Skip to main content

A Perfect Hire

On July 15, 2024, a Florida-based security awareness company called KnowBe4 onboarded a new Principal Software Engineer for its internal IT AI team. Everything about the hire was, in the CEO’s own words, “clean.” The candidate’s résumé passed initial screening. Four separate video interviews were conducted on four separate days, and each time the person on the other end of the camera matched the professional headshot on the application. Background checks came back clear. References checked out. The macOS workstation was shipped to the address on file, tracked, delivered, and unboxed.

Twenty-five minutes after the machine came online, KnowBe4’s endpoint detection and response (EDR) telemetry began firing. Session history files were being manipulated. Unauthorized software was being staged. Files that did not belong on a first-day employee’s laptop were quietly landing in unexpected directories. The Security Operations Center called the “new hire” to ask about the anomalies. He replied that he was following a router troubleshooting guide, an explanation that did not add up to what the security team observed in their logs.

The person who had passed the multi-step hiring process, the person whose Social Security Number KnowBe4’s HR system was already preparing to remit taxes to, was a North Korean operative using a stolen U.S. identity and an AI-touched-up stock photograph. The stolen identity was real, while the picture was a fake that was easier to detect, once you knew the tells.

That's the mechanics behind the North Korean IT worker scheme, a state-sponsored effort that uses stolen identities and AI-altered photos to land real jobs, then routes the paycheck back to fund the regime's weapons programs. The part worth sitting with, more than the geography, is what it says about validation: a hiring process that looked thorough on paper and had never really been tested against a threat built to get past it.

KnowBe4’s founder and CEO Stu Sjouwerman did something unusual in this business: he wrote it down and published it. His words are worth reading in full because they are a key characterization of this entire campaign:

"First of all: No illegal access was gained, and no data was lost, compromised, or exfiltrated on any KnowBe4 systems. This is not a data breach notification, there was none. See it as an organizational learning moment I am sharing with you. If it can happen to us, it can happen to almost anyone. Don't let it happen to you."

— Stu Sjouwerman, Founder and CEO, KnowBe4

KnowBe4 is a cybersecurity company, and its entire business model is teaching other companies how to spot social engineering. And it hired a fake employee whose employer of record was, ultimately, the Reconnaissance General Bureau of the Democratic People’s Republic of Korea.

The scheme that placed that operative inside KnowBe4 was not a “hacker” in the way most executives still picture the word. There was no laptop with white text scrolling on a black screen, no one in a hoodie punctuating their success with a menacing “I’m in” catchphrase. There was a résumé, an interview, and a stolen driver’s license. And behind all of it a nation-state apparatus with sanctioned shell companies in China and Russia, identity brokers in Ukraine, laundering nodes in Laos and the UAE, and a chain of witting and unwitting Americans hosting the physical laptops in their homes. The candidate performed like a normal hire because he was supposed to. In this campaign, being productive is the tradecraft.

The Campaign, in Numbers Big Enough to Take Seriously

The U.S. Department of the Treasury, in the March 12, 2026 press release accompanying a new round of designations under Executive Orders 13810 and 13382, put the operation’s revenue for a single year on the record at nearly $800 million in 2024.

The State Department’s DPRK sanctions record, briefing the United Nations in January 2026 on the joint findings of an 11-nation Multilateral Sanctions Monitoring Team, put the workforce estimate at 1,000 to 1,500 based in China alone, and noted DPRK’s plans to send up to 40,000 laborers, including IT workers, to Russia. The U.N. Panel of Experts had earlier estimated the deployed workforce as high as 10,000 individuals globally.

The Department of Justice was more specific. In its December 12, 2024 indictment of 14 North Korean nationals working out of the sanctioned front companies Yanbian Silverstar and Volasys Silverstar, prosecutors documented $88 million in wages over six years, with individual workers under standing orders to earn at least $10,000 per month. In July 2025, DOJ sentenced Christina Marie Chapman of Arizona to 102 months in federal prison for running a domestic “laptop farm” that placed North Korean operatives inside 309 U.S. businesses and two international ones, generating over $17 million for Pyongyang. Chapman’s client list included, per court documents, a top-five U.S. television network, a Silicon Valley technology company, an aerospace manufacturer, an American automaker, a luxury retailer, and a U.S. media and entertainment giant.

The FBI’s own assessment in its January 23, 2025 Public Service Announcement was that after these operatives are discovered on victim networks, they have moved past passive wage collection into data extortion, publicly leaking proprietary source code when ransoms go unpaid.

And then there is the private sector’s more general view. Mandiant CTO Charles Carmakal, briefing reporters at RSAC 2025, offered a perspective grounded in the firm’s incident-response data:

“Almost every CISO of a Fortune 500 company that I’ve spoken to has admitted they had a North Korean IT worker problem.”

