The 'synthetic insider': AI-generated deepfakes posing as fictitious employees.
The most perilous individual in your organization might actually be someone who isn’t employed there. The advancements in AI deepfakes are making them more affordable and effective. Cybercriminals are now utilizing these technologies to impersonate trusted employees, a risk referred to in the industry as the “synthetic insider.”
This approach highlights a longstanding issue. Insider threats can range from a worker accidentally sending the incorrect file to a criminal who is well aware of the location of valuable assets. A 2026 study by Verizon that analyzed approximately 22,000 incidents revealed that 12% were attributed to internal actors, according to the Financial Times.
Those who act deliberately tend to cause the most harm. “They understand where the most valuable assets are and how to gain access to them,” noted Alex Lisle, chief technology officer at the deepfake detection company Reality Defender.
The impersonation of an employee
A prominent instance is a North Korean operation that the US Justice Department targeted last year. Agents improperly obtained remote positions at US companies, intending to generate income and steal information for the sanctioned regime. They exploited the stolen identities of over 80 Americans to secure jobs at more than 100 firms, according to the government. This scheme generated over $5 million for Pyongyang. Eight individuals based in the US received sentences for managing “laptop farms,” which are sets of computers in American residences that made foreign workers appear local.
Affordable deepfake technology has made this process simpler. Attackers can now replicate live video and audio, moving beyond just photographs. This allows them to successfully navigate video interviews while impersonating someone else.
Detecting them at the outset
The solution begins with the hiring process. Companies are integrating human resources, security, legal, and IT departments, stated Adam Finkelstein from the consultancy Alvarez & Marsal. He argued that treating recruitment solely as an HR responsibility is insufficient for high-risk remote technical roles.
Tom Hegel, a threat researcher at SentinelOne, suggested that businesses should analyze metadata, IP addresses, and device fingerprints when applications are submitted. They should also be alert for candidates attempting to modify their appearance or voice during real-time interactions. Some preventive measures are straightforward; for instance, asking a candidate to turn their head or wave a hand can disrupt a live deepfake, he mentioned.
The scrutiny must continue once a hire is made. Companies should ensure that new laptops aren’t sent to a “farm.” They can also employ behavior analytics to identify unusual activities.
Most leaks occur by accident
The high-profile schemes are the rare exceptions. “Insider threats are more likely to arise accidentally,” said Dave Spillane of Fortinet. A report from the firm in 2025 indicated that 62% of incidents were due to human mistakes or compromised accounts, which encompasses actions like sending the wrong file or inputting confidential information into an unauthorized chatbot.
This latter behavior is referred to as shadow AI. Employees input sensitive information into AI tools that their employer has not authorized, explained John Hultquist of Google Threat Intelligence Group.
A new concern is the software itself. As AI agents gain more autonomy, they begin to resemble employees with system access, and they can be deceived. An agent “functions similarly to an employee,” stated Hultquist. “Sometimes it can be misled into executing inappropriate actions.” Art Gilliland, CEO of identity firm Delinea, expressed it simply: agents require access to sensitive systems, making their identities as appealing to attackers as those of humans.
The surveillance dilemma
All of this benefits the security industry. Market estimates indicate that the data-loss prevention sector expanded from $33 billion last year to nearly $43 billion this year. Some companies offer Big Brother-style solutions that record keystrokes and screenshots to identify risky behavior.
However, this poses its own challenges. “Excessive monitoring can erode trust,” warned Bernard Montel of Tenable. “The challenge lies in safeguarding the organization without instilling a culture of surveillance.”
There is also a fairness concern. Finkelstein cautioned that nationality, remote work tendencies, or an atypical career path should not trigger undue suspicion. Instead, controls ought to be based on verifiable indicators, such as unusual privilege usage or implausible travel patterns.
Many agreed that the simplest defense, and possibly the oldest, is to provide access strictly based on necessity for both individuals and rogue software.
Other articles
The 'synthetic insider': AI-generated deepfakes posing as fictitious employees.
AI deepfakes enable hackers to impersonate employees, creating a "synthetic insider" threat. However, the majority of insider leaks continue to be unintentional, and AI agents represent the next potential hazard.
