The 'synthetic insider': AI deepfakes posing as fraudulent employees
The most perilous individual in your organization may not even be an employee. AI deepfakes are becoming increasingly affordable and sophisticated. Hackers are now utilizing them to impersonate trusted personnel, which the industry refers to as the “synthetic insider.”
This method highlights a long-standing issue. Insider threats can range from an employee mistakenly sending the wrong document to a criminal who knows exactly where the assets are located. According to a 2026 analysis of approximately 22,000 incidents by Verizon, 12% involved internal actors, as reported by the Financial Times.
The intentional threats cause the greatest harm. “They are aware of where the crucial assets are and how to access them,” stated Alex Lisle, chief technology officer at the deepfake-detection company Reality Defender.
The impersonated employee
A prominent example is a North Korean operation that the US Justice Department targeted last year. Operatives fraudulently obtained remote jobs at American companies. Their aim was to earn salaries and gather information for the sanctioned regime.
They used the stolen identities of over 80 Americans to gain employment at more than 100 firms, according to government reports. This scheme generated over $5 million for Pyongyang. Subsequently, eight individuals based in the US were sentenced for managing “laptop farms,” which are collections of computers in American residences designed to make overseas workers appear local.
Inexpensive deepfake tools simplify this process. Attackers can now fabricate live video and audio, not just images, allowing them to pass off as a different person during video interviews.
Preventing their entry
The solution begins with the hiring process. Companies are integrating their HR, security, legal, and IT departments, according to Adam Finkelstein of consultancy Alvarez & Marsal. He posited that treating recruitment solely as an HR responsibility “is no longer adequate for high-risk remote technical positions.”
Tom Hegel, a threat researcher at SentinelOne, suggested that organizations should examine metadata, IP addresses, and device fingerprints when a job application is received. They should also monitor for candidates who manipulate their face or voice in real time. Some defensive measures are low-tech; asking a candidate to turn their head or wave their hand can still disrupt a live deepfake, he noted.
The scrutiny continues after hiring. Companies must ensure that new laptops do not end up at a farm. They can then employ behavior analytics to identify unusual activity.
Most leaks are unintentional
The high-profile schemes are exceptions. “Insider threats are much more likely to occur accidentally,” remarked Dave Spillane of Fortinet. A report from 2025 indicated that 62% of incidents were due to human error or compromised accounts, which encompasses everything from incorrectly emailing files to inputting confidential information into unauthorized chatbots.
This latter behavior is referred to as shadow AI. Employees input sensitive information into AI tools that have not been approved by their employer, stated John Hultquist of the Google Threat Intelligence Group.
The next concern is the software itself. As AI agents gain operational capabilities, they start to resemble staff with system access and can be deceived. An agent “functions similarly to an employee,” Hultquist noted, adding that it “can occasionally be tricked into performing actions it should not.”
Art Gilliland, CEO of identity firm Delinea, expressed it simply: agents require access to sensitive systems, making their identities as significant to attackers as those of humans.
The surveillance issue
This situation presents opportunities for the security industry. The data-loss prevention market expanded from $33 billion last year to nearly $43 billion this year, by one estimate. Certain vendors offer monitoring tools that record keystrokes and screenshots to identify risky behavior.
However, this leads to its own challenges. “Excessive monitoring can erode trust,” stated Bernard Montel of Tenable. “The challenge lies in safeguarding the organization without fostering a culture of surveillance.”
There is also a risk of unfairness. Finkelstein cautioned that factors such as nationality, remote work patterns, or unconventional career backgrounds should not be grounds for suspicion. Controls should rely on verifiable signals instead, like unusual privilege usage or impossible travel.
The simplest defense, as many have argued, is also the oldest: grant individuals and potentially rogue software access only to what they truly need.
Other articles
The 'synthetic insider': AI deepfakes posing as fraudulent employees
AI deepfakes enable hackers to impersonate employees, creating the "synthetic insider" threat. However, the majority of insider leaks remain unintentional, and AI agents represent the next potential danger.
