A new insider-threat pattern is reshaping how security teams think about access risk: the “synthetic insider.” In these cases, the account is real, the credentials are real, and the employee is not. Attackers are using stolen identities, deepfake video, and remotely controlled devices to pass interviews and background checks, then logging in through fully approved accounts.
What makes this different from a typical insider threat is that the access looks completely legitimate at every layer, because it is legitimate. The person behind the account is simply not who the company believes it hired.
Generative AI Lowered the Barrier to Entry
Generative AI has cut the cost of building a convincing fake employee identity to near zero. Tools capable of producing realistic video interview performances and fabricated government-issued IDs are now widely available. The same technology can generate supporting materials such as fake resumes, portfolio websites, and writing samples that back up an invented work history.
A U.S. Department of Justice case from April 2026 illustrated how this can operate at scale, involving fabricated identities used to secure legitimate employment and system access.
Why Dwell Time Is the Real Risk
Security controls are largely built to flag illegitimate access, not access that passes every formal check. That is what makes synthetic insider schemes hard to detect quickly. The longer a fabricated identity operates undetected inside a network, the more damage it can do, regardless of how the initial access was obtained.
What the Data Shows
Verizon’s 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches across 145 countries, found that internal actors were involved in 12 percent of confirmed breaches, down from 18 percent the year before. That decline reflects a broader drop in insider-breach frequency overall. The report does not separately break out synthetic-insider schemes, so the figure should be read as context for the insider-threat landscape rather than a direct measure of how common AI-generated fake employees have become.
The Bigger Picture
Synthetic insider attacks sit at the intersection of two trends security teams have tracked separately for years: identity fraud during hiring, and insider access risk once someone is inside the organization. As generative AI tools continue to improve, the line between “verified” and “genuine” identity is becoming harder for HR and security processes to draw with confidence.
Leave a Reply