tech

‘Synthetic insider’ attacks raise stakes for corporate cyber defence

Simply sign up to the Cyber Security myFT Digest -- delivered directly to your inbox.

‘Synthetic insider’ attacks raise stakes for corporate cyber defence

TL;DR

  • North Korean citizens infiltrated US companies by fraudulently gaining employment as remote workers, using stolen identities to earn money and steal data.
  • Eight US-based individuals were sentenced for hosting 'laptop farms' to mask the true location of fake remote employees.
  • The proliferation of AI tools, creating 'synthetic insiders' with deepfake capabilities, facilitates sophisticated insider attacks.
  • Companies are enhancing security by tightening collaboration between HR, security, legal, compliance, and IT, and using identity-verification and deepfake-detection tools.
  • Insider threats can also occur through human error or compromised accounts, with incidents costing businesses significant amounts.
  • The use of unapproved AI models ('shadow AI') by staff poses a risk of inadvertently sharing sensitive data.
  • The data loss prevention market is growing significantly due to rising risks and regulatory penalties.
  • Balancing organizational protection with employee trust is a key challenge, avoiding excessive monitoring that can undermine morale.