AI & TechArtificial IntelligenceCybersecurityDigital PublishingNewswireTechnology

Synthetic Insiders: How AI Deepfakes Pose as Real Employees

▼ Summary

– Hackers use cheap AI deepfakes to pose as trusted employees, a threat known as the “synthetic insider.”
– A North Korean scheme used stolen identities to get remote jobs at over 100 US firms, raising over $5 million for the regime.
– Companies can screen candidates by checking metadata and device fingerprints, or asking them to turn their head to break a live deepfake.
– Most insider threats (62%) are accidental, caused by human error or hijacked accounts, including staff feeding data into unapproved AI tools.
– Over-monitoring employees can undermine trust, so access should be limited to only what each person or software needs.

The biggest security threat inside your organization may not be an employee at all. As AI deepfakes become more affordable and convincing, cybercriminals are increasingly using them to impersonate trusted staff members. This emerging danger is known in the industry as the “synthetic insider.”

This technique represents an evolution of a classic vulnerability. Insider threats have always existed, ranging from an employee accidentally emailing the wrong attachment to a malicious actor who knows exactly where sensitive data is stored. According to a 2026 analysis of roughly 22,000 incidents conducted by Verizon and reported by the Financial Times, 12 percent of breaches involved internal actors.

The most damaging incidents are those committed intentionally. “They know where the crown jewels are and how to access them,” said Alex Lisle, chief technology officer at deepfake-detection firm Reality Defender.

The fake employee

A stark illustration came last year when the US Justice Department dismantled a North Korean scheme. Operatives used stolen identities to fraudulently secure remote jobs at American companies. Their dual objective was to collect salaries and exfiltrate sensitive data for the sanctioned regime.

The government revealed that the group used the identities of more than 80 US citizens to gain employment at over 100 companies. This effort funneled more than $5 million back to Pyongyang. Eight individuals based in the US were later convicted for operating “laptop farms” , racks of computers placed in American homes to make overseas workers appear local.

Cheap deepfake software has made this deception far simpler. Attackers can now generate synthetic video and audio in real time, not just static images. This allows them to pass a video interview while fully impersonating another person.

Catching them at the door

Prevention begins during the hiring process. Companies are now combining efforts across HR, security, legal, and IT departments, explained Adam Finkelstein of consultancy Alvarez & Marsal. Treating recruitment as a purely administrative HR function, he argued, “is no longer sufficient for high-risk remote technical roles.”

Tom Hegel, a threat researcher at SentinelOne, recommended that organizations screen metadata, IP addresses, and device fingerprints as soon as an application is submitted. They should also watch for candidates attempting to alter their face or voice during live video. Some countermeasures are surprisingly low-tech. Simply asking a candidate to turn their head or wave a hand can still expose a live deepfake, Hegel noted.

Vetting must continue after the hire is made. Companies should ensure new laptops are shipped directly to the employee, not to a farm. Then, behavioral analytics can be used to flag unusual activity.

Most leaks are accidents

The dramatic, headline-grabbing plots are the exception, not the rule. “Insider threats are far more likely to happen by accident,” said Dave Spillane of Fortinet. A 2025 report from the firm attributed 62 percent of incidents to human error or compromised accounts. This category includes everything from sending an email to the wrong person to pasting confidential information into an unapproved chatbot.

That last behavior has its own label: shadow AI. Employees are feeding sensitive data into artificial intelligence tools that their employer never sanctioned, warned John Hultquist of Google Threat Intelligence Group.

A growing concern involves the software itself. As AI agents gain the ability to take independent actions, they begin to resemble employees with system access. And they can be deceived. An agent “operates in a similar way to an employee,” Hultquist said. It “can sometimes be fooled into doing things it shouldn’t do.” Art Gilliland, chief executive of identity firm Delinea, put it plainly. Agents require access to sensitive systems, making their identities just as valuable to attackers as a human’s.

The surveillance trap

All of this is a boon for the security industry. The market for data-loss prevention has grown from $33 billion last year to nearly $43 billion this year, according to one estimate. Some vendors offer intrusive tools that log keystrokes and take screenshots to flag risky behavior.

This approach creates its own dilemma. “Too much monitoring can undermine trust,” said Bernard Montel of Tenable. “The challenge is protecting the organisation without creating a culture of surveillance.”

There is also a risk of unfair bias. Finkelstein cautioned that nationality, remote-work patterns, or an unusual career history should never become grounds for suspicion. Controls should instead rely on verifiable signals, such as unusual privilege usage or impossible travel patterns.

The simplest defense, several experts agreed, is also the most time-tested. Give people , and rogue software , access only to what they absolutely need.

(Source: The Next Web)

Topics

synthetic insider 95% insider threats 92% north korean scheme 88% Deepfake Detection 85% remote hiring risks 83% laptop farms 80% accidental data leaks 78% shadow ai 75% ai agent risks 73% behavior analytics 70%