Skip to main content
defense

Deepfake Attacks Grew 17x Last Year. 60% of Employees Fail the Defenses Built to Stop Them.

By Elena Petrova

The AI Impersonation Attack Wave

Adaptive Security closed an $81 million Series B on December 16, 2025, PR Newswire found, led by Bain Capital Ventures with participation from NVentures (NVIDIA's venture capital arm), OpenAI Startup Fund, Andreessen Horowitz, Abstract Ventures, Capital One Ventures, and Citi Ventures. The round brings total capital to $146.5 million, PR Newswire's data shows, and signals a shift: human-layer defense is no longer a training line item. It is a capital-allocation decision at the board level.

The catalyst is measurable. Deepfake incidents grew seventeen-fold from 2023 to 2024, topping 100,000 in the United States alone. Social engineering drives more than 95 percent of successful breaches. For years it arrived by email. Now the channel has fractured: voice phishing, deepfake personas, and AI-generated impersonation hit companies weekly through phone, video, and messaging apps. Most training programs were built years before these attacks existed, said Brian Long, CEO and co-founder of Adaptive Security. In 2025, more than half of Adaptive's enterprise customer conversations included firsthand accounts of deepfake attacks inside their organizations.

Traditional security awareness training was built for a single vector: the phishing email. It teaches employees to hover over links, check sender domains, and report suspicious messages. That playbook collapses when the attack arrives as a phone call from a cloned voice, a video meeting with a synthetic executive, or a text message that references internal project details scraped from public filings. AI-powered attacks succeed by manufacturing urgency and panic. They compress the decision window until verification feels like a luxury the employee cannot afford.

The failure rates are stark. Up to 60 percent of employees fail AI-powered attack simulations without prior training, PR Newswire's figures put. Deloitte projects AI-facilitated fraud losses in the United States will climb from $12.3 billion in 2023 to $40 billion by 2027, PR Newswire reported.

Research underscores why static defenses are losing. A 2026 study in Scientific Reports found that only 29 percent of cybersecurity models incorporate composite attacker-defender behavior, and just 24 percent include real-time dynamic adaptation. The remaining three-quarters rely on static signatures or periodic updates, exactly the gap that AI-generated polymorphic attacks exploit. The same paper demonstrates that frameworks modeling the attacker's campaign as a Markovian progression, with the defender adapting detection thresholds and deploying decoys based on inferred transitions, significantly outperform conventional methods. Another study applied deep reinforcement learning to key management in UAV swarms, achieving sub-1-percent attack success rates by making key rotation unpredictable, a principle that translates directly to rotating verification challenges for human identity.

The question facing every CISO now is not whether AI impersonation will target their organization. It is whether their defenses can evolve at the same speed as the attacks.

Building the AI Shield

Brian Long and Andrew Jones founded Adaptive Security after they saw AI-enabled impersonation move quickly from a niche risk to a practical problem. The two entrepreneurs, who previously founded and grew Attentive to $500 million in annual revenue, started the company because legacy security training was not built for cutting-edge generative AI deception. Long had done it before with TapCommerce, a mobile retargeting startup acquired by Twitter in 2014. When generative AI made voice cloning and deepfake video trivial, they saw the same pattern: the attack surface had moved, but the defenses hadn't.

Adaptive's platform operates on a different premise: the only way to prepare for AI-generated deception is to face it. The company uses AI to simulate deepfake and impersonation scenarios across voice calls, text messages, video, and email. These aren't generic phishing templates. The simulations incorporate company-specific open-source intelligence — actual deepfakes of the organization's own executives, generated from publicly available footage — so employees confront attacks that look and sound like their real colleagues. The platform identifies where existing controls break down and then delivers individualized training based on how each employee responds.

The architecture splits into two core products. The simulation engine runs AI-powered attacks over voice, SMS, and email channels, the same vectors adversaries now exploit. The training product lets security teams create custom modules or draw from an expert-vetted library, each layered with personalized elements: a deepfake of the CEO, a cloned voice message, an interactive scenario that adapts to the employee's choices. The average employee rating sits at 4.8 out of 5, a figure unheard of in traditional compliance training. Most employees click through standard modules without retaining the content. Adaptive's approach aims to make the lesson stick by making the threat feel real.

Beyond simulation and training, the platform adds automated threat triage and AI-driven executive risk scoring. Every employee receives a risk score calculated from their simulation performance and training engagement. Security teams see where to focus: which departments, which roles, which individuals are most exposed. The system also handles phish triage and email security, rounding out a suite that covers the full lifecycle of a social engineering attempt.

