Deepfake hiring insurance fraud and shadow AI use are…
The 2024 KnowBe4 incident illustrates how synthetic insiders using AI-generated identities shift fraudulent hiring from an HR failure to a complex cyber event
- Incident date
- Jan 2024
- Target
- KnowBe4
In early 2024, an incident involving KnowBe4 highlighted the rapid escalation of security threats posed by synthetic insiders. This event demonstrated how a fraudulent hire can transition from an initial human resources failure to a significant cyber security event once the individual gains network access.
What happened
The incident serves as a case study for the risks associated with synthetic insiders—fraudsters who utilize AI-generated photos, video, or voice to impersonate candidates and successfully navigate organizational onboarding processes. In this scenario, the attacker leveraged a fake identity to secure employment, effectively bypassing standard hiring controls. Once onboarded, the individual gained internal network access, shifting the nature of the event from a recruitment error to a potential data breach or malware risk. This incident underscores the difficulty insurers and organizations face in categorizing such events, as the resulting losses often blur the lines between cyber policy coverage and traditional crime insurance. Because the attacker gained access as a recognized employee, the subsequent investigation forced a complex analysis of failed identity verification standards and the gaps between written security procedures and actual daily operational behavior.