• Aug 28, 2026
  • 13 min read

Insider Fraud: Why It Happens and How to Prevent It (2026)

Insider fraud costs companies millions each year. Learn how internal fraud happens, why IAM alone can’t prevent it, and which controls can help close the gap.

A former TD Bank employee pleaded guilty in New York in May 2026 to taking at least $155,000 in bribes and helping facilitate more than $3.4 million in fraud. According to the US Department of Justice, he used his position to identify high-balance customer accounts, steal confidential information, and share it with co-conspirators who defrauded the victims.

In Germany, prosecutors are investigating three employees of Volksbank Köln Bonn, including a board member, over alleged bribery and breach of trust connected to a €5 million loan used to finance the purchase of a Cologne brothel. BaFin has questioned the bank about a possible kickback. The individuals deny wrongdoing, and the reputational pressure has already started.

One case ended in a guilty plea, the other is unproven. And both point at the same structural weakness: insiders hold valid credentials, know how the controls work, and have direct access to customer data, payments, or compliance processes. Malicious activity from that position is hard to spot, because it looks like routine work.

Remote work has expanded, cloud systems carry more of the load, and AI is evolving fast. In 2026, that combination has made it considerably easier for bad actors to exploit businesses.

What is insider fraud?

Insider fraud is the deliberate misuse of trusted access, organizational knowledge, or professional authority for personal gain or to assist another party. The perpetrator might be an employee, executive, contractor, vendor, or a former worker whose access to company systems was never revoked. Criminals also enter organizations under a stolen or fabricated identity and become insiders that way.

The playbook is familiar: stealing data, redirecting payments, creating fake vendors, approving fraudulent transactions, suppressing compliance alerts.

Insider fraud vs. insider threat: What’s the difference?

An insider threat is any potential harm arising from trusted access or knowledge. The definition given by the United States Cybersecurity and Infrastructure Security Agency (CISA) includes intentional malicious acts, unintentional negligence, and compromised accounts. For example, an employee who accidentally exposes customer data creates an insider threat, even though there is no fraudulent intent.

Insider fraud is the narrower category. It's the subset that uses deliberate deception for the perpetrator's benefit or an accomplice's. Forged credentials used to reach data that's then sold for personal gain: fraud. The same data exposed by accident: a threat, but not a fraud.

Insider fraud vs. employee fraud

The two terms get used interchangeably. "Employee fraud" generally means fraud committed by an employee. "Insider fraud" runs broader, covering fraudulent activity by anyone with legitimate access to an organization's systems or information, contractors and other insiders included. In practice, employee fraud is one type of insider fraud.

Suggested read: Employee Fraud: Detection, Prevention, and Compliance Strategies in 2026

Common types of employee fraud and internal fraud

  • Misappropriation of assets: An insider steals or misuses company property or funds for personal gain (e.g., misusing company credit cards). As per KPMG’s Global Profiles of the Fraudster, asset misappropriation is the most common type of fraud.
  • Expense reimbursement fraud: An insider submits false, duplicated, or inflated expense reports (e.g., charging twice for the same claim). Generative AI is also making it easier for insiders to defraud organizations with AI-generated receipts.
  • Simple theft: An insider steals company property (e.g., money, resources, goods).
  • Bribery: An insider solicits or accepts money, gifts, or other benefits in return for abusing their position or improperly influencing an outcome. KPMG’s 2025 survey identified bribery or corruption in 36 of the 256 fraud cases they examined.
  • Payroll fraud: An insider manipulates the payroll system to receive higher compensation (e.g., declaring more hours than actually worked).
  • Data theft and insider information abuse: An insider steals sensitive company information with the intent to benefit from it (e.g., by selling it to a third party). In one case, a former DuPont employee downloaded hundreds of DuPont files containing proprietary information, including customer, pricing, testing, and yield data, and sent them to a competitor. He pleaded guilty to trade-secret theft.
  • Fraudulent workforce identities: A criminal uses a stolen, synthetic, or fabricated identity, forged qualifications, deepfakes, or a stand-in interviewer to obtain employment and trusted access or creates a “ghost employee” through which company funds can be extracted. Between 2024 and 2025, there was a 220% surge in cases of companies being infiltrated by remote workers from North Korea to raise funds for the regime.
  • Access-credential abuse: Where an employee shares, steals, or reuses another worker’s credentials to commit or conceal fraud. In one case, a financial analyst for Honeywell used the login credentials of a colleague and two former employees to approve fictitious vouchers and bypass controls against self-dealing. 

