Blog

Deepfake Statistics 2026: The Numbers Behind AI-Generated Fraud

Sandy Kronenberg

Sandy Kronenberg

Chief Executive Officer

Published: July 20, 2026

Deepfake Statistics 2026: AI Fraud by the Numbers Image
TL;DR

Deepfake fraud is the use of AI-generated voice, video, image, or text to impersonate a real person to steal money, credentials, or access. In 2026, it is a mainstream attack vector: 62% of organizations have faced at least one deepfake attack, reported losses have passed $2 billion, and campaigns routinely span voice, video, and email at once. This guide collects the verified deepfake statistics that matter, every figure attributed to a named source, so you can size the risk and brief on your board.

What do the 2026 deepfake statistics actually measure?

A deepfake statistic is only as good as its source. The numbers below come from three kinds of evidence: surveys of security leaders (how many organizations are being attacked), incident and loss databases (how much money is being taken), and law-enforcement reporting (what victims formally report). Each answers a different question, and together they describe the same trajectory: sharply up.

Deepfakes are one technique inside the broader category of impersonation attacks and social engineering. The statistics here focus on the deepfake layer specifically: synthetic voice, video, and AI-assisted email.

Key Takeaways

  • checkmark

    62% of organizations experienced at least one deepfake attack in the past 12 months, and 37% of security leaders have encountered one on a live video call, according to Gartner's 2025 survey of 302 security leaders.

  • checkmark

    Reported deepfake fraud losses have reached $2.19 billion globally, $1.65 billion of it in 2025 alone, per Surfshark's 2026 analysis of the Resemble AI and AI Incident databases.

  • checkmark

    The US is the most-targeted country at $712 million in losses, 43% of it aimed at the corporate sector (Surfshark, 2026).

  • checkmark

    The FBI logged its first-ever AI-related crime category in 2025: 22,000+ complaints and roughly $893 million in losses, per the 2025 Internet Crime Report.

  • checkmark

    Three seconds of audio is enough to clone a voice with an ~85% match, and 70% of people are not confident they could tell the difference, per McAfee's voice-cloning research.

  • checkmark

    Deloitte projects US generative-AI-enabled fraud losses of $40 billion by 2027, up from $12.3 billion in 2023.

In This Article

How common are deepfake attacks in 2026?

Deepfake attacks are now a baseline threat, not an emerging one. In Gartner's survey of 302 cybersecurity leaders across North America, EMEA, and APAC, 62% of organizations experienced at least one deepfake attack in the preceding 12 months: a voice or video impersonation, an attack on an automated verification process, or both (Gartner, 2025).

The same research found that 37% of security leaders have personally encountered a deepfake incident during a video call; the channel employees trust most. Exposure is no longer limited to work either: the average American now encounters roughly 2.6 deepfakes per day across media and messaging (McAfee, 2025). When synthetic content is this routine, recognizing it by eye stops being a defense.

How much money is deepfake fraud costing businesses?

Reported deepfake-related fraud has cost $2.19 billion globally, with $1.65 billion of that in 2025 alone and $96 million already recorded in early 2026. The United States leads all countries at $712 million in losses, 43% of it targeting the corporate sector through executive impersonation and fraudulent transfer requests.

Official US figures point in the same direction. In 2025, the FBI introduced AI-related fraud as a formal crime descriptor for the first time in its 26-year history, logging 22,000+ complaints and roughly $893 million in losses (FBI IC3, 2026). Business email compromise, increasingly AI-assisted, cost another $3.04 billion, the #2 crime type by losses. Both figures are understated by design: most incidents are never reported.

The trajectory matters more than any single number. Deloitte's base case projects US generative-AI-enabled fraud losses reaching $40 billion by 2027, a 32% compound annual growth rate from $12.3 billion in 2023.

Measure

Figure

Source (year)

Cumulative reported deepfake losses, global

$2.19 billion

Surfshark (2026)

Reported deepfake losses in 2025 alone

$1.65 billion

Surfshark (2026)

US losses (most-targeted country)

$712 million

Surfshark (2026)

AI-related crime losses reported to the FBI, 2025

~$893 million

FBI IC3 (2026)

BEC losses reported to the FBI, 2025

$3.04 billion

FBI IC3 (2026)

Projected US gen-AI fraud losses by 2027

$40 billion

Deloitte (2024)

Measure

Figure

Source (year)

Cumulative reported deepfake losses, global

$2.19 billion

Surfshark (2026)

Reported deepfake losses in 2025 alone

$1.65 billion

Surfshark (2026)

US losses (most-targeted country)

$712 million

Surfshark (2026)

AI-related crime losses reported to the FBI, 2025

~$893 million

FBI IC3 (2026)

BEC losses reported to the FBI, 2025

$3.04 billion

FBI IC3 (2026)

Projected US gen-AI fraud losses by 2027

$40 billion

Deloitte (2024)

Which channels do deepfake attacks use: voice, video, or email?

All three, usually in the same campaign. The channel-level statistics show why single-channel defenses keep missing coordinated attacks.

Voice cloning and vishing

Vishing incidents surged +442% between the first and second half of 2024, and H1 2025 volume already exceeded all of 2024 (CrowdStrike, 2025). The barrier to entry is gone: three seconds of audio yields an ~85% voice match (McAfee, 2023). Any earnings call or LinkedIn video is enough source material.

