3 Sources
[1]
'Synthetic insider' attacks raise stakes for corporate cyber defence
Use of AI deepfake employees to infiltrate companies highlights wider risk of internal security breaches In June last year, the US Justice Department announced a clampdown on a North Korean hacking campaign. North Korean citizens had infiltrated US companies by fraudulently gaining employment as remote workers, in an attempt to earn money and steal data for the country's authoritarian regime. According to the US government, the perpetrators used the stolen identities of more than 80 American citizens across over 100 companies to get the jobs and carry out the attack, generating more than $5mn in illicit revenue for the government of the Democratic People's Republic of Korea (DPRK), which faces UN sanctions. As part of the crackdown, eight US-based individuals were also sentenced in recent months for hosting so-called "laptop farms" -- a physical collection of laptops in a US residence, which allows fake employees to appear as if they are in America when they are in fact operating from overseas. The case offers a glimpse inside some of the most sophisticated examples yet of insider threats, which encompass the unintentional leaking of information as well as the deliberate stealing of data or funds motivated by financial opportunity or by a grudge against an employer, for example. Of about 22,000 incidents, 12 per cent globally were carried out by internal actors, according to a 2026 analysis by the US mobile operator Verizon. The deliberate hacks "have always been the most devastating attacks and usually the most successful", says Alex Lisle, chief technology officer at deepfake detection group Reality Defender. "[They are] even more devastating because those people know where the crown jewels are and how to access them." These sorts of targeted insider attacks are being in part facilitated by a proliferation of tools that allow hackers to create convincing AI deepfakes at scale, at low cost, known as "synthetic insiders". These include not just deepfake images, but deepfake video and audio in which they can pose as a trusted person. Adam Finkelstein, a managing director of disputes and investigations at consultancy Alvarez & Marsal, says companies are responding "by tightening the connection between HR, security, legal, compliance and IT". He notes that historically, hiring was treated mainly as an HR process. "That is no longer sufficient for high-risk remote technical roles." Tom Hegel, a senior threat researcher at cyber security company SentinelOne, says tightly monitoring the entire hiring process is critical. "Companies should use identity-verification and deepfake-detection tools that screen metadata, IP and device fingerprints at the application stage," he says. Employers should watch for signs that a candidate is using AI software to alter or replace their face and voice in real time, while "low-tech methods still work too, like asking a candidate to turn their head or wave a hand", he adds. Once a person has been recruited, companies must also check that they are not sending devices to laptop farms, and from there, use behaviour analytics to detect unusual activity, Hegel says. Dave Spillane, a systems engineering director at cybersecurity group Fortinet, notes that "while stories like the North Korean IT worker schemes grab the headlines, insider threats are far more likely to happen by accident". According to a 2025 Fortinet report, for example, 62 per cent of incidents came from human error or compromised accounts. "This could be anything from inputting sensitive information into unsanctioned GenAI tools to emailing the wrong file," he says, adding that serious incidents cost businesses between $1mn and $10mn, the report found. John Hultquist, chief analyst at Google Threat Intelligence Group, notes the rise of so-called shadow AI, whereby staff use AI models that have not been approved for use by employees and might inadvertently share sensitive data with those models. The challenge is protecting the organisation without creating a culture of surveillance As AI gains more agentic capabilities, Hultquist adds, companies need to consider that bots themselves might go rogue or accidentally expose data. An AI agent "operates in a similar way to an employee", he says. "It can sometimes be fooled into doing things it shouldn't do." Art Gilliland, chief executive of identity security group Delinea agrees: "AI tools and agents need access to sensitive systems in the same way employees and contractors do, and their identities are just as valuable to attackers," he says. Given the rising risks plus the threat of penalties from regulation such as the EU's General Data Protection Regulation (GDPR), the size of the data loss prevention market -- groups that help protect sensitive data from unauthorised access, theft or leakage -- rose from $33bn in 2025, to nearly $43bn this year, according to Mordor Intelligence. In many cases, cyber security vendors offer Big Brother-like services that wield machine learning and analytics to crunch data -- potentially including keystrokes and screenshots -- on employees' activity and proactively flag worrying behaviours. Nevertheless, "there are trade-offs", says Bernard Montel, field chief technology officer for Emea at security group Tenable. "Too many controls can create friction and encourage workarounds. Too much monitoring can undermine trust. The challenge is protecting the organisation without creating a culture of surveillance." Finkelstein at Alvarez & Marsal also points to the risk of bias or over-reach. "Location anomalies, nationality, remote work patterns or unconventional career histories should not become proxies for suspicion," he says. "Controls need to focus on verifiable risk indicators," he adds, which could include unauthorised remote access, unusual privilege use or impossible travel. Montel agrees that instead of layering in new technologies, companies should focus on ensuring staff only have the access they need. "The strongest defence is often the simplest," he says. "The fewer unnecessary paths to critical systems that exist, the fewer opportunities attackers have to exploit them."
