• 3 min read
AI deepfakes made fake employees a real corporate threat
Cheap AI deepfakes are helping criminals pose as employees, turning hiring into a frontline security risk for companies.

Image: TNW
The most dangerous insider at a company may not be an employee at all. Security researchers now use the term “synthetic insider” for attackers who use AI deepfakes to pose as trusted staff, slipping into hiring pipelines and corporate systems with convincing fake identities.
The threat builds on a longstanding security problem. A 2026 Verizon analysis of about 22,000 incidents found 12% involved internal actors, according to the Financial Times. The worst cases are deliberate, not accidental.
“They know where the crown jewels are and how to access them.”
One of the clearest examples came from a North Korean operation the US Justice Department targeted last year. Operatives fraudulently secured remote jobs at US companies using the stolen identities of more than 80 Americans, the government said, and got hired at over 100 companies. The scheme raised more than $5m for Pyongyang. Eight US-based people were later sentenced for operating so-called “laptop farms” — racks of computers in American homes that made overseas workers appear local.

Recommended reading
WordPress bugs are now under attack at scale
Cheap deepfake tools have made those scams easier to run. Attackers can now fake live video and audio, not just profile photos, making it harder to catch them in a video interview.
How companies are trying to catch fake hires
That has pushed hiring into the security stack. Adam Finkelstein of Alvarez & Marsal said companies are increasingly bringing together HR, security, legal, and IT rather than treating recruitment as a pure HR function, especially for high-risk remote technical roles.
Tom Hegel, a threat researcher at SentinelOne, said firms should examine:
- metadata
- IP addresses
- device fingerprints
- signs that a candidate is altering their face or voice in real time
Some checks are simpler. Asking a candidate to turn their head or wave a hand can still disrupt a live deepfake, Hegel said. After hiring, companies should also verify that laptops are not being shipped to a laptop farm and use behaviour analytics to flag suspicious activity.
Shadow AI and the surveillance risk
The headline-grabbing cases are still not the norm. Dave Spillane of Fortinet said insider threats are more often accidental. A 2025 Fortinet report attributed 62% of incidents to human error or hijacked accounts — from sending the wrong file to entering sensitive information into an unapproved chatbot.
That practice has its own label: shadow AI. Employees are feeding confidential data into tools their employers never approved, said John Hultquist of Google Threat Intelligence Group. He also warned that AI agents are beginning to resemble employees with system access, and can be manipulated into taking actions they should not.
Art Gilliland, chief executive of Delinea, said those agents need access to sensitive systems, making their identities just as valuable to attackers as a human worker’s.
The boom in insider-risk concerns is lifting the security market. By one estimate, the market for data-loss prevention grew from $33bn last year to almost $43bn this year. But aggressive monitoring brings its own costs. Some tools log keystrokes and screenshots to detect risky behaviour.
“Too much monitoring can undermine trust. The challenge is protecting the organisation without creating a culture of surveillance.”
Finkelstein also warned against turning nationality, remote-work patterns, or an unusual career history into reasons for suspicion. He said controls should focus on verifiable signals such as odd privilege use or impossible travel. Several experts landed on the same basic rule: give people — and software agents — access only to what they need.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TNW


