logo
North Korean Hackers Pose As Remote Workers To Infiltrate U.S. Firms

North Korean Hackers Pose As Remote Workers To Infiltrate U.S. Firms

Forbes25-04-2025
Remote hiring has created extraordinary flexibility for global workforces. It has also opened new ... More frontiers for exploitation by nation-state actors using synthetic identities and cross-border deception.
Even cybersecurity companies aren't immune.
In mid-2024, KnowBe4, a global leader in security awareness training, hired a seemingly well-qualified remote software engineer. The candidate passed a rigorous background check, provided references, attended multiple video interviews, and even submitted a professional photo.
But just weeks into the role, their security team discovered malware being installed on the employee's company-issued laptop. The engineer wasn't who he claimed to be. He was a North Korean threat actor using a stolen U.S. identity and an AI-enhanced image to dupe one of the most security-conscious companies in the world.
That incident, once viewed as an outlier, now appears to be part of a much larger and more coordinated national security threat.
In December 2024, the Department of Justice announced the indictment of 14 North Korean nationals who fraudulently obtained remote IT jobs with U.S. companies using stolen identities and false credentials. Over six years, the scheme generated at least $88 million, money that was ultimately funneled to the North Korean regime to fund its weapons programs.
Just weeks later, in January 2025, another indictment charged two additional North Korean nationals and three international facilitators — including two U.S. citizens — with similar fraud. That group allegedly infiltrated 64 U.S. companies, laundering more than $866,000 through just ten of them. One of the American defendants reportedly ran a 'laptop farm' out of his North Carolina home, receiving company-issued devices and installing remote access software so North Korean workers could appear to be U.S.-based hires.
'The Department of Justice remains committed to disrupting North Korea's cyber-enabled sanctions-evading schemes, which seek to trick U.S. companies into funding the North Korean regime's priorities, including its weapons programs,' said Devin DeBacker of the DOJ National Security Division.
This isn't a minor fraud operation. It's an intentional, state-directed economic campaign.
Thousands of North Korean 'IT warriors' have been dispatched abroad, mostly to China and Russia, where they use fabricated online profiles and borrowed identities to gain employment with U.S. firms, often as freelancers or contract developers. Some even extort their employers by threatening to leak stolen source code if additional payments aren't made.
'The indictments announced today should highlight to all American companies the risk posed by the North Korean government,' warned FBI Cyber Division Assistant Director Bryan Vorndran.
The methods used by these operatives are sophisticated and increasingly difficult to detect:
In the KnowBe4 case, a stolen identity was paired with an AI-enhanced photo to impersonate a qualified U.S. engineer. Despite multiple interviews, background checks, and reference calls, the ruse held until malware activity triggered an alert.
This mirrors growing concerns from federal law enforcement. A 2021 FBI bulletin warned that foreign and criminal actors would 'almost certainly leverage synthetic content' to enable cyber and fraud operations. This includes a rising threat known as Business Identity Compromise (BIC), a form of digital impersonation where adversaries use AI to pose as legitimate employees or contractors.
