Nearly one in four (24%) British employees under 35 would act on a suspicious message if they believed it came from a colleague or senior leader, highlighting a growing workplace risk as cyber-criminals use AI and deepfakes to impersonate trusted contacts, new Accenture research finds.
A survey of over 1,000 British employees found that 15% would share company data or make payments via messaging apps, without verifying the sender, if the message seemed to come from a leader or colleague. This rose to 24% of under-35s, suggesting that Millennial and Gen Z employees who use consumer messaging apps, like WhatsApp, to contact colleagues could be vulnerable to scams.
This vulnerability persists despite widespread cyber confidence: four in five employees (81%) believe they could spot a phishing attempt or AI-driven cyber-attack at work. Men were nearly twice as likely as women to say they were very confident in doing so (22% vs 12%). While cyber confidence is high, it did not translate into greater caution or change in workplace behaviour.
These findings will likely stoke organisational concerns: Accenture’s latest State of Cyber Resilience report found 56% of UK businesses are already worried about cyber threats driven by the accessibility of AI, and 23% rank deepfakes among their top concerns.
Despite concerns, a major preparedness gap remains. More than a third of UK workers (37%) have never received cybersecurity training, including 44% of over-55s.
Only one in five employees (20%) have been trained to recognise deepfakes or AI-generated phishing emails. The shortfall in training is more significant in smaller companies, where 79% of microbusinesses (less than 10 employees) and 55% of small firms (10-49 employees) offer no cybersecurity training at all.
These findings could prompt growing concerns about AI-powered cyber risks among smaller vendors in the supply chain.
“Recent cyber-attacks prove no organisation is untouchable, and these results show a growing threat from AI-driven social engineering where attackers target trust instead of technical flaws,” Kamran Ikram, Accenture’s Security lead in the UK & Ireland, said.
“With cyber-criminals weaponising information from social media to deceive people with realistic messages or calls, employees must make faster judgement calls on what’s real and what’s not. The workforce feels cyber confident – though its uneven among men and women – there remains a serious skills and training gap across the board.
“Being overconfident yet undertrained is a dangerous position to be in. Organisations must look to be resilient in every area of their operations and supply chain, which means ongoing education on cyber threats. Businesses can’t rely on patchy preparedness when attackers are advancing by the day.”
Recommended reading
- The Future of Cybersecurity May Look More Physical Than Digital
- Report: Cyber Breaches Are Tanking Share Prices
- Cyber-crime Costs to Hit $1.2tn in 2025, New Report Warns
AI training divide
As companies introduce more AI at work, guidance on using it responsibly is not keeping pace. Half of employees in companies that provide cyber training (50%) have received no guidance on using AI safely – such as what data should not be shared with public tools or how to identify AI-enabled attacks.
This lack of training is reflected in employees’ awareness of attacks: one in five (17%) have no awareness of AI-driven cyber threats. Deepfake videos (61%) and AI-generated phishing emails (61%) are the best-known threats, followed by voice cloning (47%) and identity theft (45%).
Despite the risks, employees have a sense of collective responsibility. While a quarter (25%) of British employees believe that the IT/security department is most responsible for protecting a company against cyber threats, more than half (53%) accept that it is a joint responsibility across the organisation.
Ikram added, “AI is bringing immense opportunity to business, but it also is changing the risk landscape as criminals increasingly incorporate AI into their arsenal.
“Today, awareness of AI-enabled attacks is still uneven, and that gap is where the next wave of breaches will likely happen. But more than that – building a cyber-savvy workforce isn’t just about protecting your systems, it’s also what allows innovation and trust to scale together.”





