KnowBe4: Fake AI workers behind numerous cyber attacks, researchers find

KnowBe4: Fake AI workers behind numerous cyber attacks, researchers find

Rise of "Synthetic Insiders" and Shadow AI Reshape Cybersecurity Risks for Businesses

A growing wave of insider-driven cyber threats fueled by AI and remote work vulnerabilities is forcing insurers and businesses to rethink risk exposure. Recent reports highlight three key trends: the rise of "synthetic insiders," the financial toll of insider incidents, and the rapid adoption of unsanctioned AI tools in corporate environments.

AI-Powered Impersonation and State-Sponsored Schemes
Attackers are increasingly using AI-generated deepfakes to pose as trusted employees or job candidates, a tactic researchers term "synthetic insiders." The most high-profile example remains North Korea’s fraudulent IT worker scheme, where operatives used stolen identities to secure remote roles at over 100 U.S. companies, funneling $5 million to the regime before a 2023 Justice Department crackdown. The Financial Times reports the tactic has since spread to Europe, with UK-based "laptop farms" enabling overseas operatives to appear as local hires.

While state-sponsored infiltration remains a high-severity risk, it accounts for a smaller share of incidents compared to human error and negligence. Verizon’s 2026 Data Breach Investigations Report found internal actors were involved in 12% of breaches down from 18% the prior year but still a significant factor given the scale of modern cyberattacks.

Shadow AI and Uncontrolled Data Access
A more pervasive threat comes from "shadow AI": employees using unsanctioned AI tools on corporate devices. Verizon’s data shows 45% of employees now regularly use AI tools, up from 15% a year ago, with 67% of that usage occurring through non-corporate accounts that bypass security controls. This unchecked adoption has made shadow AI the third most common cause of non-malicious insider data loss, quadrupling year-over-year.

The financial impact is substantial. The Ponemon Institute estimates the average cost of a North American insider incident at $22.2 million in 2025, a figure insurers are factoring into policy limits and retentions particularly for organizations with large remote or contractor workforces. Yet, 73% of security leaders admit they lack full visibility into how staff interact with sensitive data across endpoints, SaaS platforms, and generative AI tools.

Insurance Gaps and Coverage Disputes
The blurring line between insider threats and external attacks is complicating cyber insurance claims. Deepfake-enabled fraud has exposed a "pass-the-parcel" problem between cyber and crime policies, with disputes arising over whether losses fall under social engineering extensions, fraudulent instruction coverage, or employment practices liability. Some insurers are now explicitly defining AI-assisted impersonation in policy language, but gaps remain especially when verification failures or lax hiring processes are involved.

For example, if a fraudulent hire is detected before gaining system access, it may not trigger a cyber policy at all. But if the operative exfiltrates data or deploys malware as in KnowBe4’s 2024 breach the loss profile shifts, potentially triggering multiple policies with overlapping exclusions. Insurers are also scrutinizing whether companies meet authentication requirements, as AI tools make impersonation harder to detect.

Underwriting and Risk Mitigation Shifts
The data suggests that while nation-state infiltration grabs headlines, everyday negligence and shadow AI represent the higher-frequency, high-cost baseline risk. Insurers are adjusting underwriting questions to address AI governance and data-handling practices, rather than focusing solely on high-profile espionage cases. Brokers recommend that organizations with significant remote hiring explicitly confirm whether AI-enabled impersonation is covered under cyber or crime policies and at what sublimit.

Access-based controls remain the most effective mitigation, reducing both the frequency and severity of insider-driven losses. As deepfake tools become cheaper and more accessible, the distinction between insider threats and external attacks will continue to erode, requiring policies to evolve alongside the risks.

Source: https://www.insurancebusinessmag.com/us/news/cyber/fake-ai-workers-behind-numerous-cyber-attacks-researchers-find-583095.aspx

KnowBe4 cybersecurity rating report: https://www.rankiteo.com/company/knowbe4

"id": "KNO1784637351",
"linkid": "knowbe4",
"type": "Breach",
"date": "1/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'United States',
                        'name': 'Over 100 U.S. companies',
                        'type': 'Corporations'},
                       {'location': 'United Kingdom',
                        'name': 'UK-based companies',
                        'type': 'Corporations'},
                       {'industry': 'Cybersecurity',
                        'name': 'KnowBe4',
                        'type': 'Company'}],
 'attack_vector': ['Deepfake Impersonation',
                   'Fraudulent Hiring',
                   'Unsanctioned AI Tools'],
 'data_breach': {'data_exfiltration': 'Yes (in KnowBe4’s 2024 breach)'},
 'description': 'A growing wave of insider-driven cyber threats fueled by AI '
                'and remote work vulnerabilities is forcing insurers and '
                'businesses to rethink risk exposure. Recent reports highlight '
                "three key trends: the rise of 'synthetic insiders,' the "
                'financial toll of insider incidents, and the rapid adoption '
                'of unsanctioned AI tools in corporate environments.',
 'impact': {'financial_loss': '$22.2 million (average cost of North American '
                              'insider incident in 2025)'},
 'initial_access_broker': {'entry_point': 'Fraudulent IT worker hiring'},
 'lessons_learned': 'The distinction between insider threats and external '
                    'attacks is eroding due to AI-powered impersonation and '
                    'shadow AI. Access-based controls and AI governance are '
                    'critical for mitigation.',
 'motivation': ['Financial Gain', 'Espionage', 'Data Exfiltration'],
 'post_incident_analysis': {'corrective_actions': ['AI governance',
                                                   'Access-based controls',
                                                   'Enhanced monitoring'],
                            'root_causes': ['AI-powered impersonation',
                                            'Lax hiring processes',
                                            'Unsanctioned AI tool usage']},
 'recommendations': ['Explicitly confirm coverage for AI-enabled impersonation '
                     'under cyber or crime policies.',
                     'Implement stricter hiring verification processes.',
                     'Enhance visibility into employee interactions with '
                     'sensitive data and AI tools.',
                     'Adopt access-based controls to reduce insider-driven '
                     'losses.'],
 'references': [{'source': 'Verizon’s 2026 Data Breach Investigations Report'},
                {'source': 'Ponemon Institute'},
                {'source': 'Financial Times'}],
 'response': {'law_enforcement_notified': 'Yes (2023 Justice Department '
                                          'crackdown)'},
 'threat_actor': ['North Korean Operatives',
                  'State-Sponsored Actors',
                  'Negligent Employees'],
 'title': "Rise of 'Synthetic Insiders' and Shadow AI Reshape Cybersecurity "
          'Risks for Businesses',
 'type': ['Insider Threat', 'AI-Powered Impersonation', 'Shadow AI'],
 'vulnerability_exploited': ['Remote Work Vulnerabilities',
                             'Lax Hiring Processes',
                             'Lack of AI Governance']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.