[2]
AI supercharges the cyber hacker's toolkit
In 2025, a North Korean hacking group called PutridSlug used deepfake video and audio to pose as company executives during Zoom calls, in order to trick tech employees into downloading malicious code. The efforts marked an example of extreme social engineering -- where attackers psychologically manipulate people to dupe them into performing actions or divulging sensitive information -- in this case, allowing them to conduct financial theft. Wielding new AI tools to generate hyper-realistic fake personas or clones of existing people, hackers are increasingly able to gain unauthorised access to private data and otherwise secure environments. According to Cloudflare's 2026 threat report, PutridSlug is one of three North Korean hacking groups that have now "industrialised" the use of generative AI in this way. "Social engineering works because it exploits the same human pressures it always has: urgency, authority, trust, fear and confusion, generating emotive knee-jerk responses," says Matthew Lloyd Davies, principal cyber security author and researcher at tech education platform Pluralsight. But, he adds, AI has "changed attacker economics", by making it cheaper and easier to carry out sophisticated attacks. Gone are the days of broad, opportunistic efforts using clunkily written emails laden with spelling mistakes and jarring cultural errors. Instead, large language models and generative text tools can help attackers scale outreach that is personalised and compelling, at a lower cost than ever before. By scraping from LinkedIn, company websites and other public filings, attackers can then generate highly customised emails that might trick a user into clicking on a malicious link -- a tactic known as phishing. Even hackers who are not technologically savvy are able to wield AI coding assistants to analyse stolen data and build victim profiles to then target people. We have officially crossed the threshold where a live video call is no longer proof of life According to data from security group DeepStrike, phishing attacks rose by 1,265 per cent in 2025, attributed to the growth of generative AI tools. "Attackers know your organisational chart, your vendors and your executives' communication styles before they send a single message," says Douglas Wadkins, chief technology officer at network group Opengear. "The more important shift is how AI is helping attackers industrialise the back office of fraud operations," says Gabriel Bernadett-Shapiro, a senior AI research scientist at cyber security group SentinelOne. "The notable pattern is the use of AI across the entire fraud supply chain." On top of phishing emails, AI is supercharging the creation of more sophisticated scams that use deepfakes -- cloned or faked voices and visuals. This includes so-called celeb bait, creating fake adverts featuring AI-generated clones of celebrities to manipulate victims, all the way through to a fake applicant appearing in manipulated video interviews for a remote job, in order to get inside a company's systems. "We have officially crossed the threshold where a live video call is no longer proof of life," says David Warburton, director of the threat intelligence arm of security group F5. "Threat actors are executing flawless, real-time corporate espionage and identity fraud directly over platforms like Zoom." Cyber analysts note a rise in hackers creating entire personas with backstories, or so-called synthetic identities, in order to later carry out fraud or espionage. "Social engineering is shifting towards identity as its primary target, and synthetic identities are emerging as one of the most complex threats to defend against," says Gus Tomlinson, chief product and technology officer at identity verification group GBG. These identities might "open accounts, build histories and accrue trust", she adds. According to Opengear's Wadkins, there is also a trend towards multi-vector attacks. "Rather than a single email, threat actors combine SMS, messaging platforms, and follow-up voice calls to build credibility before the malicious request arrives," he says. "The attack unfolds over days or weeks, making it much harder for employees to recognise the manipulation in real time." For companies, the challenge appears existential. "The real risk isn't simply that people believe fake content. It's that they begin to question genuine content as well," says Amit Sinha, chief executive at digital security company DigiCert. "Once people lose confidence in the authenticity of the information they're receiving from an organisation, every interaction requires an extra layer of verification." But defenders are themselves wielding advanced AI tools to help root out attacks. According to Tomlinson, some organisations concerned about fake identities are now using advanced "liveness detection" systems, which analyse "subtle biological signals such as micro-texture variations and the way light reflects off the face" to confirm whether someone is real or not. On top of biometric indicators, other contextual data can help make an assessment, such as "the cadence of typing, the way a device is handled", he adds. Matthew Ferraro, a partner specialising in cyber security at law firm Crowell & Moring, argues that businesses must also educate their staff and adopt a "zero trust" framework where all important requests, such as financial transfers or password resets, require human verification. Executives, finance teams and their family members should also establish "pre-established passphrases" to confirm each other's identity, he says. Leadership teams should rehearse these scenarios, run cyber crisis exercises and simulations of attacks that include AI-enabled social engineering, agrees Adam Finkelstein, a managing director of disputes and investigations at consultancy Alvarez & Marsal. "In our experience, preparation is the difference between a contained incident and a business crisis." "The human vulnerability hasn't changed, but the attack has," says David Maimon, head of fraud insights at software company SentiLink and a professor at Georgia State University. "Train your people to pause before they act, and verify through a channel they trust independently. The scam only works if you move fast." But Darren Meyer, security research advocate at IT security company Checkmarx, argues that "no amount of security training fixes this issue". Instead, he adds, companies need to draw up ways to reduce the fallout of an inevitable social engineering campaign, including "creating proactive controls" to limit the impact of attacks.
