tech
‘Synthetic insider’ attacks raise stakes for corporate cyber defence
Simply sign up to the Cyber Security myFT Digest -- delivered directly to your inbox.

TL;DR
- North Korean citizens infiltrated US companies by fraudulently gaining employment as remote workers, using stolen identities to earn money and steal data.
- Eight US-based individuals were sentenced for hosting 'laptop farms' to mask the true location of fake remote employees.
- The proliferation of AI tools, creating 'synthetic insiders' with deepfake capabilities, facilitates sophisticated insider attacks.
- Companies are enhancing security by tightening collaboration between HR, security, legal, compliance, and IT, and using identity-verification and deepfake-detection tools.
- Insider threats can also occur through human error or compromised accounts, with incidents costing businesses significant amounts.
- The use of unapproved AI models ('shadow AI') by staff poses a risk of inadvertently sharing sensitive data.
- The data loss prevention market is growing significantly due to rising risks and regulatory penalties.
- Balancing organizational protection with employee trust is a key challenge, avoiding excessive monitoring that can undermine morale.