How insider fraud happens in banks

Bank staff hold access to systems that move money, store identity information, assess customers, and generate regulatory reports. Insider bank fraud starts when someone abuses that legitimate access or authority.

Certain conditions make it easier. Access rights that exceed what a role requires. Incompatible duties assigned to the same person. Sensitive actions that complete without independent approval. Add shared accounts, dormant credentials, incomplete audit logs, poorly controlled administrator privileges, and delays in removing access when someone changes roles or leaves, and the gap widens further.

Effective bank fraud prevention rests on four things: binding accounts to verified employees, restricting access according to role, requiring additional verification for high-risk actions, and monitoring whether activity is consistent with the insider's responsibilities.

Common insider bank fraud schemes

Insider bank fraud can target customers, the financial institution itself, or controls intended to stop financial crime.

  • Customer account theft: An insider obtains account details, changes contact information, resets security credentials, or initiates unauthorized withdrawals and transfers.
  • Fraudulent account opening: Insiders create accounts using forged documents, nominee owners, or shell companies. They may falsify signatures, bypass identity checks, or override adverse risk indicators.
  • Facilitation of financial crime: An insider helps criminals commit or conceal money laundering, fraud, sanctions evasion, or other illicit activity by opening or maintaining accounts, unblocking restricted cards, concealing the true parties behind transactions, or improperly closing monitoring alerts. In 2024, the US Department of Justice found that five TD employees conspired with a laundering network, helping move about $39 million to Colombia, partly by issuing ATM cards.
  • Payment and ledger manipulation: Insiders redirect transfers, issue unauthorized refunds, alter beneficiary information, or conceal theft through adjustments to internal ledgers and suspense accounts.
  • Loan and credit fraud: Insiders approve ineligible borrowers, inflate collateral values, manipulate credit assessments, or cooperate with applicants and brokers in return for kickbacks.
  • Data theft and access brokering: Customer identity data, account balances, security information, or authentication credentials are sold or supplied to external fraudsters.
  • Misuse of confidential information: Insiders exploit non-public information about transactions, clients, or corporate activities for insider trading or other financial gain.

Understanding which roles can perform these actions is central to bank fraud prevention.

Why banks and financial institutions are high-risk targets

A single bank employee might view sensitive customer information, influence an account-opening decision, or override a restriction that an external fraudster could never bypass directly.

Banks also hold liquid assets and valuable identity data, and their staff understands where alert thresholds sit and which controls are weak. For a criminal network, bribing, coercing, or recruiting an insider is often easier than breaching the institution head-on.

Suggested read: I Spent Years Being a Fraudster: The System Was My Accomplice

The real cost of employee fraud and internal fraud

The ACFE’s Occupational Fraud 2026: A Report to the Nations examined 2,402 cases across 143 countries, with combined losses above $3.4 billion. Median loss was $104,000, average loss was $1.457 million, and 20% of cases exceeded $1 million. A typical scheme lasted 12 months before detection. The ACFE estimates that organizations lose about 5% of annual revenue to fraud.

Financial and regulatory impact

Stolen funds are the visible number. The rest of the bill covers customer reimbursement, investigations, legal and compliance support, system downtime, remediation, litigation, and recruitment to replace dismissed employees. If an insider falsifies KYC records, changes risk ratings, or suppresses alerts, this can undermine AML, sanctions, data protection, safeguarding, and fraud prevention obligations, and potentially lead to regulatory reviews, penalties, or civil claims.

Reputational and customer trust damage

Employee theft is especially damaging because it involves an extra layer of breached trust. Customers expect organizations to control who can access their money and data, and when that trust is abused, it’s difficult to rebuild. Employee fraud can lead to customer loss, complaints, negative media coverage, increased regulatory scrutiny, concerns from business partners, higher acquisition costs, and lower staff morale. 

Stolen identity information may be resold or reused in future attacks. Affected customers may remain vulnerable to impersonation, account takeover, and targeted social engineering.

The goal is to secure internal systems without destroying workplace trust. Prompt investigation, customer redress, and transparent remediation can limit lasting reputational damage.

Suggested listen: Insider Fraud: The Enemy Within

How to build an insider fraud prevention strategy

Fraud prevention works when HR, fraud, compliance, cybersecurity, and identity systems are connected to each other. A mature insider fraud program keeps answering four questions: who the worker is, whether the role still requires the access attached to it, whether the current action makes sense, and how suspicious activity gets contained and investigated.

Integrating IDV into access management workflows

Traditional access management, through Okta and other identity and access management (IAM) providers, determines what an account may use. It doesn't always prove the account was issued to a genuine worker. Identity verification (IDV) integration closes that gap by verifying the person before credentials are issued, binding the verified identity to a unique record, and triggering reverification in high-risk scenarios.