[3]
Fake Employees Are Banks' Newest Insider Threat | PYMNTS.com
Generative AI is what makes that impersonation possible at scale. It has lowered the cost of building a fake employee identity to near zero. Artificial intelligence tools can now deliver convincing video interview performances and fabricate government-issued IDs. That same technology makes it simple to generate fake resumes, portfolio websites and writing samples that backup a fabricated work history, Cloudflare reported in its 2026 Threat Report. A Department of Justice case in April 2026 showed what that looks like at scale: two U.S. residents were sentenced for running operations that placed fraudulent workers inside more than 100 U.S. companies using the stolen identities of more than 80 Americans, generating more than $5 million for the North Korean government, TechCrunch reported. DOJ's announcement does not specify whether the scheme triggered internal security alerts at the affected companies. Inside a Bank, the Data Is Worth More Than the Money The immediate risk from synthetic insiders in financial services is not a fraudulent wire transfer. It is access to the systems that make wire transfers possible. A worker with approved access can reach fraud detection models, payment flow architectures, customer records, pricing data, merchant information and internal controls. That information does not trigger an alert when it is read. It gets copied and studied over months before anything visible happens. Kaspersky found in an April 2026 report that more than 1 million banking accounts at the world's 100 largest banks were compromised by infostealers in 2025, with 74% of stolen payment card numbers remaining valid as of March 2026. The shelf life of stolen identity data extends months past the breach. That shelf life matters most when the access came from inside the company. Internal actors appeared in 12% of confirmed breaches analyzed in Verizon's 2026 Data Breach Investigations Report, which covered more than 22,000 confirmed breaches across 145 countries, Verizon reported. That figure is down from 18% the prior year. The decline reflects overall insider-breach frequency, not the sophistication of synthetic-insider schemes specifically, which are not broken out separately in the report. What makes insider incidents particularly damaging is not their frequency but their dwell time. Access that looks legitimate at every layer does not trigger the controls built to detect illegitimate access. By the time the activity is flagged, the information has often already left. Threat Enters Through the Front Door With a Real Badge A valid login used to mean a verified employee. Synthetic insider schemes answer the login check correctly while the threat operates behind it. Cloudflare's 2026 Threat Report found that traditional background checks and standard identity verification are struggling to keep pace with attackers who have adapted to pass them. Remote administration tools such as AnyDesk and TeamViewer let operators run company-issued devices from overseas a tactic Skadden reported in a June 2026 publication as a hallmark of these schemes. The verification gap is not confined to hiring. Outdated identity controls are costing businesses nearly $100 billion annually in fraud, according to PYMNTS Intelligence research conducted with Trulioo. Nearly 90% of enterprises said bot management is now a major challenge. That research measures bot traffic and AI agent activity in digital commerce rather than fraudulent hiring specifically, but it points to the same underlying gap: identity controls built to verify humans are not built to verify what is operating behind a login. The controls being deployed to address synthetic insiders go beyond checking whether a login is valid. They monitor behavioral signals: whether the working hours, location data and activity patterns of the person operating a device match the profile of the employee who was hired. The attack surface is the gap between the identity that was verified and the person now sitting behind it.
Share
Copy Link
North Korean hackers generated over $5 million by placing fraudulent employees created using generative AI inside more than 100 US companies. These synthetic insiders use deepfake video, audio, and stolen identities to bypass traditional security checks, accessing sensitive systems and data. The attacks highlight how AI cyberattacks are transforming corporate cyber defence strategies.
