Deepfake fraud, sophisticated social engineering, and hiring scams are set to explode this year, according to a new report from Nametag, which argues that traditional approaches to identity security are leaving gaps for attackers to slip in.
The fraud prevention firm’s 2026 Workforce Impersonation Report warns that genAI has now blurred the line between real identities and machine-made clones, with bad actors routinely combining text-based tools like ChatGPT with next-gen video generators like Sora 2 that can convincingly impersonate “dynamic, living scenarios”.
Investigating the trends set to define identity security over the coming year, Nametag predicts that criminal groups will begin to extend their Deepfake-as-a-Service (DaaS) offerings, with new kits including the latest deepfake injection capabilities, allowing less advanced crooks access to bigger payouts.
There is already evidence that scammers are building skill in this area, with an unnamed Singaporean business narrowly avoiding a half-million-dollar loss to fraudsters impersonating their CEO last year, though that pales in comparison to the £20 million lost by UK engineering outfit Arup in a deepfake incident back in 2024.
Industry figures show that DaaS was one of the fastest-growing tools used by cybercriminals in 2025, with AI-powered deepfakes involved in over 30% of high-impact corporate impersonation attacks, with voice cloning fraud alone rising 680% in the past year.
According to Nametag, 2026 will be the moment when consumer-grade identity verification proves unable to detect these injected deepfakes, forcing enterprises away from visual checks and AI detection systems and towards continuous, hardware-based identity verification.
The same pattern holds for other identity attack vectors, with AI fast becoming the root of every emerging evil. Helpdesk social engineering attacks like those perfected by Scattered Spider, for instance, are expected to ramp up their use of deepfakes and genAI, as are criminals leaning on AI-personalisation for spear phishing attacks.
Worryingly, these tactics have already been combined by bad actors in the wild. In August 2025, Group‑IB uncovered a sophisticated vishing campaign in which attackers impersonated recruiters from major tech firms, using deepfaked voice calls to follow up on phishing emails, with fewer than 5% of funds lost to such sophisticated scams ever recovered.
Nametag’s report also cautions firms to be wary of identities added to systems in-house. Last year, AI agents quickly became a first-class identity in their own right, having access and autonomy over tools and applications at levels similar to some human employees.
For security teams, this is a serious new threat. Security researchers from Unit 42 have already demonstrated that adversaries can use indirect prompt injection to “silently poison” the long-term memory of an AI agent, inserting malicious instructions across future sessions without further human interaction.
Recommended reading
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
- Is It Now Practically Impossible To Identify Deepfakes?
- Report: More Than 50% of Fraud Is Now Driven by AI
Nametag said that this year, these challenges will see agentic identity governance become a board‑level and compliance priority, much like supply chain or insider risk management, with Identity and Access Management (IAM) providers expanding their platforms to manage both human and machine identities under one umbrella.
“Traditional approaches to identity security that authenticate devices and credentials, but not actual people, leave a widening identity assurance gap that adversaries are actively exploiting,” concludes the report.
“Closing that gap will require a fundamental shift in how organisations think about workforce identity. Organisations that adapt will make the shift from periodic identity check to continuous identity assurance, embedding workforce identity verification into the places where trust matters most.”





