A wave of cyberattacks carried out by fraudulent employees, rather than external hackers, is forcing insurers to confront a claims category that doesn't sit neatly inside either a cyber or a crime policy.
Security researchers have coined the term "synthetic insider" for the trend, in reporting by the Financial Times this week: attackers who use AI-generated deepfake images, video and voice to pose as trusted staff or job candidates, then exploit that trust from inside a company's own network. The clearest example remains North Korea's fraudulent IT-worker scheme, in which operatives used stolen American identities to land remote technical jobs at more than 100 US companies, generating over $5 million for the sanctioned regime before a Justice Department crackdown last year. Earlier FT reporting found the tactic has since spread to Europe as well, with UK-based "laptop farms" letting overseas operatives appear to log in from inside the country.
For risk managers, the more pressing question isn't whether this is happening — it plainly is — but where the resulting losses actually land on the policy schedule.
Deepfake-enabled fraud has repeatedly exposed what brokers describe as a "pass-the-parcel" problem between cyber and crime cover. As one broker interviewed by Insurance Business UK put it, social engineering cover inside a cyber policy is often sublimited — capped at a fraction of the overall limit — because insurers still treat the loss as fundamentally a crime exposure wearing a cyber wrapper.
That ambiguity applies just as much to a fake employee as to a spoofed wire-transfer instruction. If a fraudulent hire is detected before any system access occurs, it may not trigger a cyber policy at all. If the same operative gains network access and exfiltrates data or plants malware — as happened in cybersecurity vendor KnowBe4's well-publicized 2024 incident — the loss profile shifts toward a conventional breach response, but questions about who authorized the hire, and under what verification standard, can still complicate an employment-practices or crime claim running in parallel.
US carriers have been adjusting policy language in response. Some insurers now specifically define their social engineering extensions to capture AI-assisted impersonation, according to sources cited in Insurance Business's coverage of AI-driven fraud and cyber insurance — though many of those same policies build in authentication or callback requirements that can be difficult for employees to satisfy consistently in practice, creating a new source of claims friction. Separately, Insurance Business has reported that cyber carriers have generally been reinforcing rather than retreating from AI-related coverage, even as insurers in other lines grow more cautious about AI exposure generally.
Independent data suggests insider-driven losses are a persistent, if secondary, share of the overall breach picture. Verizon's 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, found internal actors were involved in 12% of them — down from 18% the prior year, but still a meaningful slice given the scale of the dataset. More striking for underwriters is Verizon's "shadow AI" finding: 45% of employees are now regular users of AI tools on corporate devices, up from just 15% a year earlier, and 67% of that usage runs through non-corporate accounts that bypass whatever controls a company has in place. Shadow AI use is now the third most common category of non-malicious insider data-loss event Verizon tracks, a fourfold increase year over year.
Fortinet's 2025 Insider Risk Report points the same way: 62% of insider incidents stemmed from human error or compromised accounts rather than deliberate misconduct, and nearly three-quarters of the security leaders it surveyed admitted they lack full visibility into how staff interact with sensitive data across endpoints, SaaS tools and generative AI platforms. Separate research attributed to the Ponemon Institute puts the average cost of a North American insider incident at approximately $22.2 million in 2025 — a figure I'd recommend verifying against Ponemon's own report before publication, since it reached me via a secondary summary rather than the primary source — but even directionally it's a number underwriters are factoring into limits and retentions for accounts with large remote or contractor workforces.
Taken together, the data suggests deliberate, state-sponsored infiltration like the North Korean scheme is a high-severity but comparatively low-frequency exposure, while everyday negligence and shadow AI use represent the higher-frequency, still-costly baseline risk that most insider-related claims will actually come from.
A few practical implications follow for the US cyber and crime markets:
As deepfake tools get cheaper and easier to use, the distinction between "insider threat" and "external attacker" is set to keep blurring — and coverage built around that older distinction will need to keep catching up.