Do you really know who is on your payroll?
Synthetic identities, cloned voices and deepfake videos are helping fraudsters infiltrate organizations from within.
The evolving landscape of remote work has ushered in a new challenge for businesses worldwide: the growing threat of "deepfake employees." As companies increasingly adopt fully remote models, the ability to physically verify the identities of new hires has diminished, giving rise to a sophisticated form of fraud that leverages AI technology.
Threat actors are creating synthetic identities, using voice cloning, and deploying real-time deepfake video to pass through hiring processes and secure legitimate employment. This emerging risk is proving difficult to detect, as deepfake candidates can appear convincing during video interviews, answer questions fluently, and provide credentials that seem legitimate.
The deception often remains undetected until it is too late, when the presence of the fabricated individual within the organization starts to raise suspicions. Real-world examples demonstrate the feasibility of this threat. In a recent experiment, a cybersecurity expert successfully created deepfake personas, including a white man resembling himself and an Asian woman, and used these personas to secure two separate tech roles without being identified as fake candidates.
Advanced AI tools enabled these synthetic identities to progress through interview stages undetected, using fabricated credentials, real-time voice modulation, and live deepfake video. Cloudflare's latest threat research underscores the scale and sophistication of this phenomenon. Fraudulent "remote worker" operations are increasingly utilizing fabricated identities, deepfake-assisted interviews, and remote access "laptop farms" to infiltrate corporate payrolls.
In some cases, multiple individuals are operating under a single employee identity, maintaining persistent access while appearing as a single, legitimate user. Once hired, these actors become insider threats, possessing valid company credentials, devices, and trusted access to sensitive systems. By the time these individuals are identified, they have already gained access to the organization's internal network, blending in with normal business activity.
This highlights the need for a fundamental shift in how organizations approach identity verification. Current assumptions that identity can be verified once and then trusted indefinitely are no longer valid. The virtual environment, where organizations rely heavily on screen names, login credentials, and video, creates a significant vulnerability at the point of hire.
A candidate may provide documentation, pass background checks, and complete onboarding, but these initial verification steps are no longer sufficient in the face of synthetic identities. To combat this threat, organizations must adopt continuous identity assurance measures. Rather than relying on static identity checks, businesses must move towards verifying identities continuously throughout an individual's interactions with the organization.
This requires verifying not only who someone is at the moment of hire but also ensuring that the same individual remains authentic throughout their engagement with the company. The solution lies in fused biometric verification, which combines multiple identity signals, such as facial recognition, voice authentication, and behavioral cues, into a layered verification process.
Unlike single-factor methods, fused biometrics provides a more robust defense against deepfake attacks. By validating multiple biometric traits—such as facial characteristics, voice patterns, and behavioral cues—organizations can create a more reliable means of confirming that a real, live human is present during critical interactions, from interviews and onboarding to system access and sensitive transactions.
This continuous verification approach significantly reduces the risk of identity sharing, replacement, or hijacking. Advanced biometric technologies are designed to detect and block attempts to impersonate users through synthetic voices, deepfakes, or manipulated audio and video. These systems are trained on extensive datasets of both genuine and synthetic voice samples, enabling them to identify subtle acoustic differences between natural and artificial voices.
While a single biometric modality may be fooled by sophisticated synthetic inputs, combining multiple modalities makes it significantly more challenging for fraudsters to successfully impersonate an individual. In conclusion, the rise of deepfake employees represents a critical vulnerability in the current identity infrastructure of organizations.
The shift from physical to virtual environments, combined with advancements in AI technology, has created new opportunities for fraudsters to exploit. To mitigate this risk, businesses must transition from static to continuous identity verification, leveraging fused biometric solutions that provide layered protection against deepfake attacks.
By adopting this proactive approach, companies can better safeguard their payrolls and protect against the emerging threat of synthetic identities.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written; read the original for the full account.

