The most dangerous person in your company might not work there at all. AI deepfakes are getting cheaper and better. Hackers now use them to pose as trusted staff, a threat the industry calls the “synthetic insider.”

The tactic sits at the sharp end of an old problem. Insider threats run from a worker emailing the wrong file to a thief who knows exactly where the valuables are. A 2026 analysis of about 22,000 incidents by Verizon found 12% were the work of internal actors, the Financial Times reported.

The deliberate ones do the most damage. “They know where the crown jewels are and how to access them,” said Alex Lisle, chief technology officer at deepfake-detection firm Reality Defender.

The clearest example is a North Korean scheme the US Justice Department cracked down on last year. Operatives fraudulently landed remote jobs at US firms. The goal was to earn wages and steal data for the sanctioned regime.

They used the stolen identities of more than 80 Americans to get hired at over 100 companies, the government said. That raised more than $5m for Pyongyang. Eight US-based people were later sentenced for running “laptop farms.” These are racks of computers in American homes that made overseas workers look local.