AI accelerates identity impersonation attacks, enterprises unprepared in protection
Outtake's latest report indicates that AI not only enhances hackers' abilities to analyze vulnerabilities and write malware but also poses a serious threat in identity impersonation. This year, 53% of organizations have faced impersonation attacks targeting executives or frontline employees, and 47% have encountered confirmed or suspected synthetic media impersonation incidents. However, 75% of surveyed enterprises only conduct limited monitoring or post-incident response, and only 43% carry out executive identity deception simulations. The lack of oversight for AI agents also poses a hidden risk, with only 4% of enterprises fully monitoring AI agents. Governance fragmentation is widespread, with 21% of enterprises lacking a dedicated team responsible for digital trust risks.

Briefing
- The cybersecurity industry has paid close attention to how AI helps hackers analyze vulnerabilities faster and write more sophisticated malware, but a new report points out that AI's progress in imitating corporate leaders is equally far-reaching.
- This year, more than half (53%) of organizations experienced impersonation attacks targeting executives or frontline employees, according to a report released by security company Outtake on June 4.
- At the same time, the report found that among respondents surveyed by Outtake, three-quarters only conduct limited impersonation monitoring or respond passively when attacks occur.
Deep Insights
AI's ability to generate realistic fake media has opened a "second front" for enterprises in combating impersonation scams, Outtake noted in the report based on a survey of more than 1,100 cybersecurity and risk management leaders.
The report shows that nearly half (47%) of enterprises "have experienced confirmed or suspected synthetic media impersonation of executives or brand representatives." Additionally, enterprises view AI-generated attacks as the largest visibility gap in their anti-impersonation strategies.
"People are the attack surface with the greatest exposure and the weakest protection," said Outtake. The report states that only 43% of enterprises conduct identity deception simulations involving the executive level to identify the greatest potential impersonation risks.
The report found that enterprises' AI threat preparedness is equally concerning regarding agent technology. Outtake pointed out that most enterprises fail to effectively supervise and protect these agents, increasing the risk of agent hijacking attacks that could damage corporate reputation or finances. Only 4% of enterprises said they fully monitor and control their AI agents.
The report gives an example: an AI agent in the accounting department receives a seemingly harmless payment inquiry email containing hidden code that overrides the agent's programming, forcing it to share information with untrusted third parties.
"Agents now sit at a new trust boundary: one foot in the untrusted external world, the other in trusted internal systems," said Outtake. "Injected instructions cross the boundary between them."
The report also found that governance fragmentation is another major weakness for enterprises. 21% of enterprises have no dedicated team responsible for assessing and managing digital trust risks; security operations centers handle this responsibility in 18% of enterprises, fraud and security teams account for 13%, and threat intelligence teams account for 11%. More than 60% of enterprises describe their digital trust risk management activities as fragmented and siloed.