Synthetic insiders using AI deepfakes infiltrate companies, generating millions for hackers

Reviewed byNidhi Govil

3 Sources

Share

North Korean hackers generated over $5 million by placing fraudulent employees created using generative AI inside more than 100 US companies. These synthetic insiders use deepfake video, audio, and stolen identities to bypass traditional security checks, accessing sensitive systems and data. The attacks highlight how AI cyberattacks are transforming corporate cyber defence strategies.

AI-Generated Deepfake Employees Breach Corporate Defenses

The US Justice Department uncovered a sophisticated scheme in June 2024 that exposed a new frontier in cyber threats: North Korean hackers had successfully placed fraudulent employees created using generative AI inside more than 100 US companies. Using stolen identities of over 80 American citizens, these synthetic insiders generated more than $5 million in illicit revenue for the North Korean government, which operates under UN sanctions

1

. The case involved eight US-based individuals sentenced for hosting "laptop farms"—physical collections of laptops that allowed fake employees to appear as if they were working from America while actually operating from overseas

1

.

Source: PYMNTS

Source: PYMNTS

These AI cyberattacks represent a dramatic escalation in insider threat tactics. According to Verizon's 2026 analysis covering over 22,000 incidents across 145 countries, 12 per cent of confirmed breaches globally were carried out by internal actors

1

3

. What makes these attacks particularly devastating is that legitimate employees know exactly where sensitive data resides and how to access it without triggering conventional security alerts.

North Korean Hackers Industrialize AI-Driven Social Engineering

Cloudflare's 2026 threat report identified three North Korean hacking groups, including PutridSlug, that have "industrialized" the use of generative AI to conduct sophisticated attacks

2

. In 2025, PutridSlug used AI-generated deepfake employees with convincing video and audio to pose as company executives during Zoom calls, tricking tech employees into downloading malicious code that enabled financial theft

2

. "We have officially crossed the threshold where a live video call is no longer proof of life," says David Warburton, director of the threat intelligence arm at security group F5

2

.

Source: FT

Source: FT

The economics behind these attacks have fundamentally shifted. AI has "changed attacker economics" by making it cheaper and easier to carry out sophisticated attacks, according to Matthew Lloyd Davies, principal cyber security author at Pluralsight

2

. Generative AI has lowered the cost of building a fake employee identity to near zero, enabling attackers to generate convincing video interview performances, fabricate government-issued IDs, create fake resumes, and build portfolio websites that support entirely fabricated work histories

3

.

Unauthorized Access to Critical Systems Poses Long-Term Risk

For financial institutions, the primary concern extends beyond immediate fraudulent transactions. The real danger lies in unauthorized access to critical systems that control fraud detection models, payment architectures, customer records, and internal controls

3

. A Kaspersky report from April 2026 found that more than 1 million banking accounts at the world's 100 largest banks were compromised by infostealers in 2025, with 74 per cent of stolen payment card numbers remaining valid as of March 2026 .

What makes insider incidents particularly damaging is not their frequency but their dwell time—the period during which attackers operate undetected. Access that appears legitimate at every layer does not trigger controls built to detect illegitimate access. Remote administration tools such as AnyDesk and TeamViewer allow operators to run company-issued devices from overseas, a tactic that has become a hallmark of these schemes

3

.

Corporate Cyber Defence Adapts to AI Supercharges the Cyber Hacker's Toolkit

Data from security group DeepStrike shows phishing attacks rose by 1,265 per cent in 2025, attributed directly to the growth of generative AI tools

2

. By scraping data from LinkedIn, company websites, and public filings, attackers generate hyper-personalized phishing campaigns that are far more convincing than the clumsy, error-laden emails of the past. "Attackers know your organisational chart, your vendors and your executives' communication styles before they send a single message," says Douglas Wadkins, chief technology officer at network group Opengear

2

.

Companies are responding by fundamentally restructuring their approach to corporate cyber defence. Adam Finkelstein, a managing director at Alvarez & Marsal, notes that companies are "tightening the connection between HR, security, legal, compliance and IT" because treating hiring as mainly an HR process "is no longer sufficient for high-risk remote technical roles"

1

. Tom Hegel, a senior threat researcher at SentinelOne, emphasizes that companies should use deepfake detection tools that screen metadata, IP addresses, and device fingerprints at the application stage, while also watching for signs that candidates are using AI software to alter their face and voice in real time

1

.

Shadow AI and Behavioral Monitoring Emerge as Key Concerns

Beyond external threats, organizations face rising concerns about shadow AI—the use of AI models by staff that have not been approved by employers and might inadvertently share sensitive data

1

. John Hultquist, chief analyst at Google Threat Intelligence Group, warns that as AI gains more agentic capabilities, companies must consider that bots themselves might go rogue or accidentally expose data, since an AI agent "operates in a similar way to an employee"

1

.

The data loss prevention market has expanded rapidly in response to these threats, growing from $33 billion in 2025 to nearly $43 billion in 2026, according to Mordor Intelligence

1

. Organizations are deploying behavioral monitoring systems that track whether working hours, location data, and activity patterns match the profile of the employee who was hired

3

. Some companies concerned about fake identities now use liveness detection systems that analyze "subtle biological signals such as micro-texture variations and the way light reflects off the face" to confirm authenticity

2

. Research from PYMNTS Intelligence conducted with Trulioo indicates that outdated identity controls are costing businesses nearly $100 billion annually in fraud, with nearly 90 per cent of enterprises identifying bot management as a major challenge

3

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved