3 Sources
[1]
'Synthetic insider' attacks raise stakes for corporate cyber defence
Use of AI deepfake employees to infiltrate companies highlights wider risk of internal security breaches In June last year, the US Justice Department announced a clampdown on a North Korean hacking campaign. North Korean citizens had infiltrated US companies by fraudulently gaining employment as
[2]
AI supercharges the cyber hacker's toolkit
In 2025, a North Korean hacking group called PutridSlug used deepfake video and audio to pose as company executives during Zoom calls, in order to trick tech employees into downloading malicious code. The efforts marked an example of extreme social engineering -- where attackers psychologically
[3]
Fake Employees Are Banks' Newest Insider Threat | PYMNTS.com
Generative AI is what makes that impersonation possible at scale. It has lowered the cost of building a fake employee identity to near zero. Artificial intelligence tools can now deliver convincing video interview performances and fabricate government-issued IDs. That same technology makes it
Share
Copy Link
North Korean hackers generated over $5 million by placing fraudulent employees created using generative AI inside more than 100 US companies. These synthetic insiders use deepfake video, audio, and stolen identities to bypass traditional security checks, accessing sensitive systems and data. The attacks highlight how AI cyberattacks are transforming corporate cyber defence strategies.
The US Justice Department uncovered a sophisticated scheme in June 2024 that exposed a new frontier in cyber threats: North Korean hackers had successfully placed fraudulent employees created using generative AI inside more than 100 US companies. Using stolen identities of over 80 American citizens, these synthetic insiders generated more than $5 million in illicit revenue for the North Korean government, which operates under UN sanctions
1
. The case involved eight US-based individuals sentenced for hosting "laptop farms"—physical collections of laptops that allowed fake employees to appear as if they were working from America while actually operating from overseas1
.
Source: PYMNTS
These AI cyberattacks represent a dramatic escalation in insider threat tactics. According to Verizon's 2026 analysis covering over 22,000 incidents across 145 countries, 12 per cent of confirmed breaches globally were carried out by internal actors
1
3
. What makes these attacks particularly devastating is that legitimate employees know exactly where sensitive data resides and how to access it without triggering conventional security alerts.Cloudflare's 2026 threat report identified three North Korean hacking groups, including PutridSlug, that have "industrialized" the use of generative AI to conduct sophisticated attacks
2
. In 2025, PutridSlug used AI-generated deepfake employees with convincing video and audio to pose as company executives during Zoom calls, tricking tech employees into downloading malicious code that enabled financial theft2
. "We have officially crossed the threshold where a live video call is no longer proof of life," says David Warburton, director of the threat intelligence arm at security group F52
.
Source: FT
The economics behind these attacks have fundamentally shifted. AI has "changed attacker economics" by making it cheaper and easier to carry out sophisticated attacks, according to Matthew Lloyd Davies, principal cyber security author at Pluralsight
2
. Generative AI has lowered the cost of building a fake employee identity to near zero, enabling attackers to generate convincing video interview performances, fabricate government-issued IDs, create fake resumes, and build portfolio websites that support entirely fabricated work histories3
.For financial institutions, the primary concern extends beyond immediate fraudulent transactions. The real danger lies in unauthorized access to critical systems that control fraud detection models, payment architectures, customer records, and internal controls
3
. A Kaspersky report from April 2026 found that more than 1 million banking accounts at the world's 100 largest banks were compromised by infostealers in 2025, with 74 per cent of stolen payment card numbers remaining valid as of March 2026 .What makes insider incidents particularly damaging is not their frequency but their dwell time—the period during which attackers operate undetected. Access that appears legitimate at every layer does not trigger controls built to detect illegitimate access. Remote administration tools such as AnyDesk and TeamViewer allow operators to run company-issued devices from overseas, a tactic that has become a hallmark of these schemes
3
.Related Stories
Data from security group DeepStrike shows phishing attacks rose by 1,265 per cent in 2025, attributed directly to the growth of generative AI tools
2
. By scraping data from LinkedIn, company websites, and public filings, attackers generate hyper-personalized phishing campaigns that are far more convincing than the clumsy, error-laden emails of the past. "Attackers know your organisational chart, your vendors and your executives' communication styles before they send a single message," says Douglas Wadkins, chief technology officer at network group Opengear2
.Companies are responding by fundamentally restructuring their approach to corporate cyber defence. Adam Finkelstein, a managing director at Alvarez & Marsal, notes that companies are "tightening the connection between HR, security, legal, compliance and IT" because treating hiring as mainly an HR process "is no longer sufficient for high-risk remote technical roles"
1
. Tom Hegel, a senior threat researcher at SentinelOne, emphasizes that companies should use deepfake detection tools that screen metadata, IP addresses, and device fingerprints at the application stage, while also watching for signs that candidates are using AI software to alter their face and voice in real time1
.Beyond external threats, organizations face rising concerns about shadow AI—the use of AI models by staff that have not been approved by employers and might inadvertently share sensitive data
1
. John Hultquist, chief analyst at Google Threat Intelligence Group, warns that as AI gains more agentic capabilities, companies must consider that bots themselves might go rogue or accidentally expose data, since an AI agent "operates in a similar way to an employee"1
.The data loss prevention market has expanded rapidly in response to these threats, growing from $33 billion in 2025 to nearly $43 billion in 2026, according to Mordor Intelligence
1
. Organizations are deploying behavioral monitoring systems that track whether working hours, location data, and activity patterns match the profile of the employee who was hired3
. Some companies concerned about fake identities now use liveness detection systems that analyze "subtle biological signals such as micro-texture variations and the way light reflects off the face" to confirm authenticity2
. Research from PYMNTS Intelligence conducted with Trulioo indicates that outdated identity controls are costing businesses nearly $100 billion annually in fraud, with nearly 90 per cent of enterprises identifying bot management as a major challenge3
.Summarized by
Navi
1
Technology

2
Technology

3
Policy and Regulation
