"That New Hire on Your Zoom Call Might Be a Deepfake"
A North Korean operation recently placed fake IT workers inside Western companies using AI-generated faces, stolen résumés, and deepfake video interviews. One scheme netted over $5 million. Another fake developer reportedly sat inside a defense contractor for 11 months — long enough to touch nuclear submarine data — before anyone noticed. The cybersecurity industry now has a name for this: the "synthetic insider."
The mechanics are disturbingly simple. Generative AI tools have made it cheap and fast to produce convincing deepfake video, audio, and identity documents at scale. Remote work, which normalized the idea that you might never meet your colleagues in person, did the rest. Combine those two trends with recruiters under pressure to fill roles quickly, and you get a hiring pipeline that can be gamed with a few hundred dollars' worth of AI tooling. As Adam Finkelstein of Alvarez & Marsal put it, companies historically treated hiring as "mainly an HR process" — not a security one. That assumption is now breaking.
The scale of the insider threat, however, is more nuanced than the headlines suggest. Verizon's 2026 Data Breach Investigations Report found that internal actors appeared in 12% of breaches — down from 18% the year before. Most of those weren't deepfake spies; they were accidents. Misconfigured databases, emails sent to the wrong person, lost laptops. The synthetic insider is a real and growing problem, but it sits atop a much larger pile of mundane human error that companies still haven't solved.
What makes the synthetic insider uniquely dangerous isn't the technology — it's how it exploits a structural blind spot. Companies have spent decades building security perimeters against external attackers while treating anyone inside as trusted. Background checks, the traditional gatekeeper, were designed for an era when identity fraud meant a fake diploma or an embellished job title. They were never built to catch a real-time deepfake on a video call. The fix, security researchers say, is low-tech as much as high-tech: cross-functional hiring panels that include security and IT, metadata screening on interview recordings, and the surprisingly effective "move your hand across your face" check that breaks most real-time deepfake renderers.
Beyond the hiring stage, a subtler risk is emerging. As AI agents gain access to company systems — reading email, querying databases, executing workflows — they become a new class of insider by design. An AI agent with legitimate credentials is harder to profile than any human employee because it has no behavioral baseline. It does exactly what it's told, which is precisely the problem. The same tools we're racing to deploy for productivity may turn out to be the next frontier of insider risk, and nobody has a playbook for that yet.
Sources: The Next Web, Financial Times, Verizon 2026 DBIR, LMG Security, Blacksmith Infosec
Comments
pogchamp wait so that guy was a deepfake the whole time?? 11 months on the job touching nuke subs 💀 chat surely this is fine
@sleepyCamper63 11 months collecting a paycheck AND touching nuclear data? thats a power move not a security breach. maybe companies should level up their KYC instead of crying about getting outplayed 🤷
Leave a Comment