Step-up verification for high-risk transactions

Step-up authentication requires stronger proof when risk increases, such as before a high-value transfer, a beneficiary change, a bulk data export, a privilege elevation, a new-device enrollment, or an account recovery. This may mean phishing-resistant multi-factor authentication (MFA), a device-bound credential, or renewed facial verification with liveness.

Behavioral monitoring and anomaly detection

An employee may pass identity and authentication checks and still fraudulently use their legitimate access. Two controls close that gap, and they do different work:

Behavioral monitoring is the collection layer. It records what an account actually does inside a specific system: login time, device, location, records viewed, data exported, transactions approved, alerts overridden. Run over time, that record establishes what normal use looks like for a given system and a given role.

Anomaly detection is the judgment layer. It measures live activity against that baseline and surfaces the sessions that don't fit. Inside a platform, that might be hundreds of unrelated customer searches, an unusual download in the days before a resignation, or override volumes far above peer levels.

Monitoring without detection produces logs nobody reads. Detection without monitoring has no baseline to measure against. Both operate inside a single platform, which separates them from the broader behavioral red flags. Those involve changes in an employee's conduct or circumstances outside any one system.

Combining role-based access with continuous identity assurance

Role-based controls define what a worker may do, but permissions can become outdated and overly broad. Continuous authentication can reassess risk based on device signals, session behavior, network context, employment status, and recent alerts, and then allow, restrict, step up, or terminate access.

This should be combined with least-privilege access, regular access recertification, time-limited privileged access, separate administrator accounts, and immutable logs.

Insider threat detection: Warning signs to watch for

The ACFE found that 84% of fraudsters exhibited at least one behavioral red flag prior to detection. While insider threat indicators are not proof of wrongdoing, they must be taken seriously.

Behavioral red flags

Potential behavioral warning signs include:

  • Living beyond known means or experiencing severe financial pressure
  • Developing an unusually close relationship with a customer, vendor, or intermediary
  • Refusing to share responsibilities, delegate work, or take leave
  • Becoming excessively protective of particular accounts, records, or processes
  • Resisting audits, quality-control checks, or independent review
  • Concealing conflicts of interest or outside business relationships
  • Seeking information unrelated to current responsibilities
  • Reacting defensively when asked to explain transactions or exceptions
  • Expressing serious grievances alongside threats to misuse access or expose data

Access-pattern and technical red flags

Technical indicators may reveal that an account is being used outside its expected role, location, or working pattern. Examples include:

  • Access outside normal working hours without a business reason
  • Logins from unfamiliar devices, networks, or locations
  • Concurrent sessions from geographically distant locations
  • Access to customer records unrelated to assigned cases
  • Repeated attempts to access restricted systems
  • Creation of unauthorized accounts or privilege changes
  • Use of dormant, shared, or former-employee credentials
  • Frequent password resets, MFA changes, or account-recovery requests
  • Unusual numbers of customer-detail amendments or beneficiary changes
  • Repeated overrides of fraud, KYC, AML, or sanctions controls
  • Transactions just below approval or monitoring thresholds
  • Attempts to disable logging, delete records, or interfere with monitoring tools
  • Continued access after resignation, dismissal, or transfer to another role

Best practices to prevent insider bank fraud

Banks should assume that preventive controls can fail or be circumvented. A defense-in-depth approach limits what one person can do, reviews whether access is appropriate, and makes it safe for employees to report suspicious behavior.

Segregation of duties

Segregation of duties cuts internal fraud by preventing any single employee from controlling every stage of a sensitive process.

Banks can apply this principle by separating:

  • Payment creation from payment approval
  • Customer onboarding from final KYC approval
  • Alert investigation from quality assurance
  • Vendor creation from invoice approval
  • Loan origination from underwriting and disbursement
  • User-access requests from permission approval
  • Software development from production deployment
  • Transaction processing from account reconciliation

Segregation cannot prevent collusion. It should be combined with access monitoring, job rotation, transaction analytics, and independent review of overrides and exceptions.

Regular access reviews and recertification

Reviews should confirm that each worker remains authorized, every permission is necessary, privileged access is justified, temporary access has expired, and no one holds incompatible duties. Employment or role changes should trigger immediate review, while automated updates between HR and IAM systems should revoke obsolete access promptly. Decisions should be recorded for audit purposes.

