The 'synthetic insider': AI deepfakes posing as fraudulent employees

The 'synthetic insider': AI deepfakes posing as fraudulent employees

      The most perilous individual in your organization may not even be an employee. AI deepfakes are becoming increasingly affordable and sophisticated. Hackers are now utilizing them to impersonate trusted personnel, which the industry refers to as the “synthetic insider.”

      This method highlights a long-standing issue. Insider threats can range from an employee mistakenly sending the wrong document to a criminal who knows exactly where the assets are located. According to a 2026 analysis of approximately 22,000 incidents by Verizon, 12% involved internal actors, as reported by the Financial Times.

      The intentional threats cause the greatest harm. “They are aware of where the crucial assets are and how to access them,” stated Alex Lisle, chief technology officer at the deepfake-detection company Reality Defender.

      The impersonated employee

      A prominent example is a North Korean operation that the US Justice Department targeted last year. Operatives fraudulently obtained remote jobs at American companies. Their aim was to earn salaries and gather information for the sanctioned regime.

      They used the stolen identities of over 80 Americans to gain employment at more than 100 firms, according to government reports. This scheme generated over $5 million for Pyongyang. Subsequently, eight individuals based in the US were sentenced for managing “laptop farms,” which are collections of computers in American residences designed to make overseas workers appear local.

      Inexpensive deepfake tools simplify this process. Attackers can now fabricate live video and audio, not just images, allowing them to pass off as a different person during video interviews.

      Preventing their entry

      The solution begins with the hiring process. Companies are integrating their HR, security, legal, and IT departments, according to Adam Finkelstein of consultancy Alvarez & Marsal. He posited that treating recruitment solely as an HR responsibility “is no longer adequate for high-risk remote technical positions.”

      Tom Hegel, a threat researcher at SentinelOne, suggested that organizations should examine metadata, IP addresses, and device fingerprints when a job application is received. They should also monitor for candidates who manipulate their face or voice in real time. Some defensive measures are low-tech; asking a candidate to turn their head or wave their hand can still disrupt a live deepfake, he noted.

      The scrutiny continues after hiring. Companies must ensure that new laptops do not end up at a farm. They can then employ behavior analytics to identify unusual activity.

      Most leaks are unintentional

      The high-profile schemes are exceptions. “Insider threats are much more likely to occur accidentally,” remarked Dave Spillane of Fortinet. A report from 2025 indicated that 62% of incidents were due to human error or compromised accounts, which encompasses everything from incorrectly emailing files to inputting confidential information into unauthorized chatbots.

      This latter behavior is referred to as shadow AI. Employees input sensitive information into AI tools that have not been approved by their employer, stated John Hultquist of the Google Threat Intelligence Group.

      The next concern is the software itself. As AI agents gain operational capabilities, they start to resemble staff with system access and can be deceived. An agent “functions similarly to an employee,” Hultquist noted, adding that it “can occasionally be tricked into performing actions it should not.”

      Art Gilliland, CEO of identity firm Delinea, expressed it simply: agents require access to sensitive systems, making their identities as significant to attackers as those of humans.

      The surveillance issue

      This situation presents opportunities for the security industry. The data-loss prevention market expanded from $33 billion last year to nearly $43 billion this year, by one estimate. Certain vendors offer monitoring tools that record keystrokes and screenshots to identify risky behavior.

      However, this leads to its own challenges. “Excessive monitoring can erode trust,” stated Bernard Montel of Tenable. “The challenge lies in safeguarding the organization without fostering a culture of surveillance.”

      There is also a risk of unfairness. Finkelstein cautioned that factors such as nationality, remote work patterns, or unconventional career backgrounds should not be grounds for suspicion. Controls should rely on verifiable signals instead, like unusual privilege usage or impossible travel.

      The simplest defense, as many have argued, is also the oldest: grant individuals and potentially rogue software access only to what they truly need.

Other articles

Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya is looking into a cyberattack that altered President Ruto’s website and included a ransom demand of five bitcoins. Officials report that no data was taken. The 'synthetic insider': AI-generated deepfakes posing as fictitious employees. The 'synthetic insider': AI-generated deepfakes posing as fictitious employees. AI deepfakes enable hackers to impersonate employees, creating a "synthetic insider" threat. However, the majority of insider leaks continue to be unintentional, and AI agents represent the next potential hazard. If you really enjoy pinball, this app will help you locate a table no matter where you are. If you really enjoy pinball, this app will help you locate a table no matter where you are. Pinball Map is a free app driven by community contributions that assists players in finding pinball machines located in arcades, bars, restaurants, and various other locations around the globe. This bug in the Android lock screen allows anyone to send texts via Gemini without needing to enter your PIN. This bug in the Android lock screen allows anyone to send texts via Gemini without needing to enter your PIN. A recently found Gemini vulnerability allows anyone to bypass your Android PIN, enabling them to send SMS and WhatsApp messages from a locked device. Alibaba claims that Qwen3.8 is the second-best AI model in the world. Alibaba claims that Qwen3.8 is the second-best AI model in the world. Alibaba has introduced Qwen3.8, a model with 2.4 trillion parameters that it asserts ranks just behind Anthropic’s Fable 5; however, it has yet to provide any benchmarks or openly share its weights. Prysmian enters into a €5.5 billion agreement with Molex to provide fiber optics for AI data centers. Prysmian enters into a €5.5 billion agreement with Molex to provide fiber optics for AI data centers. Prysmian has entered into a 10-year agreement valued at €5.5 billion with Molex, which is owned by Koch, to provide optical cable for use in AI data centres, including an initial payment of €550 million.

The 'synthetic insider': AI deepfakes posing as fraudulent employees

AI deepfakes enable hackers to impersonate employees, creating the "synthetic insider" threat. However, the majority of insider leaks remain unintentional, and AI agents represent the next potential danger.