The ‘synthetic insider’: how AI deepfakes turned the fake employee into a corporate threat AI deepfakes are enabling a new corporate threat called the 'synthetic insider,' where hackers pose as trusted employees using cheap, realistic fake video and audio. A North Korean scheme used stolen identities of over 80 Americans to land remote jobs at more than 100 US firms, raising over $5 million for Pyongyang, according to the US Justice Department. Verizon's 2026 analysis of about 22,000 incidents found 12% were internal actor threats, with deliberate insiders causing the most damage, said Alex Lisle, CTO of Reality Defender. The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.” The tactic sits at the sharp end of an old problem. Insider threats run from a worker emailing the wrong file to a thief who knows exactly where the valuables are. A 2026 analysis of about 22,000 incidents by Verizon found 12% were the work of internal actors, the Financial Times reported https://www.ft.com/content/67fe2b44-2041-4ee1-b606-5def4d717407 . The deliberate ones do the most damage. “They know where the crown jewels are and how to access them,” said Alex Lisle, chief technology officer at deepfake-detection firm Reality Defender. The fake employee The clearest example is a North Korean scheme the US Justice Department cracked down on last year. Operatives fraudulently landed remote jobs at US firms. The goal was to earn wages and steal data for the sanctioned regime. They used the stolen identities of more than 80 Americans to get hired at over 100 companies, the government said. That raised more than $5m for Pyongyang. Eight US-based people were later sentenced for running “laptop farms.” These are racks of computers in American homes that made overseas workers look local. Cheap deepfake https://thenextweb.com/news/google-synthid-mcconnell-deepfake-debunked tools make this easier. Attackers can now fake live video and audio, not just a photo. That lets them sail through a video interview as someone else. Catching them at the door The fix starts with hiring. Companies are knitting together HR, security, legal and IT, said Adam Finkelstein of consultancy Alvarez & Marsal. Treating recruitment as a pure HR task, he argued, “is no longer sufficient for high-risk remote technical roles.” Tom Hegel, a threat researcher at SentinelOne, said firms should screen metadata, IP addresses and device fingerprints when an application lands. They should also watch for candidates altering their face or voice in real time. Some defences are low-tech. Asking a candidate to turn their head or wave a hand can still break a live deepfake, he said. The checks continue after the hire. Firms should make sure new laptops are not shipped to a farm. Then they can use behaviour analytics to flag odd activity. Most leaks are accidents The headline-grabbing plots are the exception. “Insider threats are far more likely to happen by accident,” said Dave Spillane of Fortinet. A 2025 report from the firm blamed 62% of incidents on human error or hijacked accounts. That covers everything from emailing the wrong file to pasting secrets into an unsanctioned chatbot. That last habit has a name: shadow AI. Staff feed sensitive data into AI tools https://thenextweb.com/news/1password-claude-credential-zero-exposure-agentic-mode their employer never approved, said John Hultquist of Google Threat Intelligence Group. The next worry is the software itself. As AI agents https://thenextweb.com/news/cloudflare-precursor-bots-agentic-web gain the power to act, they start to look like staff with system access. And they can be tricked. An agent “operates in a similar way to an employee,” Hultquist said. It “can sometimes be fooled into doing things it shouldn’t do.” Art Gilliland, chief executive of identity firm Delinea, put it plainly. Agents need access to sensitive systems, so their identities https://thenextweb.com/news/oak-60m-seed-ai-native-identity-platform are as valuable to attackers as a human’s. The surveillance trap All this is good for the security industry. The market for data-loss prevention grew from $33bn last year to almost $43bn this year, by one estimate. Some vendors sell Big Brother-style tools that log keystrokes and screenshots to flag risky behaviour. That raises its own problem. “Too much monitoring can undermine trust,” said Bernard Montel of Tenable. “The challenge is protecting the organisation without creating a culture of surveillance.” There is a fairness risk too. Finkelstein warned that nationality, remote-work patterns or an unusual career history should not become grounds for suspicion. Controls should hang on verifiable signals instead, such as odd privilege use or impossible travel. The simplest defence, several argued, is also the oldest. Give people, and rogue https://thenextweb.com/news/runta-a16z-seed-ai-agent-infrastructure software, access only to what they need. Get the TNW newsletter Get the most important tech news in your inbox each week.