Deepfake video on live calls

37% of security leaders have encountered a deepfake on a live call (Gartner, 2025). Every major incident on record, including Arup, WPP, and Ferrari, began or closed inside a meeting platform, and no major platform natively detects synthetic participants.

AI-assisted email and BEC

The FBI's 2025 data show voice cloning layered onto business email compromise: an AI-written email sets up the wire, then a follow-up calls in the CFO's cloned voice confirms it (FBI IC3, 2026). This cross-channel pattern is why deepfake detection fails without cross-channel awareness.

A real-world example: the Arup deepfake fraud

In early 2024, a finance employee at the Hong Kong office of engineering firm Arup joined a video conference with people he recognized as the company's CFO and several colleagues. Every person on that call was deepfake. He completed 15 transfers totaling roughly $25.6 million before discovering the fraud through routine follow-up with headquarters. The funds were never recovered (CFO Dive, 2024).

The statistics above are this story at scale: the employee did his job, confirmed with colleagues who appeared to be in the room, and no alert fired, because the room itself was fake.

Can people detect deepfakes on their own?

The evidence says no. 70% of people say they are not confident they could distinguish a cloned voice from a real one (McAfee, 2023). The human element remains present in 62% of breaches per the Verizon 2026 Data Breach Investigations Report: people, not infrastructure, are the attack surface deepfakes are engineered to exploit.

Gartner reached the structural conclusion in 2024: by 2026, 30% of enterprises will no longer consider standalone identity verification reliable because of AI-generated deepfakes. Awareness training helps people question anomalies, but no amount of vigilance detects a synthetic face rendered in real time. That takes a detection layer, which is the core argument of human defense.

Where are the numbers heading: regulation and Trust Ops

Two forces will define the next 24 months. First, regulation: from 2 August 2026, the EU AI Act's Article 50 requires deployers to disclose deepfake content, with fines up to €15 million or 3% of global turnover. Second, the market response: Gartner predicts 50% of enterprises will invest in disinformation security and Trust Ops by 2027, up from under 5% in 2025, and 40% of government organizations will establish Trust Ops functions by 2028. For a full breakdown of the discipline, see What Is TrustOps in Cybersecurity?.

In short: deepfake defense is moving from a nice-to-have to a budgeted, named function, with a compliance deadline attached.

How Netarx closes the gap the statistics expose

Netarx is a trust operations platform built to defend the human attack surface these statistics describe. Rather than relying on a single signal, the platform analyzes more than 75 metadata signals alongside multimodal voice and video AI inference models, correlating them in real time across every communication channel.

Capabilities most relevant to the numbers in this article:

All-media coverage across video, voice, email, SMS, file, and image, so the cross-channel campaigns behind the FBI's BEC figures are not missed.

Real-time alerts inside the workflow as the interaction happens, closing the window in which Arup-style transfers are approved.

Injection and replay resistance to flag virtual cameras and pre-recorded video used to spoof live calls.

Continuous identity verification via the Netarx Identity Key, so trust builds over a verified history rather than being assumed at the start of a call.

Explore the full capability set on the Netarx product page, or start with why a dedicated detection layer is now a baseline requirement.

SOURCES & REFERENCES

  1. Gartner. (2025). Why CIOs Can't Ignore the Rising Tide of Deepfake Attacks. gartner.com

  2. FBI Internet Crime Complaint Center. (2026). 2025 Internet Crime Report. ic3.gov

  3. Surfshark. (2026). Global deepfake fraud reaches $2.19B, US leads in losses. surfshark.com

  4. Deloitte Center for Financial Services. (2024). Generative AI is expected to magnify the risk of deepfakes and other fraud in banking. deloitte.com

  5. CrowdStrike. (2025). Global Threat Report. crowdstrike.com

  6. McAfee. (2023). Artificial Imposters: AI voice cloning research. mcafee.com

  7. Verizon. (2026). 2026 Data Breach Investigations Report. verizon.com

sandy

Sandy Kronenberg

VerifiedVerified

Chief Executive Officer

CEO/Founder of Netarx LLC, Real-time detection of deepfake and social engineering threats via enterprise video, voice and email. Managing Partner of Koach Capital, a Private Equity firm managing a multitude of commercial real estate (CRE) funds whose focus is retail sale-leasebacks. Sandy's entrepreneurial success began by founding a network integration and services provider that served large enterprises. We focused on advanced technologies including Business Intelligence (BI), Network & Information Security, Virtualization, Storage Area Networks, Unified Communications and Data Center Services. In 2009, Netarx acquired the VAR business of Analysts International (including Sequoia and Entree Systems). In 2011 Netarx was acquired by Logicalis (a division of Datatec - Symbol LSE: DTC) and stayed on as its Chief Technology Officer. He continued to build by founding Verge.io (Formerly Yottabyte) and Service.com. Also, Sandy served as a General Partner of Ludlow Ventures, a venture capital fund focusing on investments in early-stage tech companies. Sandy contributes to the community via lectures, publications and developing new technologies - he currently holds 8 Patents.

LinkedIn

Not sure how your defenses would hold up against a real-time deepfake?

Frequently Asked Questions

Very. 62% of organizations reported at least one deepfake attack in the past 12 months in Gartner's 2025 survey of 302 security leaders, and 37% of security leaders have encountered a deepfake during a live video call.