Employee training and whistleblower channels

For many organizations, an internal reporting channel is a legal requirement rather than just best practice. The EU Whistleblowing Directive, for example, requires private-sector legal entities with 50 or more workers to establish internal reporting channels. Reports must generally be acknowledged within seven days, with feedback provided within three months. In the UK, firms covered by the FCA’s whistleblowing rules must maintain appropriate and effective arrangements for reporting suspicions.

A confidential whistleblower hotline gives employees, contractors, and potentially customers or vendors a confidential way to report concerns outside the ordinary management chain, which helps to identify employee fraud. Confidential reporting, however, is not necessarily anonymous. A confidential channel may still require the reporter’s identity but protect it from disclosure, whereas an anonymous channel allows someone to report without revealing their identity at all.

In the ACFE’s 2026 study, tips uncovered 43% of cases, and employees supplied more than half of those tips. Training should cover common schemes, rules for credentials and sensitive data, criminal tactics, deepfake communications, escalation, and evidence preservation.

Suggested read: Payroll Fraud: Schemes, Examples & How to Prevent Them

Why IAM systems without IDV integrated into access management are not enough

Identity and access management (IAM) systems are the technologies and policies organizations use to control digital identities and access to internal resources. They create and manage user accounts, issue or connect authentication methods, assign permissions, and revoke access when workers change roles or leave. 

They may include employee directories, single sign-on, MFA, role-based controls, and privileged access management.

IAM determines what an account can do, while IDV establishes who is actually behind the account. Without IDV, if a fraudulent worker is onboarded, an account is taken over, or an employee shares credentials, the system may still see a valid account with legitimate permissions.

IAM verifies credentials, not identity

Identity and access management can confirm that a user controls a credential and that the associated account has the necessary permissions. It cannot infer that the original applicant was genuine.

Account takeover looks identical to legitimate insider access

In account takeover fraud, an attacker gains control of an existing account through stolen credentials, phishing, session token theft, malicious account recovery, or manipulation of a help desk. The criminal then inherits whatever privileges the employee possesses. 

At first, this may resemble ordinary access. The username is valid, the account is active, and the requested action may fall within its assigned permissions. However, the compromised account has become an insider threat.

The onboarding gap: Synthetic and fabricated identities inside IAM

Synthetic identity fraud involves constructing a persona from a mixture of real and invented information. Workforce infiltration can involve entirely fabricated profiles, stolen identities, forged documents, or one person completing an interview on behalf of another.

Once a fake applicant passes hiring and receives an account, IAM generally treats them as an authorized employee. 

Google Threat Intelligence reported in April 2025 that, in late 2024, one North Korean IT worker operated at least 12 personas while seeking roles at European organizations, particularly in the defense and government sectors. The applicant supplied fabricated references and used other personas as referees. Separate investigations identified further personas seeking work in Germany and Portugal, as well as North Korean IT workers completing projects in the UK. 

A convincing employment profile can become a trusted digital identity without the person behind it being reliably established. Risk-based identity verification can help validate documents and authoritative data, match the applicant to the evidence, use liveness against replay and deepfake attacks, and bind the verified person to the account.

No continuous verification at high-risk moments

A session may remain trusted even after a token is stolen or a device compromised. Continuous authentication reassesses risk using session, device, network, and employment signals. And when confidence falls, step-up authentication can require phishing-resistant MFA, a device-bound credential, or renewed IDV before privilege elevation, high-value payments, bulk exports, security control changes, or alert overrides. The strength of the response should track the size of the uncertainty.

Why regulators expect more than “authenticated access”

While authentication can show that a valid credential was used, it does not necessarily prove that the intended worker is behind it or that their actions are legitimate. Financial-sector regulation often expects additional controls for higher-risk scenarios.

In the EU, for example, binding DORA technical standards require unique user identification, risk-proportionate authentication, and controls over remote, privileged, and emergency access. In the United States, FFIEC guidance, which is not a binding rule, calls for risk-based layered security and stronger authentication for high-risk access. 

Neither mandates IDV or step-up authentication for every action, but firms must be able to evidence their controls and remain responsible when using third-party ICT providers. IDV can support this by strengthening proof of who is behind an account at onboarding and higher-risk moments.

Suggested read: How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026

The rise of remote and hybrid work, as well as rapidly evolving AI systems, is expanding who or what can operate inside trusted environments.

Remote and hybrid work will remain widespread 

A 2025 study of 16,422 employees across 40 countries found that working from home represented approximately 25% of paid working days. Demand for flexible work is high: a Korn Ferry survey of more than 15,000 professionals found that 48% considered hybrid work ideal and another 25% preferred fully remote work, although only 27% currently had a hybrid arrangement. This gap suggests that more workers will choose remote or hybrid roles when they are available. Businesses will need to keep strengthening remote recruitment, device enrollment, access management, and offboarding.

