
- Most organizations reported they have not yet conducted deepfake-focused tabletop exercises.
Deepfake Threats Are Active and Often Go Undetected
46% of respondents either reported an incident or could not rule one out.
When asked about their primary concerns, respondents overwhelmingly pointed to fraud and impersonation scenarios (such as AI-generated phishing, social engineering, and voice cloning) rather than manipulated media or public-facing content.
These fraud attempts can all be inserted into everyday business processes, including payment requests, account access requests, customer interactions, and help desk communications. All scenarios are ones which employee actions and operational processes play an important role in detection and response.
Confidence and Readiness Lag Behind the Threat
The survey also found that confidence levels remain relatively low. Only 8% of institutions reported high confidence in employees' ability to recognize AI-generated scams and impersonation attempts.
At the same time, most organizations have not yet tested their response capabilities through deepfake-related tabletop exercises under realistic conditions.
This highlights important areas of focus as institutions evaluate their incident response programs against AI-related threats, such as verification procedures, employee training, and response testing.
Preparing for AI-Driven Impersonation Risks
While many organizations have begun incorporating deepfake risks into training and security discussions, the findings indicate that awareness alone is not sufficient.
Financial institutions must move toward:
- Strengthening verification and escalation procedures
- Improving detection of human-layer attacks
- Testing response capabilities through real-world scenarios
Organizations that make this transition will be better positioned to reduce exposure and respond effectively as AI-driven threats continue to evolve.


