2024-07-15 (incident) · US · KnowBe4
KnowBe4 catches a North Korean fake IT worker it had hired, 2024
Disclosed by the affected organisation.
KnowBe4 hired a remote principal software engineer for its internal IT AI team after four video interviews and background checks, which came back clear because the person used a valid but stolen US-based identity, with a photo that was AI enhanced from stock photography. On 15 July 2024, soon after the company workstation arrived, KnowBe4's EDR software detected the person loading malware, and its security team contained the device about 25 minutes after the activity began. KnowBe4 said no illegal access was gained and no data was lost, identified the hire as a North Korean fake IT worker, and shared its findings with Mandiant and the FBI.
Timeline
- 2024-07-15 At 9:55 pm EST suspicious activity begins on the new hire's workstation; the security team contains the device at about 10:20 pm.
- 2024-07-23 KnowBe4 publishes an account of the incident.
- 2024-10-19 KnowBe4 updates the account with changes it recommends to hiring processes.
Lessons
- Check that a candidate's name, photo and documents are consistent across every stage of hiring, not only that a background check passes.
- Ship new starters' equipment only to a verified home address; KnowBe4 says these workers use laptop farms and connect remotely.
- Give new hires minimal access at first and alert on malware or unusual activity from new devices, as KnowBe4's EDR did.
Scam types: North Korean fake IT workers
Sources
- KnowBe4: How a North Korean fake IT worker tried to infiltrate us (Company disclosure, primary, accessed 2026-09-24)