'Synthetic content may also be used... to create a sophisticated emulation of an existing employee,' the FBI states.
And now, the DOJ has launched a formal crackdown on domestic enablers of this threat. Under the DPRK RevGen: Domestic Enabler Initiative, prosecutors are targeting individuals operating laptop farms in the U.S. and facilitating access to sensitive systems for foreign adversaries.
Hiring fraud has evolved. It's no longer limited to resume inflation or fake degrees. It now involves state-sponsored threat actors, synthetic identities, and cross-border data laundering. The stakes? Intellectual property theft, regulatory liability, sanctions exposure, and brand-damaging extortion.
And it's not just the 'big names' being targeted. The DOJ confirmed that dozens of U.S. companies, across sectors, have unknowingly employed Democratic People's Republic of Korea (DPRK) operatives, sometimes for years.
This is a wake-up call for employers to modernize identity verification and improve cyber-hiring resilience.
Identity verification should go beyond basic document review to include government-issued ID validation, biometric face matching, and liveness detection.
One example is HireRight's Global ID check, which leverages technology from identity verification provider Yoti Ltd. to authenticate identity documents from more than 200 countries. The system can also verify that the individual presenting the document is both physically present and matches the ID photo, all completed remotely in minutes.
This process offers a practical alternative to in-person verification, helping employers strengthen identity assurance while streamlining remote hiring.
Don't rely on a single video call. Spread interviews across stages, require on-camera participation during onboarding, and watch for proxies or inconsistencies in responses.
Ensure endpoint protection is in place. Look for signs of foreign remote access, VPN manipulation, or device sharing. In KnowBe4's case, early detection through endpoint detection and response (EDR) software helped prevent a deeper breach.
Be cautious about shipping equipment to addresses that don't match hiring documentation. If devices are requested at odd times or to alternate addresses, investigate further.
The FBI warns of telltale signs of synthetic media, such as distorted facial features, inconsistent lighting, or awkward lip-syncing in video. Use identity screening platforms with liveness and deepfake detection features.
Train HR and talent acquisition teams on how to recognize fraud indicators. Use the FBI's SIFT method — Stop, Investigate the source, Find trusted coverage, Trace original content — to evaluate suspicious profiles or resumes.
The line between a fake resume and a national security breach is blurring.
Remote hiring has created extraordinary flexibility for global workforces. It has also opened new frontiers for exploitation by nation-state actors using synthetic identities and cross-border deception. What began as a fringe tactic has become a well-coordinated global campaign, and the private sector is squarely in its sights.
As Stu Sjouwerman, CEO of KnowBe4, warned after his company fell victim to one such scheme:
As the DOJ ramps up enforcement and threat actors increase their sophistication, employers must shift from reactive to proactive hiring security.
In this era, it's not enough to verify that someone can work. You must confirm who they are.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Trump says he's ended 6 (or 7) wars. Here's some context.
Trump says he's ended 6 (or 7) wars. Here's some context.

