In 2024, cybercriminals launched over 105,000 deep fur cake attacks. That's the same One every 5 minutes. Cybercriminals no longer treat deepfake audio and video as novelties. They use them to commit fraud, steal data and disrupt companies. The risks become even more severe in manufacturing, where teams rely heavily on remote coordination and supply chain trusts.
Massive deception
Verizon's 2025 Data Breach Investigation Report (DBIR) It reveals that social engineering accounts for 22% of manufacturing violations. Phishing alone was caused by 19% of violations. This means that attackers do not need to hack their systems or exploit software vulnerabilities to cause serious damage. They simply need to deceive humans.
Generating AI is at your fingertips, they do exactly what's massive, refined and refined.
Genetic AI overcharged these deception tactics and provided attackers with new tools to manipulate awareness and abuse trust in ways traditional phishing never could have done, including the use of deepfakes.
Deepfake is an extreme synthetic media that allows attackers to create using deep learning to bring eerie accuracy to executives, vendors, or partners. The CEO's voicemail or the face of a supply chain manager on a video call can be sufficient to override internal skepticism and cause expensive behavior.
Multi-faceted threats to manufacturing operations
an analysis Deepmind, a public case of nearly 200 people of Google's generation AI misuse, has identified two major threat categories: Exploitation of generated AI capabilities (spoofing or creating fake video calls) and compromise of generated AI systems with Jaybreaked or hostile prompts. In real-world attacks targeting businesses, most cases are attributed to exploitation, often using widely available consumer-level tools.
One such case involved employees at a multinational company in Hong Kong. Cybercriminals tricked them into transferring what was worth $25.6 million in depth video conferencing. All individuals, including those who appear to be the company's chief financial officer, were computer-generated con artists. As Hong Kong police reported, “everyone he saw was fake.”
In another example, bank employees wired $35 million after receiving an audio call that mimics a senior executive using AI-generated speeches.
Manufacturing relies on constant communication between teams, partners and time zones. Email, video calling and messaging platforms keep the global supply chain running, but offer many opportunities for attackers to pose as trustworthy contacts. That, coupled with the fact that the manufacturing digital footprint continues to grow, makes the sector particularly vulnerable to deepfakes, especially among smaller organizations.
Verizon's DBIR shows that over 90% of manufacturing organizations affected by the violation have fewer than 1,000 employees. Many of these companies operate with small IT teams, limited budgets and limited access to modern security tools.
Deepfark-led fight against cybercrime
There is no single solution to the Deepfark dilemma, but manufacturers can take important steps to prevent this new threat.
Start by adopting the zero trust mindset: “Never trust, always check.” Scrutinize all requests, including financial transactions, production changes, and access to credentials, even if you think you're coming from a trusted contact. If you find the request unusual, check it through another channel before performing the action.
Employee education is another important defense. Google Deepmind's research highlights the value of “Pre-Bunking” and actively shows how bad actors create deepfakes and what kind of red flags they are looking for, including unnatural facial movements, inconsistent lighting, and mismatches in voice lip syncing. Raising awareness helps teams resist manipulation, especially under pressure.
Email is the main entry point for these attacks. According to Barracuda 2025 Email Threat Reportone in four email messages is malicious or unwanted spam, with 20% of companies experiencing at least one account acquisition incident per month.
Once inside, the attacker can impersonate a trusted individual and launch a highly targeted spear phishing or business email compromise (BEC) attack. Meanwhile, almost half of all businesses lack a well-configured DMARC policy, with 77% not actively preventing spoofed emails, leaving their doors wide open. As these tactics become more persuasive, traditional email security becomes insufficient on its own.
Manufacturing organizations should also limit the amount of executive video and audio content published online. Many deepfakes use public footage, such as revenue calls, interviews, and promotional content. Reducing that digital footprint makes it difficult for attackers to construct compelling spoofs.
A layered security approach is essential. This includes email security, identity and access management, communication validation protocols, and behavior-based monitoring tools. Most deepfake-based attacks are part of a fake contract, fake scenario, or a broader campaign that combines insider reconnaissance and spoofed communication.
Finally, manufacturers need to enhance their incident response playbooks. When a deepfake is discovered or suspected, prompt action can minimize financial losses and reputational damage. Research shows that most reputation fallouts occur within the first 24 hours of an incident.
Building digital trusts in the age of synthetic deception
Synthetic media is not inherently harmful. Widely used in engineering, training, marketing and simulation. However, deepfakes used for fraud, impersonation, or fear tor represent a rapidly growing threat to global manufacturing.
Tools powered by generative AI allow cybercriminals to make phishing and spoofing attempts much more convincing and easier to carry out. All you need to do with technical skills once is to take the right tools and some stolen clips. To remain resilient, manufacturers need to rethink their ways of defining and defending trust and realize that the next attack can come through familiar faces on the screen, not through code.
Adam Khan is the VP of Global Security Operations for Barracuda MSP.
