Guest Post: Dark web analysis: Deepfakes as a service discussions soar by 39%

Findings from the dark web reveal that discussions surrounding deepfakes as a service have exploded in 2026, already surpassing 2025’s totals and potentially paving the way for a new wave of business email compromise attacks

The latest findings from NordStellar, a threat exposure management platform, reveal that dark web discussions surrounding cybercrime as a service are trending upward in 2026. Deepfakes as a service is proving especially popular, with posts surging 39% in the first five months of 2026 — already surpassing the total volume recorded in 2025 and potentially giving cybercriminals new tools for “fake boss” scams.

According to data analyzed by NordStellar, 9,234 dark web posts discussed cybercrime as a service (CaaS) in 2025. Between January and May 2026 alone, that number has already reached 6,866 — representing 74% of last year’s total.

The analysis reveals that discussions about deepfakes as a service (DFaaS) are growing the fastest. In just the first five months of 2026, there were 924 posts — marking a 39% increase compared to the 663 posts recorded for all of 2025.

“The rapid growth in popularity of deepfakes as a service is likely accelerated by advancements in generative AI, which help cybercriminals in two ways — by speeding up the creation of deepfakes and making them hyper-realistic,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ultimately, this service lowers the barrier to entry for deepfake technology, enabling threat actors to deploy highly deceptive attacks at a larger scale, regardless of their personal technical skill set.”

Deepfakes for business email compromise attacks

Noreika highlights that the growing popularity of DFaaS is a key concern for businesses. Cybercriminals can leverage deepfakes not only to target individuals with sophisticated social engineering but also to amplify business email compromise (BEC), otherwise commonly known as “fake boss” scams. In these attacks, bad actors impersonate vendors, colleagues, or executives to manipulate employees.

The FBI reports that business email compromise was the second costliest cybercrime of 2025, with company losses exceeding $3 billion. This marks an 11% increase over $2.7 billion reported in 2024.

The real-life case covered by the World Economic Forum involving engineering firm Arup highlights the stakes: An employee was tricked into transferring $25 million after attending a video call where all other participants were AI-generated deepfakes.

“Deepfakes can be used to elevate business email compromise attacks to make them even harder to spot — instead of receiving fake payment instructions in an email, employees can now be targeted via highly realistic video and voice calls impersonating partners or managers asking them to transfer funds,” says Noreika. “As AI tools grow more sophisticated, deepfakes are evolving rapidly. It is now easier than ever to create convincing video or audio that lacks the usual telltale signs of AI generation, making it extremely challenging for users to spot the deception — especially when a sense of urgency is involved.”

He explains that cybercriminals usually deploy these attacks to obtain fake payments or confidential documents or to infiltrate the company’s network to launch a larger-scale attack. Advanced BEC attacks usually involve gathering extensive intel on the target to ensure that the attack itself contains convincing details, is context-appropriate, and is delivered at the right time — for example, when the recipient is already waiting for an incoming invoice.

Deepfake defense strategies in the era of AI

Noreika suggests that a deepfake-resistant cybersecurity strategy should focus on two main areas — prevention and employee education. While companies can’t control whether cybercriminals target them, robust security measures can make advanced BEC attacks much harder to execute.

“The more details and access attackers obtain, the easier it is for them to craft highly realistic, targeted attacks,” says Noreika. “Monitoring the dark web for leaked company information is a critical step in preventing cybercriminals from finding credentials to breach accounts or data to use as intel.”

He emphasizes that educating employees on BEC attacks is vital. However, he notes that fostering a positive cybersecurity culture is equally important.

“Attackers take advantage of their targets by creating a sense of urgency,” says Noreika. “Even if employees are aware of cybercriminals’ tactics, slowing down to double-check a request that’s coming from a person of authority can be daunting to most, especially if deadlines are tight. Efficiency shouldn’t come at the expense of possibly exposing the company to a cyberattack, and employees should feel safe and empowered to raise red flags when something is off, and take some time to inspect the request before diving headlong.”

Noreika stresses that having a robust cybersecurity strategy in place will help mitigate the aftermath of a BEC attack if threat actors succeed in tricking employees and gain access to the company’s network. He notes that security measures like network segmentation and multi-factor authentication can help prevent attackers from moving laterally inside the network as well as prevent them from accessing resources.

Methodology: The NordStellar platform was used to analyze underground discussions from dark web forums and monitored Telegram channels. NordStellar tracked 6 categories covering as-a-service offerings. For each category, NordStellar retrieved monthly post counts across both forums and Telegram for every month from January 2024 through May 2026. For more information, visit NordStellar’s blog post.

Disclaimer. This analysis is based on detected activity and is for informational purposes only; it does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading