Kasey Cromer, Netlok | August 24, 2026
Executive Summary
Targeted impersonation is no longer an edge case. According to Outtake’s 2026 State of Digital Risk Report, based on a survey of more than 900 enterprise security, fraud, and risk leaders, 53% of organizations had an executive or employee impersonated in the past year. A separate Outtake report — the 2026 State of Executive Impersonation, drawn from 40,000 impersonation alerts across approximately 300 monitored executives — found that 47% of organizations had already encountered confirmed or suspected AI-generated impersonation of an executive or brand representative. AI has made these attacks faster to produce, harder to detect, and easier to execute across every channel an organization uses — email, voice, text, video, and collaboration tools.
The objective behind every impersonation attempt is consistent: persuade a trusted person to reveal a password, enter it into a login page while the attacker watches, approve an authentication request, or grant access under false pretenses. That makes impersonation fundamentally an identity security problem. Filters and training help, but they cannot guarantee that every employee will recognize every convincing fraud. Password-based authentication gives attackers a transferable prize. Removing password-based credentials at the identity layer changes the payoff entirely: even when the deception gets through, there is no password to hand over.
Photolok by Netlok does not prevent every impersonation attempt from reaching an employee. But it removes what the attacker is trying to obtain when one does.
Impersonation Has Reached Enterprise Scale
The evidence shows an environment where impersonation and fraud are now pervasive across organizations of every size and sector. Outtake’s 2026 Report found that 84% of organizations experienced material digital risk incidents in the past year, yet only 7% describe their program as leading — meaning the vast majority are dealing with active threats while operating programs they themselves consider underdeveloped. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of respondents reported an increase in fraud and impersonation-driven attacks in 2025, and that 73% said they or someone in their network had been personally affected.
At the transaction level, the Anti-Phishing Working Group (APWG) recorded 971,181 phishing attacks in the first quarter of 2026, rising from 853,244 in Q4 2025 — a 13.8% increase in a single quarter, directly reported in APWG’s Q1 2026 Phishing Activity Trends Report. The FBI’s 2025 Internet Crime Report registered phishing and spoofing as the most frequently reported cybercrime category for the third consecutive year, with more than 191,000 complaints filed. Business email compromise — fraud in which an attacker poses as a trusted executive, supplier, or colleague to redirect payments or access — accounted for $3.046 billion in reported losses in 2025 across 24,768 tracked incidents. These are directly reported complaint and loss totals; a per-incident average of approximately $123,000 is a figure calculated from those totals, not a number directly reported by the FBI.
The pattern behind these numbers is consistent. Verizon’s 2025 Data Breach Investigations Report found that the human element was involved in 60% of breaches, and that creating a false story to manipulate someone into taking an action — a tactic known as pretexting — overtook phishing as the most common manipulation-based attack for the first time. Impersonation is not peripheral to modern breach activity. It is central to it.
AI Has Changed the Economics of Deception
Generative AI has removed the skill barrier that once limited high-quality impersonation to sophisticated and well-resourced attackers. Targeted, convincing content that previously took hours to develop and produce can now be generated in minutes. Messages can be personalized to a specific person’s role, relationships, and communication style. Rewriting tools eliminate the awkward phrasing that awareness training traditionally teaches employees to spot.
CrowdStrike’s 2026 Threat Hunting Report shows that voice phishing — attacks conducted by fraudulent phone call to pressure someone into sharing information or taking an access-related action — increased 134% from 2024 to 2025, and the first half of 2026 has already matched the volume recorded in the entire second half of 2025. The threat is not just prevalent. It is still accelerating. An attacker does not need a sophisticated setup: AI tools can produce a convincing voice clone from a short audio sample scraped from a public recording.
Video has introduced similar risks to visual verification. iProov’s 2026 Threat Intelligence Report, drawn from real-world data across iProov’s global security operations, found that AI-generated attacks targeting iOS devices surged 741% in 2025 alone, and that deepfake impersonation has expanded beyond identity verification systems into everyday corporate video calls and workflows. The Ponemon Institute found that 41% of organizations have already experienced deepfake attacks targeting executives. Seeing someone on a video call is no longer reliable proof that the person is who they appear to be.