Boston Globe

time28 minutes ago

  • Boston Globe

Trump says he's ended 6 (or 7) wars. Here's some context.

Every U.S. president has world conflicts land on his desk, and Trump has used the power of his office, including the threat of economic penalties, to intervene in several this year, leading to an end to fighting. In some cases, warring parties have credited him with advancing peace or calming hostilities. In others, his role is disputed or less clear — or fighting goes on. Asked for clarification, the White House provided a list of the six wars he says he has resolved. It did not respond to a subsequent question about the seventh. Advertisement Armenia and Azerbaijan Trump brought the leaders of Armenia and Azerbaijan to the White House this month to sign a joint declaration aimed at bringing their long-running conflict closer to an end. It was not a peace deal, but it was the first commitment toward one since fighting broke out in the late 1980s when a weakening Soviet Union unleashed interethnic strife in the Caucasus. Advertisement Both leaders praised Trump, who stepped into a conflict that had long been mediated by Russia, until President Vladimir Putin's attention shifted after his 2022 invasion of Ukraine. As part of the agreement, Armenia said it would grant the United States rights to develop a major transit corridor through its territory, the Trump Route for International Peace and Prosperity. The project has been described as an economic game changer for the region that would better connect Europe with Azerbaijan and Central Asia. But it is not clear when the route will open and on what terms. And major barriers to a lasting peace remain. Azerbaijan continues to demand that Armenia change its constitution to remove mentions of the disputed Nagorno-Karabakh region, which Azerbaijan took over in 2023. Azerbaijan also occupies small areas of Armenia, citing security concerns, and the countries have not agreed on a shared border. For now, the border between the two nations is closed, diplomatic ties remain broken. Congo and Rwanda In June, the top diplomats from Rwanda and Congo came to the Oval Office to sign a peace agreement aimed at ending a war that has raged for over three decades. Qatar also played a major role in the deal, which was intended to pave the way to a full peace agreement. Trump called the accord 'a glorious triumph.' But talks on a comprehensive agreement have since faltered and deadly fighting has continued. On Monday, the main rebel group in eastern Congo, known as M23 and backed by Rwanda, threatened to renege on the U.S.-backed deal, claiming that its primary foe, the Congolese army, had broken its terms. Advertisement India and Pakistan Trump has taken credit for mediating an end to a military escalation between the two nuclear powers that broke out after a terrorist attack in Kashmir this spring killed 26 civilians. India has acknowledged the American role in mediating but says it negotiated an end to the fighting directly with Pakistan. India claims that Pakistani officials asked for ceasefire talks under pressure from India's military assaults. Pakistan denies this and has thanked Trump for helping to end the hostilities. The differing accounts have contributed to a deterioration of relations between Washington and New Delhi, which is also playing out in Trump's trade war. Pakistan, which said it would nominate Trump for the Nobel Peace Prize for his mediation, faces U.S. tariffs of 19%. India, on the other hand, faces a crippling 50% tariff, a rate that could crush the country's exporters. Israel and Iran After 12 days of strikes in June that included U.S. attacks on Iranian nuclear sites, Trump abruptly announced a ceasefire agreement. He said the United States had mediated it and claimed that Israel had turned around its warplanes at his behest. 'It was my great honor to Destroy All Nuclear facilities & capability, and then, STOP THE WAR!' he posted on Truth Social. Although neither side has disputed the American role in the truce, its durability remains in question. Talks have broken off between Iran and the United States on the future of Tehran's nuclear program, which Israel considers an existential threat. And while American intelligence assesses that the U.S. bombings badly damaged Iran's most advanced nuclear enrichment site, some experts believe Tehran could eventually resume enriching uranium, which is needed to build a nuclear weapon, at other sites. Advertisement Cambodia and Thailand The two Southeast Asian neighbors engaged this summer in days of fighting that killed at least 42 people and displaced more than 300,000, one of the bloodiest conflicts between them in decades. At the time, the Trump administration was discussing trade deals with a host of countries, and Trump said he had told the leaders of Thailand and Cambodia that he would stop trade talks unless they agreed to a ceasefire. Two days later, officials met in Malaysia for talks organized by Malaysian and U.S. officials and reached a deal to pause hostilities. 'They will hopefully get along for many years to come,' Trump said afterward. Critics of Trump's approach say his intervention did not address the underlying issues of the conflict, though fighting has stopped. Egypt and Ethiopia Egypt and Ethiopia face not a military conflict but a diplomatic dispute over Africa's largest hydroelectric dam. Still, there are fears that it might descend into fighting. (Trump said in 2020 that Egypt had threatened to 'blow up' the dam.) Trump's diplomacy has done little to resolve the dispute. Ethiopia recently announced that it had completed the dam, with an official opening scheduled for next month. Egypt and Sudan continue to oppose the project, fearing it will limit the flow of water from the Nile River to their countries. This article originally appeared in .

Minnesota sues TikTok, alleging it preys on young people with addictive algorithms

time29 minutes ago

Minnesota sues TikTok, alleging it preys on young people with addictive algorithms

