Briefing

  • The cybersecurity industry has paid close attention to how AI helps hackers analyze vulnerabilities faster and write more sophisticated malware, but a new report points out that AI's progress in imitating corporate leaders is equally far-reaching.
  • This year, more than half (53%) of organizations experienced impersonation attacks targeting executives or frontline employees, according to a report released by security company Outtake on June 4.
  • At the same time, the report found that among respondents surveyed by Outtake, three-quarters only conduct limited impersonation monitoring or respond passively when attacks occur.

Deep Insights

AI's ability to generate realistic fake media has opened a "second front" for enterprises in combating impersonation scams, Outtake noted in the report based on a survey of more than 1,100 cybersecurity and risk management leaders.

The report shows that nearly half (47%) of enterprises "have experienced confirmed or suspected synthetic media impersonation of executives or brand representatives." Additionally, enterprises view AI-generated attacks as the largest visibility gap in their anti-impersonation strategies.

"People are the attack surface with the greatest exposure and the weakest protection," said Outtake. The report states that only 43% of enterprises conduct identity deception simulations involving the executive level to identify the greatest potential impersonation risks.

The report found that enterprises' AI threat preparedness is equally concerning regarding agent technology. Outtake pointed out that most enterprises fail to effectively supervise and protect these agents, increasing the risk of agent hijacking attacks that could damage corporate reputation or finances. Only 4% of enterprises said they fully monitor and control their AI agents.

The report gives an example: an AI agent in the accounting department receives a seemingly harmless payment inquiry email containing hidden code that overrides the agent's programming, forcing it to share information with untrusted third parties.

"Agents now sit at a new trust boundary: one foot in the untrusted external world, the other in trusted internal systems," said Outtake. "Injected instructions cross the boundary between them."

The report also found that governance fragmentation is another major weakness for enterprises. 21% of enterprises have no dedicated team responsible for assessing and managing digital trust risks; security operations centers handle this responsibility in 18% of enterprises, fraud and security teams account for 13%, and threat intelligence teams account for 11%. More than 60% of enterprises describe their digital trust risk management activities as fragmented and siloed.