The next insider threat may not be a human 

The next source of insider risk could be a contractor or vendor with legitimate access, a fraudulent remote hire using a stolen or fabricated identity, or an external criminal controlling an employee’s account. It may not even be human. An AI agent with permission to access data, alter vendor records, approve transactions, or initiate payments could be manipulated into assisting a criminal scheme. Each of these operates through apparently valid credentials and approved workflows, which push assessment toward identity, permissions, and behavior rather than employment status alone.

AI-enabled insider threats will increase

According to Proofpoint’s 2025 research, 50% of organizations expected data leakage through GenAI tools to affect them within the following 12 months. Shadow AI incidents were cited by 49%, while 41% expected AI-driven insider threats. The persistent risks: employees exposing sensitive information through approved or unauthorized tools, criminals producing synthetic documents and deepfake communications, and attackers manipulating AI agents wired into internal systems.

Traditional fraud schemes will persist

Established fraud trends, such as asset theft and misappropriation, bribery and collusion, fake-vendor and invoice schemes, payroll fraud, credential abuse, and the falsification of internal records, will all continue. KPMG discovered that 46% of the frauds it investigated involved no technology, while another 35% used technology but could probably have occurred without it. AI is more likely to produce familiar schemes faster, more cheaply, and more convincingly.

How Sumsub helps prevent insider fraud

Sumsub helps reduce insider fraud through a layered approach by adding workforce verification and identity assurance to existing IAM controls. Integrations with Okta and Auth0, for example, can verify employees during onboarding, login, recovery, and other sensitive access events.

This enables the IAM platform to base its decision on more than possession of a password or device. Sumsub confirms the person behind the request, and the organization's IAM policies determine whether that verified individual should receive access.

Biometric verification and liveness checks for internal access

Sumsub’s identity verification combines document and database checks with biometric verification. Its Liveness and Face Match technology checks that a real person is present and compares them with the verified identity reference. It is designed to detect photos, recorded or manipulated video, masks, lookalikes, deepfakes, and injection attacks.

Triggered at onboarding, account recovery, authenticator enrollment, or access to highly sensitive systems, this supports insider fraud prevention by making stolen credentials harder to use. 

Device and digital footprint signals for access risk

Device Intelligence can add context around sensitive access events by analyzing the device, browser, network, and environment behind a request. This helps identify unusual or manipulated setups, such as new devices, emulators, VPN use, spoofed location, rooted or jailbroken devices, or repeated activity across multiple accounts.

Digital Footprint Check is more useful at onboarding or access provisioning. It can assess whether an employee, contractor, or third-party user’s email or phone number looks established and consistent with the claimed identity, or whether it appears newly created, disposable, virtual, or otherwise risky.

None of these signals proves insider fraud on its own. They help IAM and risk teams decide when to allow access, when to trigger step-up verification, when to route a case for review, and when to block a high-risk action.

Step-up identity checks across the employee lifecycle

Insider risk controls shouldn't stop at onboarding. Sumsub checks trigger when risk changes: first login, role or privilege changes, account recovery, sensitive profile updates, unusual device and location events.

This complements continuous authentication models, where IAM, device, and behavioral signals reassess session risk in the background. When those systems register lower confidence or a high-risk action, Sumsub supplies a stronger identity check before access continues.

Insider fraud FAQ

  • What is insider fraud in banking?

    Insider fraud in banks occurs when an employee, contractor, or other trusted party deliberately misuses their access or authority for personal gain or to help another party. It covers stealing customer data, manipulating accounts, bypassing AML controls, and facilitating unauthorized transactions.

  • How common is employee fraud?

    The true scale is hard to measure, since many of these crimes go undetected. The ACFE estimates that organizations lose around 5% of revenue to occupational fraud annually, and its 2026 study found that 90% of cases involved asset misappropriation, which includes employee theft.

  • What's the difference between insider fraud and insider threat?

    An insider threat is any potential harm arising from trusted access, including deliberate malicious acts, negligence, and compromised organizational accounts. Insider fraud is the narrower category involving intentional deception or misuse for personal benefit or to assist another party.

  • Can IAM alone prevent internal fraud?

    Identity and access management controls accounts, authentication, and permissions. It cannot independently prove that the correct person obtained an account or that an authorized action has a legitimate purpose. Preventing internal fraud also takes identity verification, least-privilege access, behavioral monitoring, transaction controls, and independent approval processes.