Markets Closed
Global Markets
S&P 500 7,443.28 ▼ -0.2% DOW 51,839.26 ▼ -0.6% NASDAQ 25,508.07 ▼ -0.0% RUSSELL 2K 2,942.43 ▼ -0.7% VIX 17.52 ▼ -6.1% GOLD 4,067.3 ▲ +1.4% CRUDE OIL 82.42 ▼ -1.0% EUR/USD 1.14 ▼ -0.0% BTC 66,167 ▲ +3.4% ETH 1,937.51 ▲ +4.3%
Fintech

Banks face rising risk from synthetic insider hiring schemes

AI-enabled fake worker identities are challenging bank controls by turning approved employee access into a channel for data theft and espionage.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

Banks face rising risk from synthetic insider hiring schemes
Photo: PYMNTS

Banks and other financial firms are confronting a form of insider risk in which the login, device and employment record can appear valid while the worker behind them is fraudulent. Cloudflare said in its 2026 Threat Report that generative AI has made it far cheaper to build synthetic employee identities that can pass interviews, background screening and account onboarding.

The financial impact can extend beyond direct theft. A person hired under a false identity may obtain approved access to payment systems, fraud models, customer files, pricing data, merchant records and internal controls. That access can allow information to be copied or studied before a visible attack occurs.

Cloudflare reported that AI tools can support convincing video interview performances, fabricated identification documents, resumes, portfolio sites and writing samples. The result is a hiring process in which several conventional checks may be satisfied even though the company has not verified the real operator of the account.

A U.S. Department of Justice case in April 2026 illustrated the scale of the issue. The department said two U.S. residents were sentenced for helping place fraudulent remote information technology workers inside more than 100 U.S. companies, using the stolen identities of more than 80 Americans. TechCrunch reported that the operation generated more than $5 million for the North Korean government. The Justice Department announcement did not say whether affected companies detected the activity through internal security alerts.

Why access matters in financial services

In banking, the immediate concern is often the data and system knowledge that supports the movement of money, rather than a single attempted transfer. A worker with sanctioned credentials can view systems in ways that do not resemble an external intrusion. Reading records or observing workflows may not trigger the same alarms as malware, credential stuffing or unauthorized network entry.

Kaspersky said in an April 2026 financial threat report that more than 1 million banking accounts at the world’s 100 largest banks were compromised by infostealers in 2025. The company also found that 74% of stolen payment card numbers remained valid as of March 2026, indicating that stolen financial identity data can retain value for months after compromise.

Verizon’s 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches across 145 countries, found that internal actors appeared in 12% of confirmed breaches. Verizon said that was down from 18% a year earlier. The report did not separately measure synthetic-insider schemes, so the figure should be read as a broader indicator of insider involvement rather than a specific count of fake-employee cases.

Remote work tools widen the verification gap

Cloudflare said traditional background checks and standard identity verification are under pressure from attackers who design schemes to pass those controls. Skadden reported in a June 2026 publication that remote administration tools such as AnyDesk and TeamViewer have been used in North Korean remote IT worker schemes, allowing operators to control company-issued devices from other locations.

The same identity problem is visible in other digital channels. PYMNTS Intelligence, in research with Trulioo, said outdated identity controls cost businesses nearly $100 billion a year in fraud. The research also found that nearly 90% of enterprises view bot management as a major challenge. That work focused on bot traffic and AI agent activity in digital commerce, rather than hiring fraud, but it points to a shared control problem: confirming an identity at enrollment does not necessarily prove who or what later uses the credential.

Controls aimed at synthetic insiders increasingly look beyond whether a password, badge or device is valid. They assess behavioral signals such as working hours, location data and activity patterns, and compare them with the profile of the employee the company believes it hired. For banks, the risk sits in the gap between a verified identity and the operator using that identity after access has been granted.

This story draws on original reporting from PYMNTS.

More from Fintech

All Fintech →