Multiple outlets report that cybercriminals increasingly use AI-generated deepfakes to impersonate trusted employees, a tactic sometimes referred to as a “synthetic insider.” The approach leverages the growing accessibility and improving quality of AI deepfakes to create actors who can appear to be staff members during communications and other internal interactions.
The Financial Times highlights that these attacks raise the stakes for corporate cyber defense, framing the threat as an extension of longstanding insider-related risks, including breaches carried out through internal accounts or trusted relationships. The Next Web focuses on how the “fake employee” concept works as a corporate threat, emphasizing that the most damaging person may be external yet appear internal.
Both sources describe the key challenge for organizations: distinguishing real employees from AI-generated or manipulated identities when attackers adopt trusted roles to gain access, influence decisions, or move within company systems. As a result, the reporting suggests organizations must treat impersonation and internal security processes as evolving risk areas, not static issues confined to known insider behaviors.