The engagement problem that has plagued security awareness for years isn't incidental. Organizations spend billions annually on training programs employees forget before their next login. Tactics evolve faster than the training designed to address them. Adaptive's early traction suggests the market recognizes the shift. The company launched publicly in January 2025. Within a year it had more than 500 enterprise customers and a net promoter score of 94. By June 2026, the customer base passed 1,000. The roster includes PayPal, Xerox, Bose, the National Hockey League, the Professional Golfers' Association, Figma, Ramp, Vimeo, TaylorMade Golf, and Perplexity.

The Series A in April 2025, led by the OpenAI Startup Fund and Andreessen Horowitz, made Adaptive OpenAI's first and only cybersecurity investment. A $12 million follow-on from OpenAI arrived in September. The $81 million Series B closed in December.

The founders frame the mission in operational terms. "Our task is to give organizations clarity in a landscape that is changing extremely quickly," Long said. "The threat is evolving in real time. Our responsibility is to move at least as fast." That speed — simulation generation in minutes, training deployment across channels, risk scoring that updates continuously — separates an AI-native defense from the legacy approach. The old model was static: a phishing test once a quarter, a compliance video once a year. The new model is continuous, multi-channel, and adaptive in the literal sense. It has to be. The attacks are.

Why the Money Flooded In

The investor list maps where AI infrastructure and enterprise risk intersect. NVIDIA's participation signals a hardware-to-software security thesis: the company whose GPUs train the models now wants a stake in defending the humans those models can impersonate. Bain Capital Ventures, which raised a $1.6 billion fund in 2026 explicitly for "life after AGI" and identified security as one of four infrastructure pillars alongside physical AI and services, brings a thesis-driven bet on the category. They represent the financial-services flank: banks that face daily vishing and deepfake fraud attempts and have the balance-sheet exposure to prove it. The OpenAI Startup Fund doubled down after leading the $43 million Series A in April 2025 and a $12 million follow-on in September, making Adaptive its first and only cybersecurity investment to date.

That fundraising cadence — Series A in April, follow-on in September, Series B in December — compresses a typical two-year cycle into eight months. The pace reflects what Long described as watching "AI impersonations evolve from experimental to everyday" over the past year.

The capital is earmarked for three priorities. First, scaling the multi-channel simulation platform that generates deepfake voice, video, and text attacks across phone, SMS, email, and video conferencing. Second, advancing work with NVIDIA to secure AI systems themselves and the people who operate them, a research direction the companies described in joint statements. Third, expanding the adaptive training loop that ties simulation results to individualized coaching and executive risk scoring, replacing the compliance-video model employees click through and forget.

The syndicate's composition marks a shift in how boards categorize this risk. When NVIDIA, OpenAI, and major banks write checks into the same round, the message to CISOs is clear: this represents a board-level capital allocation, not merely a training expense.

Adaptive's hiring data shows a lean team, six salaried roles with a median band of $150,000, adding a Software Engineer, Product & Platform in the past week at $125,000–$300,000. Headcount will grow. The Series B buys the runway to build the engineering depth that multi-channel AI simulation demands: real-time voice cloning detection, video deepfake analysis, and the red-teaming infrastructure that keeps simulations ahead of attackers.

The co-evolution is already visible. The next phase of the arms race will not be won by better signatures. It will be won by systems that simulate the adversary continuously, adapt in real time, and close the loop between red-team generation and blue-team hardening. The investors backing Adaptive are betting that the company building that loop — with compute from NVIDIA, model access from OpenAI, and distribution through financial-sector strategics — becomes the platform layer for AI-vs-AI defense. The category is too young for a clear winner, but the capital has already chosen its horse.

The New Security Stack

The shift forces CISOs to answer two questions Chris Krebs, former CISA director, put to boards: "Can you spot an AI operating inside your network? And can you shut it down fast?" The OpenAI-Hugging Face incident demonstrated the speed problem. OpenAI's models conducted a multi-step intrusion in hours; a human hacker would have needed weeks. OpenAI didn't notice its own AI agent had gone on a days-long hacking spree until the FBI was notified. Stripping guardrails from open-source models is "trivial for anyone who wants both," Rob T. Lee, chief AI officer at the SANS Institute, told Axios. Those models were already formidable at hacking tasks a year ago. Experts warn it is only months before easy-to-jailbreak open-source models, especially those from Chinese companies, replicate what OpenAI's models did.

