KnowBe4 A.I CyberSecurity Scoring
KnowBe4
Company Information
Website:http://www.knowbe4.com
Employees number:2,406
Number of followers:320,748
NAICS:541514
Industry Type:Computer and Network Security
Homepage:knowbe4.com
KnowBe4 Risk Score (AI oriented)
Between 650 and 699
KnowBe4Computer and Network Security
Updated:
21/07/2026
21/07/2026
674/1000
Weak
B
KnowBe4 Global Score (TPRM)
xxxx
KnowBe4Computer and Network Security
Score locked

KnowBe4Weak
Current Score
674B (WEAK)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
675
JULY 2026
674
JUNE 2026
673
MAY 2026
670
APRIL 2026
669
MARCH 2026
667
FEBRUARY 2026
665
JANUARY 2026
663
DECEMBER 2025
659
NOVEMBER 2025
659
OCTOBER 2025
656
SEPTEMBER 2025
654
JULY 2024
674
Breach
01 Jul 2024 • KnowBe4
KnowBe4
Insider Threat at KnowBe4
615
LOW-59
KNO000072724
KnowBe4, a US-based security vendor, became the target of an insider cyber threat when it inadvertently hired a North Korean hacker posing as a software engineer. Using a stolen US identity and AI-enhanced fake photo, the hacker was onboarded and sent a Mac workstation. Upon receipt, the workstation began loading malware, signaling a deliberate threat attempt. The activity was detected by KnowBe4's Security Operations Center (SOC) before any harm was done, with no data lost, compromised, or exfiltrated. An FBI investigation is ongoing, examining the incident as a potential insider threat or nation-state actor orchestration.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2024
768
Breach
01 Jan 2024 • KnowBe4
KnowBe4: Fake AI workers behind numerous cyber attacks, researchers find
Rise of 'Synthetic Insiders' and Shadow AI Reshape Cybersecurity Risks for Businesses
663
CRITICAL-105
KNO1784637351
Rise of "Synthetic Insiders" and Shadow AI Reshape Cybersecurity Risks for Businesses
A growing wave of insider-driven cyber threats fueled by AI and remote work vulnerabilities is forcing insurers and businesses to rethink risk exposure. Recent reports highlight three key trends: the rise of "synthetic insiders," the financial toll of insider incidents, and the rapid adoption of unsanctioned AI tools in corporate environments.
AI-Powered Impersonation and State-Sponsored Schemes
Attackers are increasingly using AI-generated deepfakes to pose as trusted employees or job candidates, a tactic researchers term "synthetic insiders." The most high-profile example remains North Korea’s fraudulent IT worker scheme, where operatives used stolen identities to secure remote roles at over 100 U.S. companies, funneling $5 million to the regime before a 2023 Justice Department crackdown. The Financial Times reports the tactic has since spread to Europe, with UK-based "laptop farms" enabling overseas operatives to appear as local hires.
While state-sponsored infiltration remains a high-severity risk, it accounts for a smaller share of incidents compared to human error and negligence. Verizon’s 2026 Data Breach Investigations Report found internal actors were involved in 12% of breaches down from 18% the prior year but still a significant factor given the scale of modern cyberattacks.
Shadow AI and Uncontrolled Data Access
A more pervasive threat comes from "shadow AI": employees using unsanctioned AI tools on corporate devices. Verizon’s data shows 45% of employees now regularly use AI tools, up from 15% a year ago, with 67% of that usage occurring through non-corporate accounts that bypass security controls. This unchecked adoption has made shadow AI the third most common cause of non-malicious insider data loss, quadrupling year-over-year.
The financial impact is substantial. The Ponemon Institute estimates the average cost of a North American insider incident at $22.2 million in 2025, a figure insurers are factoring into policy limits and retentions particularly for organizations with large remote or contractor workforces. Yet, 73% of security leaders admit they lack full visibility into how staff interact with sensitive data across endpoints, SaaS platforms, and generative AI tools.
Insurance Gaps and Coverage Disputes
The blurring line between insider threats and external attacks is complicating cyber insurance claims. Deepfake-enabled fraud has exposed a "pass-the-parcel" problem between cyber and crime policies, with disputes arising over whether losses fall under social engineering extensions, fraudulent instruction coverage, or employment practices liability. Some insurers are now explicitly defining AI-assisted impersonation in policy language, but gaps remain especially when verification failures or lax hiring processes are involved.
For example, if a fraudulent hire is detected before gaining system access, it may not trigger a cyber policy at all. But if the operative exfiltrates data or deploys malware as in KnowBe4’s 2024 breach the loss profile shifts, potentially triggering multiple policies with overlapping exclusions. Insurers are also scrutinizing whether companies meet authentication requirements, as AI tools make impersonation harder to detect.
Underwriting and Risk Mitigation Shifts
The data suggests that while nation-state infiltration grabs headlines, everyday negligence and shadow AI represent the higher-frequency, high-cost baseline risk. Insurers are adjusting underwriting questions to address AI governance and data-handling practices, rather than focusing solely on high-profile espionage cases. Brokers recommend that organizations with significant remote hiring explicitly confirm whether AI-enabled impersonation is covered under cyber or crime policies and at what sublimit.
Access-based controls remain the most effective mitigation, reducing both the frequency and severity of insider-driven losses. As deepfake tools become cheaper and more accessible, the distinction between insider threats and external attacks will continue to erode, requiring policies to evolve alongside the risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for KnowBe4 ??
What was KnowBe4's A.I Rankiteo Cyber Score in July 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in June 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in May 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in April 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in March 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in February 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in January 2026 ??
What was KnowBe4's A.I Rankiteo Cyber Score in December 2025 ??
What was KnowBe4's A.I Rankiteo Cyber Score in November 2025 ??
What was KnowBe4's A.I Rankiteo Cyber Score in October 2025 ??
What was KnowBe4's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on KnowBe4's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with KnowBe4 ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view KnowBe4's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?