The ‘Synthetic Insider’: AI Deepfakes and Fake Employees
AI has made it cheap to fake a face, a voice, and a CV. That has handed companies a new nightmare: the "synthetic insider," a fraudulent employee who talks their way through the front door.
July 20, 2026 – 12:28 pm
Image by: piranka / Canva
The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.”
The tactic sits at the sharp end of an old problem. Insider threats run from a worker emailing the wrong file to a thief who knows exactly where the valuables are. A 2026 analysis of about 22,000 incidents by Verizon found 12% were the work of internal actors, the Financial Times reported.
The deliberate ones do the most damage. “They know where the crown jewels are and how to access them,” said Alex Lisle, chief technology officer at deepfake-detection firm Reality Defender.
The Fake Employee
The clearest example is a North Korean scheme the US Justice Department cracked down on last year. Operatives fraudulently landed remote jobs at US firms. The goal was to earn wages and steal data for the sanctioned regime. They used the stolen identities of more than 80 Americans to get hired at over 100 companies, the government said. That raised more than $5m for Pyongyang. Eight US-based people were later sentenced for running “laptop farms.” These are racks of computers in American homes that made overseas workers look local.
Cheap deepfake tools make this easier. Attackers can now fake live video and audio, not just a photo. That lets them sail through a video interview as someone else.
Catching Them at the Door
The fix starts with hiring. Companies are knitting together HR, security, legal, and IT, said Adam Finkelstein of consultancy Alvarez & Marsal. Treating recruitment as a pure HR task, he argued, “is no longer sufficient for high-risk remote technical roles.”
Tom Hegel, a threat researcher at SentinelOne, said firms should screen metadata, IP addresses, and device fingerprints when an application lands. They should also watch for candidates altering their face or voice in real time. Some defences are low-tech. Asking a candidate to turn their head or wave a hand can still break a live deepfake, he said.
The checks continue after the hire. Firms should make sure new laptops are not shipped to a farm. Then they can use behaviour analytics to flag odd activity.
Most leaks are accidents
The headline-grabbing plots are the exception. “Insider threats are far more likely to happen by accident,” said Dave Spillane of Fortinet. A 2025 report from the firm blamed 62% of incidents on human error or hijacked accounts. That covers everything from emailing the wrong file to pasting secrets into an unsanctioned chatbot.
That last habit has a name: shadow AI. Staff feed sensitive data into AI tools their employer never approved, said John Hultquist of Google Threat Intelligence Group.
The next worry is the software itself. As AI agents gain the power to act, they start to look like staff.