Google Cloud’s senior director of security engineering, Iain Mulholland, offered the corollary at the same event:

“If you’re not seeing this, it’s because you’re not detecting it, not because it’s not happening to you.”

An Awareness Guide for Small Businesses

Because cryptocurrency theft is a major source of revenue for the regime, DPRK IT worker operators prefer to land in, adjacent to, or upstream from a firm that operates in the crypto space. That said, they ultimately do not care whether you are a Fortune 500 firm or a 40-person managed service provider. They care whether you hire remote developers, whether your onboarding is standardized enough to be gamed, and whether your identity verification will unwittingly accept a stolen driver’s license. In the KnowBe4 case, the target was a mid-market cybersecurity company. In the LND.fi case, the target was a small blockchain project. In the Chapman case, the targets included small nonprofits sitting alongside multinationals on the same laptop farm.

 

The Productivity Paradox

After passing through the filters associated with the hiring process, the reason so many of these hires survive months or years inside Western companies is that they are, by conventional performance measures, good employees.

This is a frequent finding of investigators with hands-on incident response experience against this campaign. Mandiant’s Carmakal went further, noting on LinkedIn that in the majority of investigations they run, the North Korean operative is not doing anything malicious at all, they are just delivering code and collecting a paycheck. That is what makes this class of insider threat so challenging for HR and security teams to detect.

Waiting for the DPRK operative to underperform, to miss standups, or to ship buggy code is waiting for a signal that will not arrive in most cases. Nisos investigators watching their subject “Jo” for weeks in 2025 described him in the NBC News writeup as a “hard worker… rose early, usually by 5 a.m. ET, and worked late into the night, often six days a week… always professional.” That is the profile of the person most managers would promote.

Which means the detection burden shifts entirely to identity, infrastructure, and behavioral telemetry—the things a productive employee cannot easily hide.

 

The Major Vulnerability Is the Space Between Your Teams

Echoing most effective espionage or criminal operation, the DPRK IT worker scheme is designed to exploit the seams between security controls and oversight mechanisms.

The disclosed cases show a consistent pattern. HR owns the résumé and the interview. IT owns provisioning and the laptop shipment. Cybersecurity owns the EDR and network telemetry. The insider threat program (if one exists at all) owns behavioral monitoring after the badge is issued. Legal and compliance own the sanctions posture. And in most organizations these functions live on different platforms, report through different chains, meet on different cadences, and share almost no operational signal with each other.

That gap is the operator’s actual target. Consider what these gaps look like in practice:

  • The HR-to-IT seam is where a résumé passes screening and a laptop ship-to address quietly diverges from the government-ID address on file, because the HR system and the asset management system are not talking to each other.

  • The IT-to-cybersecurity seam is where remote monitoring and management (RMM) software gets installed inside the first hour of laptop activation, but the SOC has no baseline for what a “normal first day” looks like, because IT provisioning noise has been filtered out of the SIEM as tuning cruft.

  • The cybersecurity-to-HR seam is where an EDR sees an anomaly, HR sees a productive employee, and no one at the table connects “high output at odd hours from unusual IP ranges” to “possible foreign insider.” This is where the productivity paradox does its worst damage. The performance-review cycle actively works against detection here: a manager who is happy with the deliverables becomes an unwitting character witness for the operator.

  • The onboarding-to-continuous-monitoring seam is where the vetting rigor of week one evaporates by month three, and the DPRK operator settles in for a two-year run, often having earned a positive first performance review by then.

The Background Check Is a Screen That Cannot Keep Up; the Camera Is Next

The threat actors’ campaign is bypassing the two controls most organizations lean on hardest for remote hires: the background check and the video interview.

The background check is failing because the identity is real. Stolen identity packages sold on Telegram now cost roughly $120 for a genuine U.S. driver’s license, matching Social Security Number, and a corroborating selfie, according to Nisos research documented in June 2026. Because the SSN belongs to a real American with a real credit history, a standard background check performed against that identity passes cleanly. Every disclosed case involved a stolen but valid U.S. identity that survived vendor screening. If your last line of hiring defense is a third-party background check, it is far less effective against an organized, nation state-backed effort like the DPRK’s IT worker scheme.

The video interview is next, and the timeline is much shorter than most HR teams anticipate. Palo Alto Networks Unit 42 confirmed in April 2025 that DPRK IT workers had already begun deploying real-time deepfake technology in Zoom and Teams interviews. More alarmingly, Unit 42’s own researchers built a working real-time deepfake with a five-year-old consumer GPU in seventy minutes using only publicly available tools, proving that the cost of fooling a hiring manager on a Zoom call has decreased significantly. In one case documented in The Pragmatic Engineer and analyzed by Unit 42, a Polish AI firm was targeted by what appeared to be two separate candidates that were, in fact, the same operator running two deepfaked personas across two interviews for the same role.

