
LUBBOCK, Texas, Sept. 14, 2026 /PRNewswire/ -- A new survey of financial institutions reveals that nearly one in four organizations reported deepfake or AI-driven impersonation incidents, and many more are uncertain whether they have already been targeted.
The survey, conducted by Tandem, gathered responses from banks, credit unions, and other financial institutions across a range of asset sizes.
Among the findings:
- 25% reported a known deepfake, voice cloning, or AI impersonation incident.
- 21% were unsure whether they had experienced such an incident.
- AI-generated phishing and social engineering attacks were identified as leading concerns.
- Voice cloning ranked among respondents' most significant AI-related threats.
- Only 8% of respondents expressed high confidence in employees' ability to identify AI-generated scams.
- Most organizations reported they have not yet conducted deepfake-focused tabletop exercises.
Deepfake Threats Are Active and Often Go Undetected
46% of respondents either reported an incident or could not rule one out.
When asked about their primary concerns, respondents overwhelmingly pointed to fraud and impersonation scenarios (such as AI-generated phishing, social engineering, and voice cloning) rather than manipulated media or public-facing content.
These fraud attempts can all be inserted into everyday business processes, including payment requests, account access requests, customer interactions, and help desk communications. All scenarios are ones which employee actions and operational processes play an important role in detection and response.
Confidence and Readiness Lag Behind the Threat
The survey also found that confidence levels remain relatively low. Only 8% of institutions reported high confidence in employees' ability to recognize AI-generated scams and impersonation attempts.
At the same time, most organizations have not yet tested their response capabilities through deepfake-related tabletop exercises under realistic conditions.
This highlights important areas of focus as institutions evaluate their incident response programs against AI-related threats, such as verification procedures, employee training, and response testing.
Preparing for AI-Driven Impersonation Risks
While many organizations have begun incorporating deepfake risks into training and security discussions, the findings indicate that awareness alone is not sufficient.
Financial institutions must move toward:
- Strengthening verification and escalation procedures
- Improving detection of human-layer attacks
- Testing response capabilities through real-world scenarios
Organizations that make this transition will be better positioned to reduce exposure and respond effectively as AI-driven threats continue to evolve.
About the Survey
The survey included responses from 85 financial professionals, representing banks, credit unions, and other financial institutions. Respondents spanned a broad range of asset sizes, providing insight into how organizations of varying scale are approaching deepfake and AI-related risks.
About Tandem
Tandem helps over 1800 financial institutions across the US simplify and strengthen their security and compliance programs by providing a centralized platform for managing policies, procedures, controls, and audit readiness. By improving visibility and consistency across processes, Tandem enables organizations to better manage risks, including AI-driven threats such as deepfakes and impersonation attacks. Learn more at https://tandem.app.
SOURCE Tandem
Share this article