Despite 88% training their staff, over half of organizations lost money to deepfake attacks last year
Atlanta, GA – October 9, 2025 – IRONSCALES, the AI-powered email security leader protecting over 17,000 global customers from advanced phishing attacks, today released a new industry report, Beyond Detection: The $280K Reality of Deepfake Attacks. Based on the survey responses of 500 IT professionals in organizations with 1,000-10,000 employees, the report points to a number of leading indicators that deepfake-related fraud is now more widespread and successful than ever, causing enterprises significant financial damage. Despite this rise, the report’s findings suggest that organizations are still woefully unprepared to combat these threats, as over half (55%) of organizations reported losses attributed to deepfake or AI-voice fraud in the past 12 months.
The report confirms that financial losses from these attacks are substantial, with the mean loss standing at over $280,000. Over 61% of organizations that lost revenue reported losses exceeding $100,000, while nearly a fifth (19%) reported having lost $500,000 or more, proving six-figure losses are now the norm.
"As we enter the age of Phishing 3.0, the most worrying trend we see is that IT leaders claim confidence in their defenses, despite the majority of survey respondents reporting financial losses,” said Eyal Benishti, CEO of IRONSCALES. “When the stakes surpass six-figure losses, it's imperative that organizations make the necessary investments to mitigate these threats. The data clearly shows that traditional security defenses are no longer sufficient, and organizations must invest in adaptive security measures that will evolve with the threats they detect.”
Deepfake-enabled attacks are no longer a rare or emerging threat. They are real, widespread, and effective. The report goes on to detail a number of interesting findings that highlight the frequency and costly nature of deepfake-related incidents. Some key findings include:
Given the high costs being drained, organizations must strategically and quickly adopt a three-pronged defensive approach that includes training, technology, and policies specifically designed to detect and defend against deepfake-driven attacks. It has become clear that organizations must use AI-driven technologies to detect AI-enabled threats and automate incident responses to mitigate damages.
To take a closer look at the report findings, including how organizations can prepare for deepfake-related cyberattacks, download a complete copy of the report here.
About IRONSCALES
IRONSCALES is the leader in AI-powered email security protecting over 17,000 global organizations from advanced phishing threats. As the pioneer of adaptive AI, we detect and remediate attacks like business email compromise (BEC), account takeovers (ATO), and deepfake attacks that other solutions miss. By combining the power of AI and continuous human insights, we safeguard inboxes, unburden IT teams, and turn employees into a vital part of cyber defense across enterprises and managed service providers. IRONSCALES is headquartered in Atlanta, Georgia. To learn more, visit www.ironscales.com or follow us on X @IRONSCALES.
PR originally published at BusinessWire: https://www.businesswire.com/news/home/20251009951297/en/IRONSCALES-Report-Finds-Over-Half-of-Organizations-Reported-Significant-Revenue-Losses-Attributed-to-Deepfakes-in-the-Past-Year-with-Average-Losses-of-Over-%24280K