Insurers are running into a harder version of insider risk. Security researchers have started calling this profile a synthetic insider.
The label refers to fraudsters who use AI-generated photos, video or voice to impersonate employees, contractors or job candidates, then work their way inside a company network through normal onboarding.
The North Korean remote IT-worker scheme still the clearest example. In that case, operatives used stolen American identities to secure technical jobs at more than 100 US companies. The scheme generated more than $5 mn for the sanctioned regime before the US Justice Department moved against it last year.
Losses from a fake employee do not fit cleanly inside either a cyber policy or a crime policy. The insurance fraud begins with identity abuse and hiring controls, then shifts into network access, data theft, malware risk or payment fraud, depending on how far the attacker gets.
Deepfake-enabled fraud has already exposed the pass-the-parcel issue between cyber and crime coverage.
Brokers told Insurance Business that social engineering extensions inside cyber policies often carry sublimits, sometimes far below the main cyber limit, because insurers still view the loss as crime exposure dressed in cyber language.
The same uncertainty applies to fraudulent hires. If a fake employee gets caught before accessing systems, a cyber policy might never respond.
If the person enters the network, steals data or plants malware, the claim starts looking like a breach response. KnowBe4’s 2024 incident showed how quickly a fake hire shifts from HR failure to cyber event once the person receives access.
Claims still get messy after that. Insurers will ask who approved the hire, which identity checks failed and whether the employer followed its own verification standards.
AI is rapidly changing the economics of insurance fraud. Creating fake accident photos, forged medical reports, or manipulated claim documents no longer requires technical expertise. A smartphone and a consumer AI app can produce convincing evidence in minutes.
Research by Verisk found that people identify sophisticated AI-generated insurance images with only about 50% accuracy, essentially no better than a coin toss.
The numbers explain why insurers are paying attention.
- 98% of insurers say AI-powered editing tools are driving more digital fraud.
- 99% have already encountered AI-manipulated documents during claims handling.
- Only 32% are highly confident in detecting deepfakes.
- Fewer than 43% are confident verifying digital evidence at scale.
Fraud detection is becoming an AI-versus-AI race, with carriers investing in machine learning, digital forensics, metadata analysis and behavioral analytics to identify manipulated evidence before claims are paid, according to Beinsure.
US insurers have begun rewriting language around social engineering and impersonation. Some policies now refer directly to AI-assisted fraud. The wording helps, but it does not remove friction. Many policies still require callback procedures, dual approval or other authentication steps before coverage applies.
Inside a real company, staff skip steps under pressure, use informal workflows or trust a familiar name on Slack. That gap between written procedure and daily behaviour is now turning into claims friction.
Cyber insurers are generally tightening language rather than pulling away from AI-related coverage. For cyber underwriters, the likely direction is narrower wording, stronger verification conditions and more questions around contractors, remote staff and privileged access.
Fortinet’s report found 62% of insider incidents came from human error or compromised accounts rather than deliberate misconduct. Nearly three-quarters of surveyed security leaders said they lack full visibility into how employees use sensitive data across endpoints, SaaS tools and generative AI platforms.
Verizon’s 2026 Data Breach Investigations Report reviewed more than 22,000 confirmed breaches and found internal actors involved in 12% of them. That share fell from 18% a year earlier, but the volume still matters because insider events tend to blur negligence, credential misuse and malicious access.
Verizon’s shadow AI data looks more worrying for day-to-day exposure. The report found that 45% of employees now regularly use AI tools on corporate devices, compared with 15% a year earlier. It also found 67% of that use runs through non-corporate accounts, outside normal company controls.
Verizon ranked shadow AI as the third most common non-malicious insider data-loss category it tracks, with a fourfold increase year over year.
Ponemon Institute research has been cited as placing the average North American insider incident at about $22.2 mn in 2025. The risk now splits into two tracks. State-backed infiltration, such as the North Korean IT-worker scheme, remains severe but less frequent.
Everyday insider exposure is broader: compromised credentials, sloppy data handling, shadow AI use and weak onboarding checks. Most claims will come from that second group.
For insurers, the synthetic insider problem is less about inventing a new product than fixing the seams between existing policies. Cyber wording needs to deal with access gained through fake employment.
Crime coverage needs clearer treatment of AI impersonation and fraudulent onboarding. Policyholders need verification controls that staff actually follow, not procedures written for an audit folder.
The market has already learned that deepfake fraud does not stay in one coverage box. Synthetic insiders make that lesson harder. They arrive as employees, behave like users and generate losses that look like cyber, crime and operational failure at the same time.