That was April 2025, the leading edge of the technique’s adoption.

Fast-forward to May 2026: 404 Media’s Joseph Cox obtained and tested a Chinese-language commercial real-time deepfake product called “Haotian AI,” marketed openly to scammers and priced within reach of virtually any threat actor. Haotian AI was purpose-built to work on WhatsApp, Microsoft Teams, Zoom, TikTok, Instagram, and YouTube, and passed the pinch, cover-face, and chin-stroke tests that were, until recently, the industry’s go-to “wave your hand in front of your face” deepfake detection heuristics.

404 Media traced Haotian AI to Chinese money-laundering networks and to the ecosystem of scam compounds operating out of Southeast Asia. The software has already generated more than $4 million for its creators, and is largely built on open-source face-swap models, meaning its actual value proposition to buyers is technical support and turnkey usability, not proprietary AI. That is what turns a nation-state capability into a commodity: the moment the hard part becomes customer service, every scammer with a gaming laptop is playing at Pyongyang’s level.

Because background checks pass, video calls can no longer be trusted, and performance reviews will actively vouch for the operator, additional layered vetting methods must become mandatory for any remote hire with production access. That means at least two of the following applied to every offer: an in-person or notarized identity verification at a bank or law office, a live local-knowledge probe conducted by someone who can pattern-match a coached answer, a same-day address-of-record confirmation matched against the government-ID address, a hardware token issued in person, and a delayed first-day access grant that gives IT and security time to validate the person on the laptop is the person from the interview.

Coinbase abandoned its remote-first hiring model for sensitive roles specifically because of this threat. Coinbase now requires in-person orientation in the United States, U.S. citizenship for anyone with access to sensitive systems, and fingerprinting on hire. That is a Fortune 500 crypto exchange making the call. If you run a 40-person software company, the calculus is not different; the resources to respond are.

The practical playbook below is organized around closing the seams and upgrading the parts of the funnel that Pyongyang has already outrun, including the assumption that a productive employee is a trustworthy one.

For HR and Talent Acquisition

  • Treat the interview as a security control, not a courtesy conversation. A reliable detection method across the KnowBe4, Kraken, and Nisos investigations was a live local-knowledge question the candidate could not answer without coaching. Ask about the weather. Ask about a made-up local event. Ask them to name a restaurant near the address on their résumé. Nisos caught its operative by asking about a hurricane that never happened.

  • Assume the background check has already passed a stolen identity. Because the underlying SSN is genuine, a standard vendor screen is not a control against DPRK IT worker hiring. Layer at least one identity control the campaign cannot forge remotely: notarized ID, in-person or bank-witnessed verification, or hardware-token issuance conducted in person.

  • Stop trusting “the camera was on” as identity verification. With commercial tools like Haotian AI now available for the price of a mid-range laptop, a live video feed is no longer proof that the person you interviewed is the person you are hiring. Require the candidate to physically hold their ID up to the lens on a specific prompt (not on request), ask them to look around the room, and make at least one final-stage interview an in-person or proctored encounter for any role with production access.

  • Do not treat a strong first performance review as clearance. Mandiant, DTEX, Google Cloud, and multiple defector interviews all confirm that DPRK operatives are frequently rated as productive, even excellent, employees, because delivering the work is the tradecraft. A glowing 90-day review is not evidence of legitimacy; it is evidence that the person is meeting Pyongyang’s quota.

  • Cross-check the résumé’s contact information against social and professional footprints. A brand-new email with no breach history, a VoIP phone number, and a LinkedIn profile with fewer than 50 connections is a pattern, not a coincidence.

  • Verify prior employment and higher education by direct outreach, not by relying on documentation the candidate provides. Stolen identity packages sold on Telegram now cost roughly $120 and include a real SSN. A background check performed against the stolen identity will pass.

  • Forward every hiring artifact to security by default. Interview recordings, résumés, digital-footprint notes, and shipping addresses should be automatically ingested by the SOC and the insider threat program.

For Security and IT Operations

  • Ship laptops only to the address on the government-issued ID. If the candidate asks for a different address, treat it as a hard stop, not a customer service ticket. The FBI’s July 2025 IC3 advisory identified reshipment requests as the single most common signature of a laptop-farm hire.

  • Instrument the first 24 hours of a new device’s life aggressively. In the KnowBe4 case, the EDR fired in under 25 minutes. If your endpoint tooling cannot alert on unauthorized RMM software (AnyDesk, TeamViewer, RustDesk) installed by a first-day user, fix it immediately.

  • Build a shared “day-one” runbook that IT provisioning and the SOC own together. Every new-hire laptop should be baselined with an expected activation window, a known geolocation, and a defined set of installed software. Anything outside that envelope during the first week is an escalation, not a ticket.

