The account is real. The credentials are real. The employee is not. Synthetic insiders use stolen identities, deepfake technology and remotely controlled devices to get hired, pass background checks and log in through approved accounts: access that looks legitimate because it is legitimate. The person operating it is not who the company believes it hired.

Generative AI is what makes that impersonation possible at scale. It has lowered the cost of building a fake employee identity to near zero. Artificial intelligence tools can now deliver convincing video interview performances and fabricate government-issued IDs. That same technology makes it simple to generate fake resumes, portfolio websites and writing samples that backup a fabricated work history, Cloudflare reported in its 2026 Threat Report.

A Department of Justice case in April 2026 showed what that looks like at scale: two U.S. residents were sentenced for running operations that placed fraudulent workers inside more than 100 U.S. companies using the stolen identities of more than 80 Americans, generating more than $5 million for the North Korean government, TechCrunch reported. DOJ’s announcement does not specify whether the scheme triggered internal security alerts at the affected companies.

The immediate risk from synthetic insiders in financial services is not a fraudulent wire transfer. It is access to the systems that make wire transfers possible. A worker with approved access can reach fraud detection models, payment flow architectures, customer records, pricing data, merchant information and internal controls. That information does not trigger an alert when it is read. It gets copied and studied over months before anything visible happens. Kaspersky found in an April 2026 report that more than 1 million banking accounts at the world’s 100 largest banks were compromised by infostealers in 2025, with 74% of stolen payment card numbers remaining valid as of March 2026. The shelf life of stolen identity data extends months past the breach.

That shelf life matters most when the access came from inside the company. Internal actors appeared in 12% of confirmed breaches analyzed in Verizon’s 2026 Data Breach Investigations Report, which covered more than 22,000 confirmed breaches across 145 countries, Verizon reported. That figure is down from 18% the prior year. The decline reflects overall insider-breach frequency, not the sophistication of synthetic-insider schemes specifically, which are not broken out separately in the report. What makes insider incidents particularly damaging is not their frequency but their dwell time. Access that looks legitimate at every layer does not trigger the controls built to detect illegitimate access. By the time the activity is flagged, the information has often already left.