Mobile devices amplify the problem further. Zimperium’s 2026 Global Mobile Threat Report found that mobile phishing events detected on employee devices grew 380% since January 2025, and that the number of devices where employees clicked a malicious link grew 110% in 2025 compared to the prior year. Text messages reach employees outside managed inboxes, on smaller screens where differences in sender addresses are harder to notice, in environments where security cues are limited.
Every Channel Is Now an Impersonation Channel
The channel no longer defines the attack. The false identity does. A credible email can establish context. A text message can create urgency. A voice call can push toward action. A video can provide false reassurance. A message in a workplace collaboration tool can appear to come from an internal colleague or IT support representative. An impersonation campaign can move across channels, using each interaction to build the trust needed to trigger an authentication event.
Microsoft documented a 2026 campaign in which an attacker impersonated IT support through persistent voice phishing in a collaboration environment, targeting multiple employees across a sustained period. The campaign illustrates the shift: the support workflow itself becomes the lure when an attacker can convincingly play the role of the people employees expect to trust.
Verizon’s 2026 Data Breach Investigations Report found that mobile-centric attacks involving fake texts and voice calls achieved a success rate 40% higher than traditional email phishing — a directly reported finding. Security programs cannot treat email filtering as the primary boundary between employees and impersonation. Any channel employees use to communicate and verify identity is a channel attackers will use to deceive.
Why Traditional Defenses Are Falling Behind
Email filtering can block known malicious infrastructure and suspicious attachments, but it has little to work with when a message is well written, contextually accurate, sent from a compromised legitimate account, or followed up by a voice call. Caller verification helps only when the directory and device used for verification are trustworthy — which cannot be assumed when caller identity can be faked. Video confirmation is no longer a reliable trust signal when video can be synthesized in real time.
Awareness training is necessary but cannot carry the full weight of defense. Asking employees to serve as the final detection layer against real-time AI voice cloning and AI-generated video in a high-pressure executive impersonation scenario sets up an unreliable defense. CrowdStrike’s 2026 Threat Hunting Report found that 79% of attacks to gain initial access were carried out without using malicious software — relying instead on manipulating people and abusing valid access.
The structural problem is that password-based authentication gives a successful impersonation attempt a transferable prize. A password can be revealed in a phone call, entered into a login page while the attacker watches, or surrendered under pressure. Once obtained, it can be reused, used to initiate account recovery, or combined with further manipulation to bypass additional controls. Controls built on recognition — seeing, hearing, or reading something that seems familiar — increasingly confuse familiarity with assurance.
How Photolok by Netlok Changes the Payoff
Photolok by Netlok operates at the identity layer and integrates with platforms such as Okta Workforce. It replaces password-based credentials specifically — it does not claim to eliminate every form of credential or every security risk. Its value in an impersonation scenario is direct: when there is no password for an employee to disclose or enter after being deceived, the attacker’s ability to convert a convincing interaction into account access is materially constrained.
Photo-based authentication. Users identify images from a photo panel rather than entering a password. What makes this more than a visual password is what happens behind the scenes: each photo carries an encrypted code that changes with every login, is tied to the user’s registered device, and requires a server-side access code to validate. Even if an attacker captures or steals the photos, they cannot use them — the encryption and device binding lock them out. An attacker cannot walk away from a convincing phone call or a login page with a reusable password, because there is no password to capture.
1 Time Photo. Users can configure up to five single-use photos for authentication. Once used, that photo is no longer available. Even if an attacker intercepts a login or records a session, the encrypted codes tied to that photo have already expired — there is nothing to capture that can be reused to break in again. This directly addresses the problem that makes stolen credentials so valuable: a credential that cannot be reused has no value once captured.
Duress Photo. Users can configure up to two Duress Photos, randomly selected for display during login. If an employee is pressured or tricked into authenticating by someone impersonating a colleague, executive, or IT staff member, selecting a Duress Photo triggers a real-time alert to security teams the moment it is chosen. The security operations center receives a real-time distress signal while the person doing the coercing sees a normal login. This matters because the employee may not always be in a position to safely challenge or refuse the person on the other end of the call, meeting, or message. Security architecture should account for that reality — and this is a capability that passwords, passkeys, and biometrics do not provide.
