Insurance
Home›Insurance›Health Insurance›Insurers face “synthetic insider” AI impersonation los…
Insurers face “synthetic insider” AI impersonation losses
Researchers say fraudulent “synthetic insider” attacks use deepfake images, video, and voice to pass as trusted staff, complicating whether claims fall under cyber or crime coverage.
Security researchers say a growing wave of cyberattacks is being carried out by people posing as insiders, rather than traditional external hackers, forcing insurers to rethink how such incidents are covered. The Financial Times this week described the emerging pattern as “synthetic insider” activity, where attackers use AI-generated deepfakes to impersonate trusted employees or job candidates and exploit that access from within a company’s own network.
A widely cited example involves North Korea’s fraudulent IT-worker scheme, in which operatives used stolen American identities to land remote technical jobs at more than 100 US companies. That activity generated over $5 million for the sanctioned regime before a Justice Department crackdown last year, and the tactic has since spread to Europe, including UK-based “laptop farms” used to make overseas operatives appear to be logging in from within the country.
For insurers, the main issue is not whether the tactic is occurring, but where losses are supposed to land on policy schedules. Insurance Business UK notes a “pass-the-parcel” problem between cyber and crime cover, where social engineering protection within a cyber policy can be sublimited because insurers still treat the underlying loss as a crime exposure rather than a cyber event.
The article adds that attackers can also shift the claims profile depending on whether access is detected early. If a fraudulent hire is caught before system access occurs, a cyber policy may never be triggered, while deeper intrusion, data exfiltration, or malware planting can move the response toward a conventional breach process, potentially while employment-practices or crime claims run in parallel. US carriers are updating policy language, with some specifically defining social engineering extensions to include AI-assisted impersonation, while other policies require authentication or callback steps that can be difficult to meet in practice.