  • Watch for hardware keyboard-video-mouse (KVM) devices. Mandiant has observed a shift from software-based remote access to PiKVM-style hardware because it evades EDR entirely. USB device fingerprinting is now a legitimate hiring-security control.

  • Geolocate corporate laptops on a schedule. If the device consistently reports from an ASN associated with Astrill VPN, the DPRK IT worker VPN of choice per multiple threat intel firms, you have your answer.

 

For Insider Threat Programs (or the Team Doing Its Job Without the Title)

  • Correlate HR events with security telemetry, this is the single highest-leverage change most organizations can make. New-hire status, address changes, direct-deposit changes, and PTO patterns should be first-class signals in your SIEM alongside authentication, EDR, and network data. DPRK operators exhibit a distinctive pattern: heavy output during off-hours, near-zero collaborative activity (no chat messages, no calendar meetings, no internal email), and repeated banking-site access from the corporate device.

  • Build detections for “productive but isolated.” Because DPRK operatives are often shipping real code, the tell is not underperformance, it is asymmetric performance. High commit volume with zero Slack/Teams engagement, off-hours-only activity, no calendar meetings accepted, no participation in team standups: these are the signals a performance review will miss but a behavioral analytics platform can catch.

  • Retain every interview recording for the full statute-of-limitations window. As the deepfake threat matures, comparing a month-one interview recording against a month-six one is one of the few remaining ways to spot persona drift. Recordings deleted at 30 days for storage cost reasons will not be available when you need them.

  • Establish a monthly cross-functional review of anomalies that individually don’t warrant a ticket but collectively describe a risk pattern, the HR-security-IT-legal huddle that virtually none of the disclosed victim organizations had in place before their incident.

  • Assume the vetting standard for a remote hire on month three should be the same as month one. DPRK operatives frequently pass initial interviews cleanly, deliver strong early performance, and only degrade behaviorally once they believe they are no longer being watched, or pivot to extortion after termination.

For Legal and Compliance

  • Understand that hiring one of these workers is a sanctions matter, not just a fraud matter. OFAC has been clear across every 2018-through-2026 designation: payment to a DPRK national, even unwitting payment, is a strict-liability civil violation under the DPRK sanctions regime. Consider building voluntary self-disclosure into your incident response playbook now, before you need it.

  • Preserve interview recordings and application materials. In every disclosed case that led to indictments, retained HR artifacts became the foundation of the government’s case. If your data retention policy currently deletes interview recordings after 30 days, revisit that.

  • Sit at the security table, not next to it. Nearly every organization that discovered a DPRK hire late did so because the legal function was looped in after remediation began. By then, the OFAC disclosure clock was already running.

  • Prepare for the extortion phase. Since January 2025, the FBI has documented a clear pivot from passive wage collection to public source-code release when victims discover and terminate the operative. Legal, communications, and security should have a joint tabletop on that scenario before it arrives unannounced.

A Closing Note

The most important quality of this campaign is also its most easily missed one: it depends entirely on the assumption that its victims will not talk about it. Every disclosed case has come from an organization that chose transparency over embarrassment. Every one of those disclosures has made every other defender in the industry meaningfully safer.

If you find one of these hires inside your organization, the most valuable thing you can do after containment, after the FBI call, after the OFAC conversation, and the internal AAR to close the process gaps, is Stu Sjouwerman’s move. Write it down. Publish it. Tell your peers what the résumé looked like, what the interview cadence felt like, what the first thirty minutes on the laptop showed you. Note whether their standups were on time and whether their pull requests merged cleanly, because the next defender needs to know that the productive employee is now the profile to worry about.

The campaign is quiet because we let it be. It doesn’t have to stay that way.

If any part of this looks familiar in your own hiring process, talk to Cyberleaf and we’ll walk through where the gaps tend to sit in a setup like yours.

 


 

Frequently Asked Questions

How do North Korean IT workers get past a standard background check?

The identity being checked is usually real. Stolen U.S. identity packages, including a valid Social Security number and driver’s license, sell for as little as $120 on Telegram. A vendor screen run against a genuine identity passes, regardless of who’s holding it.

Is a video interview still reliable proof of who someone is?  

Not on its own anymore. Commercial real-time deepfake software, some of it available for a few hundred dollars, can convincingly alter a candidate’s face and expressions live on Zoom, Teams, or WhatsApp, and has already defeated common checks like asking someone to cover their face or wave a hand across the screen.

What’s the clearest warning sign of a fraudulent remote hire?  

Counterintuitively, it’s rarely poor performance. The stronger signal is high output paired with almost no collaboration: no standups, no chat activity, no calendar meetings, and work concentrated in off-hours.