Resources

Who's Really Behind That Login? The Insider Threat Surge No One's Talking About

Written by Miguel Martinez | Sep 28, 2026, 5:00:00 PM

Most insider threat conversations still default to the same mental image: a disgruntled employee, maybe recently written up, downloading files on their way out the door. That scenario still happens. But it's no longer the most useful way to think about insider risk, and organizations that haven't updated the mental model are missing where the actual growth is happening.

Recent data on insider-related incidents shows wrongdoing cases climbing sharply this year — not a modest increase, but a jump substantial enough to represent a real shift in the threat landscape rather than statistical noise. Two forces are driving it, and neither looks like the classic "disgruntled employee" story.

Force One: Layoffs Create Access Gaps

Every round of layoffs creates a predictable, well-documented risk window: offboarding that happens too slowly, access that gets revoked in one system but not another, and departing employees who retain credentials longer than anyone intended. This isn't new. What's changed is the frequency and scale of workforce reductions across the past two years, which means that access-gap window is opening far more often than it used to, at more organizations, simultaneously.

The uncomfortable reality is that most offboarding processes were designed for a world where headcount changes were occasional events, not a recurring quarterly exercise. A process that works fine when it runs twice a year starts to break down when it's running continuously — and every gap in that process is a login that shouldn't still work, sitting there until someone notices.

Force Two: Fake Employees With Real Access

The second driver is stranger and, frankly, harder for most organizations to believe applies to them: operatives using fabricated identities to get hired directly into remote IT and technical roles, pass background checks and interviews, and then use that legitimate employment as cover — sometimes to generate revenue for a sanctioned state program, sometimes to establish access for later exploitation.

This isn't a theoretical risk confined to a handful of high-profile cases. It's become common enough that it now shows up as its own distinct category in insider threat reporting, and remote-first hiring practices — video interviews, remote onboarding, distributed teams that never meet in person — have made it considerably easier to pull off than it would have been five years ago. The unsettling part isn't that this happens. It's that from an access-control perspective, a successfully placed fake employee looks exactly like a real one, because they were hired through the same process and granted access through the same systems.

Why Traditional Insider Threat Programs Miss Both

Most insider threat programs were built around behavioral monitoring — watching for the employee who suddenly downloads an unusual volume of files, or accesses systems outside their normal pattern. That approach can catch a disgruntled employee mid-exfiltration. It's far less effective against either of the forces driving this year's surge, because both of them start with a fundamentally normal-looking access grant. There's no anomaly to catch in month one, because month one looks exactly like onboarding any other new hire or maintaining any other existing account.

What both scenarios have in common is that they're identity and asset visibility problems, not behavior problems. The question isn't "is this person acting strange" — it's "do we have an accurate, current picture of every account, every system access grant, and every identity tied to a real, currently-employed, currently-authorized person, right now." Most organizations, if they're honest, would struggle to answer that completely.

What This Requires

Closing this gap starts with an uncomfortable inventory exercise: a complete, current map of every account and access grant across your environment, cross-referenced against who's still employed, still in that role, and still supposed to have that level of access. That sounds basic. In practice, most organizations discover the reality is messier — accounts tied to contractors who finished their engagement months ago, service accounts nobody remembers creating, access grants from a role change eighteen months back that were never cleaned up.

A few concrete steps make the biggest difference:

  • Real-time asset and identity visibility across cloud, on-prem, and SaaS environments — not a quarterly spreadsheet exercise, but a living, current picture of what exists and who has access to it.
  • Automated offboarding triggers tied directly to HR systems, so access revocation doesn't depend on someone remembering to file a ticket.
  • Stronger identity verification during hiring for remote technical roles specifically, including verification steps that go beyond a video call and a reference check.
  • Regular access recertification for privileged accounts, so access that should have expired doesn't just quietly persist because nobody was asked to confirm it's still needed.

The Bottom Line

The insider threat conversation has moved past the disgruntled-employee stereotype, whether most security programs have caught up or not. This year's surge is coming from access gaps left open by layoffs and hiring processes that can be — and are being — exploited from the outside using fabricated identities. Both problems share the same root cause: an incomplete, outdated picture of who has access to what. Fixing that isn't about watching people more closely. It's about knowing, with certainty, exactly what exists in your environment and exactly who it belongs to.