
For years, organisations have viewed insider threats as a problem that begins once someone has joined the business. Whether it’s a malicious employee, a compromised account or an accidental data leak, the assumption has always been that the insider is already on the inside.
That assumption is beginning to change. Advances in generative AI are making it easier for attackers to create convincing fake identities, manipulate video interviews and secure legitimate employment under false pretences. As the Financial Times recently reported, so-called “synthetic insiders” are becoming an emerging concern for organisations hiring remotely, particularly for roles with access to sensitive systems and data.
The tactic is not entirely new. Authorities in the US have spent several years investigating North Korean IT worker schemes, in which operatives used stolen or fabricated identities to obtain remote jobs at Western companies. What has changed is the speed and scale at which AI can now generate realistic CVs, profile photos, voices and even live video, making fraudulent candidates far more difficult to detect.
For security leaders, this means the recruitment process is increasingly becoming part of an organisation’s cyber-defence. HR teams have traditionally focused on assessing a candidate’s skills and experience, while security became involved once access to corporate systems was granted. That distinction is becoming harder to maintain.
Some organisations are introducing additional identity verification during recruitment, including enhanced background checks, document verification and closer collaboration between HR, IT and security teams. Rather than treating hiring as a standalone business function, organisations are beginning to recognise it as another point where attackers may attempt to gain legitimate access.
The challenge does not end once someone is hired. The same security principles used to manage insider risk still apply, including least-privilege access, continuous monitoring and regular reviews of user permissions. Guidance such as NIST’s Digital Identity Guidelines and Zero Trust Architecture emphasises verifying identities and limiting access to only what users require, reducing the impact if an account is later compromised.
While deepfakes and AI-generated identities are attracting significant attention, experts caution against relying solely on technology to identify suspicious candidates. Recruitment teams remain an important first line of defence, particularly when supported by security teams that can verify identities, investigate anomalies and respond quickly when something does not look right.
Synthetic insiders are unlikely to replace traditional insider threats, but they do expand the definition of what an insider looks like. As AI continues to reshape identity fraud, organisations may find that protecting their networks starts long before an employee logs in for their first day.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543