The 'synthetic insider': AI-generated deepfakes as fraudulent employees

The 'synthetic insider': AI-generated deepfakes as fraudulent employees

      The most perilous individual within your organization may not even be an employee. AI deepfakes are becoming more affordable and sophisticated, with hackers utilizing them to impersonate trusted personnel, a threat referred to as the “synthetic insider.”

      This method exemplifies a long-standing issue related to insider threats, which can range from an employee mistakenly emailing the wrong document to a criminal who is fully aware of where the valuables are located. According to a 2026 analysis by Verizon of approximately 22,000 incidents, 12% were attributed to internal actors, as reported by the Financial Times.

      Intentional insider threats cause the most harm. “They know where the valuable assets are and how to access them,” remarked Alex Lisle, chief technology officer at the deepfake detection company Reality Defender.

      The impersonator

      A clear instance is a scheme by North Korean operatives that the US Justice Department targeted last year. These operatives fraudulently obtained remote jobs at US companies to earn wages and gather data for the sanctioned regime. They used the stolen identities of more than 80 Americans to secure employment with over 100 firms, as stated by the government, generating more than $5 million for Pyongyang. Eight individuals based in the US were later sentenced for operating “laptop farms,” which are setups of computers in American residences that made foreign workers appear local.

      Affordable deepfake tools have facilitated these activities. Attackers can now create live video and audio personas, not just static images, allowing them to successfully navigate a video interview while impersonating someone else.

      Preventing entry

      Addressing this issue begins with the hiring process. According to Adam Finkelstein from the consultancy Alvarez & Marsal, companies should collaborate across HR, security, legal, and IT departments. He argued that viewing recruitment as solely an HR function is no longer adequate for high-risk remote technical positions.

      Tom Hegel, a threat researcher at SentinelOne, suggested that companies should examine metadata, IP addresses, and device identifiers upon receipt of applications. They should also be vigilant for candidates manipulating their appearance or voice in real time. Some defenses are low-tech, as asking a candidate to move their head or wave can effectively disrupt a live deepfake, he noted.

      The scrutiny continues after hiring. Organizations should ensure that new laptops are not dispatched to a “farm.” They can also employ behavior analytics to identify unusual activities.

      Most incidents stem from mistakes

      The more sensational schemes are exceptions rather than the rule. “Insider threats are significantly more likely to occur due to accidents,” stated Dave Spillane from Fortinet. A report from the firm in 2025 attributed 62% of incidents to human error or compromised accounts, which includes cases like mistakenly emailing sensitive files or inputting confidential information into unauthorized chatbots.

      This latter behavior is known as shadow AI, where employees input sensitive data into AI tools not approved by their employers, according to John Hultquist of the Google Threat Intelligence Group.

      Another concern is the software itself. As AI agents acquire capabilities to take action, they begin to function similarly to employees with system access and can be deceived. An agent “operates in a comparable manner to an employee,” Hultquist noted.

      It “can occasionally be misled into performing actions it shouldn’t.” Art Gilliland, chief executive of identity firm Delinea, succinctly stated that agents require access to sensitive systems, making their identities as valuable to attackers as those of humans.

      The surveillance dilemma

      All of these factors are advantageous for the security sector. The data-loss prevention market expanded from $33 billion last year to nearly $43 billion this year, by some estimates. Certain vendors offer invasive monitoring tools that track keystrokes and capture screenshots to identify risky behaviors.

      However, this leads to its own challenges. “Excessive monitoring can erode trust,” cautioned Bernard Montel of Tenable. “The challenge lies in safeguarding the organization without instilling a surveillance culture.”

      There is also a fairness concern. Finkelstein cautioned that attributes such as nationality, remote work habits, or an unusual career trajectory should not become bases for suspicion. Controls should rely on verifiable indicators, such as unusual privilege usage or implausible travel patterns.

      The most straightforward defense, as several have pointed out, is also the most traditional: limit access for individuals and potentially harmful software to only what is necessary.

Other articles

The software update for your next car might turn out to be its greatest security threat. The software update for your next car might turn out to be its greatest security threat. Experts indicate that over-the-air updates for vehicles are revolutionizing the automotive sector but are also giving rise to new cybersecurity and national security threats that governments must address. Decart's Lucy 2.5 introduces fresh live video effects, yet the true victor is physical AI. Decart's Lucy 2.5 introduces fresh live video effects, yet the true victor is physical AI. Decart's Lucy 2.5 introduces real-time visual effects to live video, featuring everything from explosions to virtual try-ons. However, the more significant development is how its enhanced physics engine bolsters the Oasis 3 world model simulations for robotics and autonomous vehicles. This bug in the Android lock screen allows anyone to send messages through Gemini without needing to enter your PIN. This bug in the Android lock screen allows anyone to send messages through Gemini without needing to enter your PIN. A recently found Gemini bug allows anyone to circumvent your Android PIN, enabling them to send SMS and WhatsApp messages from a locked device. Alibaba claims that Qwen3.8 is the second-best AI model in the world. Alibaba claims that Qwen3.8 is the second-best AI model in the world. Alibaba has showcased Qwen3.8, a model with 2.4 trillion parameters that it asserts is surpassed only by Anthropic’s Fable 5. However, it has yet to present any benchmarks or make its weights publicly available. The software update for your next car might turn out to be its greatest security vulnerability. The software update for your next car might turn out to be its greatest security vulnerability. Experts indicate that over-the-air updates for vehicles are revolutionizing the automotive industry but are also introducing new cybersecurity and national security concerns that governments can no longer overlook. Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya looks into the hacking of Ruto's official website following a bitcoin ransom request. Kenya is looking into a cyberattack that altered President Ruto’s website and included a ransom demand of five bitcoins. Officials report that no data was taken.

The 'synthetic insider': AI-generated deepfakes as fraudulent employees

AI deepfakes enable hackers to impersonate employees, creating a "synthetic insider" threat. However, the majority of insider leaks continue to be unintentional, and AI agents represent the next potential risk.