Firm hacked after accidentally hiring North Korean cyber criminal

Firm hacked after accidentally hiring North Korean cyber criminal


Since 2022, authorities and cyber defenders have warned about the rise of secret North Korean workers infiltrating western companies.

The US and South Korea accuse North Korea of tasking thousands of staff to take on multiple well-paid western roles remotely to earn money for the regime and avoid sanctions.

In September cyber security company Mandiant said dozens of Fortune 100 companies have been found to have accidentally hired North Koreans.

But secret IT workers turning on their employers with cyber attacks is rare, according to Rafe Pilling, Director of Threat Intelligence at Secureworks.

“This is a serious escalation of the risk from fraudulent North Korean IT worker schemes,” he said.

“No longer are they just after a steady pay check, they are looking for higher sums, more quickly, through data theft and extortion, from inside the company defences.”

The case comes after another North Korean IT worker was caught attempting to hack their employer in July.

The IT worker was hired by the cyber company KnowBe4, which quickly disabled access to their systems when it noticed strange behaviour.

“We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person,” the firm wrote in a blog post.

“We sent them their Mac workstation, and the moment it was received, it immediately started to load malware (malicious software).”

Authorities are warning employers to be vigilant about new hires if they are fully remote.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.