Skip to content

2024-07-15 (incident) · US · KnowBe4

KnowBe4 catches a North Korean fake IT worker it had hired, 2024

Disclosed by the affected organisation.

KnowBe4 hired a remote principal software engineer for its internal IT AI team after four video interviews and background checks, which came back clear because the person used a valid but stolen US-based identity, with a photo that was AI enhanced from stock photography. On 15 July 2024, soon after the company workstation arrived, KnowBe4's EDR software detected the person loading malware, and its security team contained the device about 25 minutes after the activity began. KnowBe4 said no illegal access was gained and no data was lost, identified the hire as a North Korean fake IT worker, and shared its findings with Mandiant and the FBI.

Timeline

  1. 2024-07-15 At 9:55 pm EST suspicious activity begins on the new hire's workstation; the security team contains the device at about 10:20 pm.
  2. 2024-07-23 KnowBe4 publishes an account of the incident.
  3. 2024-10-19 KnowBe4 updates the account with changes it recommends to hiring processes.

Lessons

Scam types: North Korean fake IT workers

Sources

  1. KnowBe4: How a North Korean fake IT worker tried to infiltrate us (Company disclosure, primary, accessed 2026-09-24)