ST. PAUL, Minn. -- Minnesota on Tuesday joined a wave of states suing TikTok, alleging the social media giant preys on young people with addictive algorithms that trap them into becoming compulsive consumers of its short videos. 'This isn't about free speech. I'm sure they're gonna holler that," Minnesota Attorney General Keith Ellison said at a news conference. "It's actually about deception, manipulation, misrepresentation. This is about a company knowing the dangers, and the dangerous effects of its product, but making and taking no steps to mitigate those harms or inform users of the risks.' The lawsuit, filed in state court, alleges that TikTok is violating Minnesota laws against deceptive trade practices and consumer fraud. It follows a flurry of lawsuits filed by more than a dozen states last year alleging the popular short-form video app is designed to be addictive to kids and harms their mental health. Minnesota's case brings the total to about 24 states, Ellison's office said. Many of the earlier lawsuits stemmed from a nationwide investigation into TikTok launched in 2022 by a bipartisan coalition of attorneys general from 14 states into the effects of TikTok on young users' mental health. Ellison, a Democrat, said Minnesota waited while it did its own investigation. Sean Padden, a middle-school health teacher in the Roseville Area school district, joined Ellison, saying he has witnessed a correlation between increased TikTok use and an 'irrefutable spike in student mental health issues,' including depression, anxiety, anger, lowered self-esteem and a decrease in attention spans as they seek out the quick gratification that its short videos offer. The lawsuit comes while President Donald Trump is still trying to broker a deal to bring the social media platform, which is owned by China's ByteDance, under American ownership over concerns about the data security of its 170 million American users. While Trump campaigned on banning TikTok, he also gained more than 15 million followers on the platform since he started sharing videos on it. No matter who ultimately owns TikTok, Ellison said, it must comply with the law. TikTok disputed Minnesota's allegations. 'This lawsuit is based on misleading and inaccurate claims that fail to recognize the robust safety measures TikTok has voluntarily implemented to support the well-being of our community," company spokesperson Nathaniel Brown said in a statement. "Teen accounts on TikTok come with 50+ features and settings designed to help young people safely express themselves, discover and learn. "Through our Family Pairing tool, parents can view or customize 20+ content and privacy settings, including screen time, content filters, and our time away feature to pause a teen's access to our app,' Brown added. Minnesota is seeking a declaration that TikTok's practices are deceptive, unfair or unconscionable under state law, a permanent injunction against those practices, and up to $25,000 for each instance in which a Minnesota child has accessed TikTok. Ellison wouldn't put a total on that but said, 'it's a lot.' He estimated that 'hundreds of thousands of Minnesota kids' have TikTok on their devices. 'We're not trying to shut them down, but we are insisting that they clean up their act,' Ellison said. 'There are legitimate uses of products like TikTok. But like all things, they have to be used properly and safely.'

Trump's federal law-enforcement crackdown ripples through DC neighborhoods
Trump's federal law-enforcement crackdown ripples through DC neighborhoods