The US Justice Department uncovered a sophisticated scheme in June 2024 that exposed a new frontier in cyber threats: North Korean hackers had successfully placed fraudulent employees created using generative AI inside more than 100 US companies. Using stolen identities of over 80 American citizens, these synthetic insiders generated more than $5 million in illicit revenue for the North Korean government, which operates under UN sanctions
1
. The case involved eight US-based individuals sentenced for hosting "laptop farms"—physical collections of laptops that allowed fake employees to appear as if they were working from America while actually operating from overseas1
.
Source: PYMNTS
These AI cyberattacks represent a dramatic escalation in insider threat tactics. According to Verizon's 2026 analysis covering over 22,000 incidents across 145 countries, 12 per cent of confirmed breaches globally were carried out by internal actors
1
3
. What makes these attacks particularly devastating is that legitimate employees know exactly where sensitive data resides and how to access it without triggering conventional security alerts.Cloudflare's 2026 threat report identified three North Korean hacking groups, including PutridSlug, that have "industrialized" the use of generative AI to conduct sophisticated attacks
2
. In 2025, PutridSlug used AI-generated deepfake employees with convincing video and audio to pose as company executives during Zoom calls, tricking tech employees into downloading malicious code that enabled financial theft2
. "We have officially crossed the threshold where a live video call is no longer proof of life," says David Warburton, director of the threat intelligence arm at security group F52
.
Source: FT
The economics behind these attacks have fundamentally shifted. AI has "changed attacker economics" by making it cheaper and easier to carry out sophisticated attacks, according to Matthew Lloyd Davies, principal cyber security author at Pluralsight
2
. Generative AI has lowered the cost of building a fake employee identity to near zero, enabling attackers to generate convincing video interview performances, fabricate government-issued IDs, create fake resumes, and build portfolio websites that support entirely fabricated work histories3
.For financial institutions, the primary concern extends beyond immediate fraudulent transactions. The real danger lies in unauthorized access to critical systems that control fraud detection models, payment architectures, customer records, and internal controls
3
. A Kaspersky report from April 2026 found that more than 1 million banking accounts at the world's 100 largest banks were compromised by infostealers in 2025, with 74 per cent of stolen payment card numbers remaining valid as of March 2026 .What makes insider incidents particularly damaging is not their frequency but their dwell time—the period during which attackers operate undetected. Access that appears legitimate at every layer does not trigger controls built to detect illegitimate access. Remote administration tools such as AnyDesk and TeamViewer allow operators to run company-issued devices from overseas, a tactic that has become a hallmark of these schemes
3
.Related Stories
Data from security group DeepStrike shows phishing attacks rose by 1,265 per cent in 2025, attributed directly to the growth of generative AI tools
2
. By scraping data from LinkedIn, company websites, and public filings, attackers generate hyper-personalized phishing campaigns that are far more convincing than the clumsy, error-laden emails of the past. "Attackers know your organisational chart, your vendors and your executives' communication styles before they send a single message," says Douglas Wadkins, chief technology officer at network group Opengear2
.Companies are responding by fundamentally restructuring their approach to corporate cyber defence. Adam Finkelstein, a managing director at Alvarez & Marsal, notes that companies are "tightening the connection between HR, security, legal, compliance and IT" because treating hiring as mainly an HR process "is no longer sufficient for high-risk remote technical roles"
1
. Tom Hegel, a senior threat researcher at SentinelOne, emphasizes that companies should use deepfake detection tools that screen metadata, IP addresses, and device fingerprints at the application stage, while also watching for signs that candidates are using AI software to alter their face and voice in real time1
.Beyond external threats, organizations face rising concerns about shadow AI—the use of AI models by staff that have not been approved by employers and might inadvertently share sensitive data
1
. John Hultquist, chief analyst at Google Threat Intelligence Group, warns that as AI gains more agentic capabilities, companies must consider that bots themselves might go rogue or accidentally expose data, since an AI agent "operates in a similar way to an employee"1
.The data loss prevention market has expanded rapidly in response to these threats, growing from $33 billion in 2025 to nearly $43 billion in 2026, according to Mordor Intelligence
1
. Organizations are deploying behavioral monitoring systems that track whether working hours, location data, and activity patterns match the profile of the employee who was hired3
. Some companies concerned about fake identities now use liveness detection systems that analyze "subtle biological signals such as micro-texture variations and the way light reflects off the face" to confirm authenticity2
. Research from PYMNTS Intelligence conducted with Trulioo indicates that outdated identity controls are costing businesses nearly $100 billion annually in fraud, with nearly 90 per cent of enterprises identifying bot management as a major challenge3
.Summarized by
Navi
1
Technology

2
Science and Research

3
Policy and Regulation
