A manager noticed it was dark outside their teammate’s window. It was the middle of the afternoon where that teammate was supposed to be sitting.
That one small detail unraveled the whole thing.
I have been having a lot of conversations with security leaders lately, and this is the one that keeps coming up. Every person who raises it is convinced they are the only one dealing with it. They are not. At the last event I attended, there were people worried about a version of this in nearly every corner of the room. Financial services especially.
The concern has a name that sounds almost too simple: fake employees. But when you look closely, it is not one problem. It is three, and they share a single root. All three are people who are legitimately authenticated into your environment, holding real permissions, doing something behind that login that you never actually approved.
That is insider threat. And it is quietly becoming one of the most relatable problems in fintech and healthcare right now.
Flavor one: the hire whose whole job is to get inside
The version that makes headlines is the state-sponsored one. A person applies for a remote role, onboards like any other new hire, and passes the interviews. Sometimes they use deepfakes on video calls to appear as someone they are not. Their goal is not to do the job. Their goal is to get inside and exfiltrate data.
This is a serious, well-documented threat, and it is especially acute in financial services, where the payoff for getting a real, credentialed identity inside the building is enormous. The unsettling part is how ordinary it looks from the inside. There is no malware to catch. The credentials are valid. The account was provisioned through your normal process. Everything about the login is legitimate except the human behind it.
Flavor two: the real employee who is not where they say they are
The version I think is actually more widespread gets almost no attention, and it is a compliance problem more than a theft problem.
Here the person is real, they are genuinely doing the job. They are just not located where they told you they are. They were approved to work from one country and they are quietly logging in from another. No deepfakes, no data exfiltration. Just a working arrangement that violates the terms under which they were hired.
In a lot of businesses that would be an HR footnote. In regulated industries it is not. In fintech and healthcare, where the person is physically working from can carry real compliance weight, and “our employee is operating from a country we are not cleared to operate in” is the kind of sentence that ends up in front of auditors.
And companies are discovering it in the strangest ways. Someone notices it is dark outside a teammate’s window when it should be the middle of their workday. A schedule that never quite lines up. A small human tell that no security tool was watching for, because the login itself looked perfect. Where are you really working from turns out to be a security question, not a small-talk one.
Flavor three: the vendor who swapped the body behind the badge
The third version is pure third-party vendor risk, and it is the one that catches mature security teams off guard because they think they already handled it.
You hire an outside firm for a project. You do everything right. You ask for the specific people who will be in your environment, you vet them, and you cut named accounts with scoped access for each one. Clean process.
But here is the incentive problem. Once someone leaves that vendor, or is simply busy, it is far easier for the firm to slide a different person into the existing named account than to put a new one through your vetting. The account you approved stays exactly where it is. Someone else signs in with it. That someone may never have passed your checks, may be in a country you never cleared, and in many cases it is not even one person but a rotating team sharing a single identity.
You vetted five pristine profiles. You have no idea whether those five are the ones actually doing the work.
Three faces, one pattern
Line them up and the resemblance is obvious.
The deepfake hire, the misrepresented remote worker, and the swapped vendor contractor look like three completely different problems. One is espionage, one is compliance, one is procurement hygiene. But underneath, they are identical. In every case you have a legitimate, authenticated identity, real permissions attached to it, and behavior behind that login that does not match what you signed off on.
That is the exact definition of an insider threat. Not the disgruntled employee downloading files that we all trained on a decade ago. A trusted identity acting inside your environment in a way you never approved. The face keeps changing. The pattern does not.
And this is why I keep pushing back when someone tells me this feels like a brand new, AI-era problem. The delivery mechanisms are newer, sure. Deepfakes are convincing now. Remote work made location invisible. Vendor ecosystems got more complex. But the thing you are actually defending against is as old as identity itself. Someone you trust, doing something you would not permit if you could see it clearly.
Why this matters more in fintech and healthcare
If you run security in financial services or healthcare, this is not an abstract worry. It is a compounding one.
You carry regulatory obligations about who can touch data and from where. You carry PII and PHI that make a credentialed insider far more valuable to an attacker and far more dangerous by accident. And you lean heavily on third-party vendors and distributed, often global, teams, which is exactly the soil all three of these flavors grow in.
The truth is that most of the stack was never built to answer the question these situations raise. Your tools can confirm that a valid credential authenticated successfully. What they usually cannot tell you is whether the behavior behind that credential matches the identity you think you approved. That gap between a valid login and legitimate behavior is where all three of these live.
What to actually do about it
I am not going to end this with a pitch. I will end it with the same advice I give in every one of these conversations.
Do not treat this as a new problem that needs a brand new category of tool. Treat it as insider threat, because that is what it is, and defend it the way you already know how. Get visibility into behavior, not just authentication. Watch what identities actually do once they are inside, look for the drift between what you approved and what is happening, and be ready to act on the footsteps rather than waiting for the damage to complete.
If any of these three stories made you a little uneasy, take that as a good sign. It means you are asking the right question. And if it makes you feel any better, you are not the only one asking it. Nearly everyone I talk to thinks this is their secret problem. It is turning out to be everybody’s.
Which of these three are you most worried about in your own environment? I would genuinely like to know, because the answer is different at almost every company I ask.