Yahoo

time37 minutes ago

  • Yahoo

Trump's federal law-enforcement crackdown ripples through DC neighborhoods

WASHINGTON (AP) — The main drag in Washington's Columbia Heights neighborhood is typically crammed with people peddling pupusas, fresh fruit, souvenirs and clothing. On Tuesday, though, things felt different: The white tents that bulge with food and merchandise were scarcer than usual. 'Everything has stopped over the last week,' said Yassin Yahyaoui, who sells jewelry and glass figurines. Most of his customers and fellow vendors, he said, have 'just disappeared' — particularly if they speak Spanish. The abnormally quiet street was one of many pieces of evidence showing how President Donald Trump 's decision to flood the nation's capital with federal law enforcement and immigration agents has rippled through the city. While troop deployments and foot patrols in downtown areas and around the National Mall have gotten the most attention, life in historically diverse neighborhoods like Columbia Heights is being reshaped as well. The White House has credited Donald Trump's crackdown with hundreds of arrests, while local officials have criticized the aggressive intervention in the city's affairs. The confrontation escalated on Tuesday as the top federal prosecutor in D.C. opened an investigation into whether police officials have falsified crime data, according to a person familiar with the situation who wasn't authorized to comment publicly. The probe could be used to bolster Trump's claims that the city is suffering from a 'crime emergency' despite statistics showing improvements. The mayor's office and the police department declined to comment. Stops are visible across the city Blocks away from where Yahyaoui had set up shop, U.S. Immigration and Customs Enforcement and local police stopped a moped driver delivering pizza. The agents drove unmarked cars and wore tactical vests; one covered his face with a green balaclava. They questioned the driver and required him to present documentation relating to his employment and legal residency status. No arrest was made. The White House said there have been 450 arrests since Aug. 7, when the federal operation began. The Trump administration has ramped up immigration enforcement and the president signed an executive order on Aug. 11 to put the police department under federal control for 30 days; extending that would require congressional approval. Karoline Leavitt, the White House press secretary, said Trump was 'unapologetically standing up for the safety of law-abiding American citizens.' Glorida Gomez, who has been working a fruit stand in Columbia Heights for more than a decade, said business is worse now than during the COVID-19 pandemic. She said many vendors stopped coming because they were afraid of interacting with federal agents. 'We need more humanity on that part of the government. Remember that these are people being affected,' she said. 'The government is supposed to protect members of the community, not attack or discriminate against them.' Reina Sosa, another vendor, said people are less willing to spend money. 'They're saving it in case something happens,' she said, like getting detained by immigration enforcement. Bystanders have captured some of the arrests on video. On Saturday morning, Christian Enrique Carias Torres was detained in another part of the city during a scuffle with ICE agents, and the footage ricocheted around social media. An FBI agent's affidavit said Carias Torres kicked one of the agents in the leg and another was injured when he fell during the struggle and struck his head on the pavement. A stun gun was used to subdue Carias Torres, who was charged Tuesday with resisting arrest. An alphabet soup of federal agencies have been circulating in the city. In the Petworth neighborhood, roughly 20 officers from the FBI, Homeland Security, Park Police and U.S. Marshals descended on an apartment building on Tuesday morning. A man extended his hands out a window while officers cuffed him. Yanna Stelle, 19, who witnessed the incident, said she heard the chatter from walkie talkies as officers moved through the hallways. 'That was too many police first thing in the morning — especially for them to just be doing a warrant," she said. More National Guard troops from other states are slated to arrive From his actions and remarks, Trump seems interested in ratcheting up the pressure. His administration has asked Republican-led states to send more National Guard troops. Mississippi, Tennessee, Louisiana, West Virginia, South Carolina and Ohio have agreed to deploy a total of 1,100 troops to the city, on top of the 800 from the D.C.-based National Guard. Resistance to that notion is starting to surface, both on the streets and in Congress. On Tuesday, Democratic Rep. Sam Liccardo of California introduced a bill that would require a report outlining the cost of any National Guard deployment unrelated to a natural disaster, as well as its legal basis. It would also require reporting on any Guard interactions with civilians and other aspects of the operation. Forty four Democrats have signed on in support, including Congresswoman Eleanor Holmes Norton, Washington's non-voting delegate in the House of Representatives. While the measure stands little chance of passing while Republicans control the chamber, it's a sign of a wider Democratic response to Trump's unprecedented moves in Washington. 'Are L.A. and D.C. a test run for a broader authoritarian takeover of local communities?" Liccardo asked. He added that the country's founders were suspicious of "executive control of standing armies.' Abigail Jackson, a White House spokeswoman, said that 'Democrats continue to side with criminals over law abiding Americans." What kind of assistance will be offered? It's unclear what kind of help the National Guard will be able to provide when it comes to crime. 'The fact of the matter is that the National Guard are not law-enforcement trained, and they're not going into places where they would be engaged in law enforcement activity," said Jeff Asher, a crime analyst and consultant at AH Datalytics. 'So I don't know that it's fair to expect much of it.' Trump declared in a social media post that his initiative has transformed Washington from 'the most unsafe 'city' in the United States' to 'perhaps the safest, and getting better every single hour!' The number of crimes reported in D.C. did drop by about 8% this week as compared to the week before, according to Metropolitan Police data. There was some variation within that data, with crimes like robberies and car thefts declining while burglaries increased a bit and homicides remained steady. Still, a week is a small sample size — far from enough time for data to show meaningful shifts, Asher said. Referring to the month-long period that D.C.'s home rule law allows the president to exert control over the police department, he said: 'I think 30 days is too short of a period to really say anything." ___ Associated Press writers Michael Kunzelman, Alanna Durkin Richer, Jacquelyn Martin and Ashraf Khalil contributed to this report. Solve the daily Crossword

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store