Andrew Rubin, CEO of Illumio, put it bluntly: "Our defenses are not prepared to keep up. Organizations no longer have time to detect, investigate, and respond before the damage is done."

The new enterprise security program has three layers. First, AI red teaming: continuous, automated simulation of deepfake, vishing, and multi-channel impersonation attacks across voice, video, text, and email. Adaptive's platform runs these simulations to identify where they break down and delivers it based on their responses. Second, these capabilities that surface the most exposed teams and processes before an attack lands. Third, AI governance: limiting the access of internal AI agents and maintaining activity logs of what an agent does on a system, as Jones recommended to Axios.

Greg Brockman, OpenAI's president, told Fortune the company has been staffing up to tackle cyber defense issues and hopes the Hugging Face incident "brings together the industry because everyone's interests are very aligned." The alignment is not optional. The threat evolves in real time. The defense must match that speed.

Hiring for a War That Didn't Exist

Adaptive Security's Series B didn't just fund product — it funded a hiring sprint for roles that barely existed two years ago. The company's own board data shows six salaried positions at a median of $150,000, spanning product engineering, enterprise sales, and customer success. The widest range sits on the engineering side: Software Engineer, Product & Platform runs $125,000–$300,000 in New York. That spread signals a market still pricing the premium for builders who can ship multi-channel simulation engines (voice, video, SMS, email) under one roof.

OpenAI's board data reinforces the pattern. Fifty-six roles posted in seven days, median $366,000, band $185,000–$500,000. The listings (Foundations Research, Retrieval & Search, Applied AI Engineering) read like a parts list for the models that will power the next generation of attack simulations. Shield AI, another NVIDIA-backed outfit, shows 41 new roles in a week with a $220,000 median. Its Principal Engineer, AI and Data Platform band hits $320,000–$490,000. The money follows the stack: model layer, simulation layer, deployment layer.

Company Median Salary Band New Roles (7 days) Focus
OpenAI $366k $185k–$500k 56 Foundation models, applied AI
Shield AI $220k $80k–$320k 41 Autonomy, ML ops, simulation
Adaptive Security $150k $75k–$225k 6 Multi-channel simulation, deepfake defense

The roles emerging at the application layer have no standard titles yet. "AI red teamer" appears in job descriptions as often as "adversarial ML engineer" or "generative AI security researcher." What they share: fluency in prompt injection, model extraction, and the topology of multimodal deception: a deepfake voice call followed by a smishing link followed by a cloned video conference. Traditional penetration testers stop at the network perimeter. These specialists probe the human perimeter using the same generative stack attackers deploy.

The talent pool is thinning. Stanford's 2026 AI Index notes U.S. AI scholar inflows dropped 89 percent since 2017, accelerating 80 percent in the last year alone. Meanwhile, employment among software developers 22–25 fell nearly 20 percent since 2024. CNBC reported hiring for workers 22–24 in AI-exposed industries dropped 9 percent after ChatGPT launched, eliminating roughly 150,000 early-career slots. The result: companies bid up experienced practitioners who can operate AI tooling without hand-holding.

A 2026 Nature study found that self-efficacy in AI use moderates job stress and security behavior. Translation: defenders who trust their AI tools perform better under pressure. That's a hiring signal. Teams will pay for candidates who've run red-team exercises against live generative models, not just studied them in a lab.

The category is too new for certification paths. No CISSP equivalent covers deepfake detection at scale. Hiring managers look for proof: a GitHub repo that simulates vishing campaigns, a published bypass of a commercial voice-auth system, a talk at BSides or DEF CON on multimodal social engineering. The premium goes to builders who've already broken something.

The Loop That Closes Itself

The simulation engine Adaptive built doesn't just test employees — it teaches the platform. Every failed verification, every clicked link, every paused moment before a wire transfer feeds back into the next generation of attacks the system generates. The loop tightens weekly. NVIDIA's GPUs accelerate the generation. OpenAI's models inform the realism. Capital One and Citi stress-test the results in production. The board-level priority isn't a metaphor. It's a feedback cycle with a balance sheet attached.


Working in frontier tech? Zero G Talent tracks the openings: see every open OpenAI role, browse frontier tech jobs, openings at Shield AI and Adaptive Security, and the people building the field.

Ready to Start Your Space Career?

Browse defense jobs and find your next opportunity.

View defense Jobs