HeadlinesBriefing favicon HeadlinesBriefing.com

Synthetic Insider Attacks Threaten Corporate Cyber Defence

Financial Times Companies •
×

In June 2025 the US Justice Department exposed a North Korea hacking campaign in which citizens fraudulently obtained remote jobs at over 100 US firms, using stolen identities of more than 80 Americans and generating $5mn for the regime. Eight US residents were sentenced for running “laptop farms” that masked the workers’ true locations.

Insider incidents accounted for 12 per cent of 22,000 global breaches in Verizon’s 2026 analysis. Experts such as Alex Lisle of Reality Defender warn that deliberate insider hacks are the most devastating because attackers know where the “crown jewels” reside. The rise of AI‑generated deepfakes — “synthetic insiders” — lets threat actors pose as trusted employees in video and audio, prompting firms to tighten coordination among HR, security, legal and IT.

Accidental insider risk remains dominant: Fortinet’s 2025 report found 62 % of incidents stem from human error or compromised accounts, including misuse of unapproved generative AI tools. The data‑loss‑prevention market grew from $33bn to $43bn this year, but leaders like Bernard Montel of Tenable caution that excessive monitoring can erode trust. The strongest defence, they argue, is limiting unnecessary access to critical systems.