For CISOs, the strategic shift is this: stop asking whether every employee can detect every convincing impersonation, and start asking what an attacker obtains when one gets through. If the answer is a reusable password, the architecture still rewards deception. Photolok removes that reward.
The Bottom Line
AI has industrialized impersonation. It has made fraudulent requests sound more natural, arrive through more channels, and adapt faster than static controls can track. The prevalence data now reflects that reality: the majority of large organizations encounter executive impersonation, phishing and fraud are the most reported cybercrime category, and $3 billion in losses flow through business email compromise every year.
The answer is not to assume every impersonation can be detected before an employee encounters it. It is to ensure a convincing impersonation cannot be converted into access. Photolok removes passwords from the identity layer, replacing them with a credential type that cannot be handed over in a phone call, entered into a fraudulent login page, or captured and reused — and gives security teams a real-time signal when someone is authenticating under duress.
Deepfakes don’t need your password. But as long as passwords exist, they are one convincing phone call away from being handed over.
Request Your Personalized Demo
About the Author
Kasey Cromer is Director of Customer Experience at Netlok.
Sources
[1] Outtake. ‘2026 State of Digital Risk Report.’ June 2026. outtake.ai
[2] Outtake. ‘2026 State of Executive Impersonation.’ July 2026. outtake.ai
[3] World Economic Forum. ‘Global Cybersecurity Outlook 2026.’ January 2026. weforum.org
[4] Anti-Phishing Working Group. ‘Phishing Activity Trends Report Q1 2026.’ May 2026. apwg.org
[5] FBI Internet Crime Complaint Center. ‘2025 Internet Crime Report.’ 2026. ic3.gov
[6] Verizon. ‘2025 Data Breach Investigations Report.’ May 2025. verizon.com/business/resources/reports/dbir
[7] Verizon. ‘2026 Data Breach Investigations Report.’ May 2026. verizon.com/business/resources/reports/dbir
[8] CrowdStrike. ‘2026 Threat Hunting Report.’ August 2026. crowdstrike.com
[9] iProov. ‘Threat Intelligence Report 2026.’ April 2026. iproov.com
[10] Ponemon Institute. ‘Deepfake Attacks Targeting Executives.’ 2026. ponemon.org
[11] Zimperium. ‘2026 Global Mobile Threat Report.’ July 2026. zimperium.com
[12] Microsoft. ‘Help on the line: How a Microsoft Teams support call led to compromise.’ March 2026. microsoft.com
[13] Netlok. ‘How Photolok Works.’ netlok.com
Deepfakes Don’t Need Your Password. Your Employees Will Hand It Over.
Kasey Cromer, Netlok | August 24, 2026 Executive Summary Targeted impersonation is no longer[...more]
Does a non-human own your ID?
Kasey Cromer, Netlok | August 4, 2026 Executive Summary For years, enterprise security p[...more]
Critical Infrastructure Isn’t Breached. It’s Logged Into.
Kasey Cromer, Netlok | July 15, 2026 Executive Summary In 2026, the most consequential cyberattac[...more]
AI-Powered Phishing and the Speed of Attack
Kasey Cromer, Netlok | June 16, 2026 Executive Summary In 2026, phishing is no longer a numbers game[...more]
Helpdesk is the Easiest Breach in Your Organization
Kasey Cromer, Netlok | June 9, 2026 Executive Summary In 2026, the most dangerous entry point in you[...more]
Leaner Teams, Smarter Logins: Why Eliminating Passwords Is the Right Move for 2026
Kasey Cromer, Netlok | May 27, 2026 Executive Summary In 2026, security leaders are being asked to d[...more]
When anyone can be faked: Photolok as the identity layer for the AI era
Kasey Cromer, Netlok | May 13, 2026 Executive summary As we move through 2026, the corporate world i[...more]
App Overload: Why SaaS apps and AI Sprawl Are Breaking Enterprise Security
Kasey Cromer, Netlok | April 29, 2026 Executive summary In 2026, most enterprises are running more a[...more]
Identity Crisis: When Attackers Log In Instead of Break In
Kasey Cromer, Netlok | April 10, 2026 Executive Summary Geopolitical escalation reliably coincides w[...more]