In a startling turn of events, KnowBe4 (www.KnowBe4.com), a leading cybersecurity awareness training company, recently uncovered an elaborate scam when it unwittingly hired a North Korean spy. This incident (https://apo-opa.co/47eiR1n) has sent shockwaves through the business community, highlighting the growing risks associated with remote hiring practices in an increasingly digital world.
The incident occurred in July when the cybersecurity firm’s US branch hired what appeared to be a qualified candidate for a remote position. Despite rigorous background checks and video interviews, the fraudster infiltrated the company by leveraging a stolen US identity. Using a virtual private network (VPN) and logging in at night from wherever he physically was (either China or North Korea), the imposter convincingly portrayed themselves as working from the United States.
Anna Collard, SVP Content Strategy & Evangelist at KnowBe4 AFRICA, explains, “Technology is making it easier for bad actors to infiltrate your organisation. They use sophisticated strategies helped by artificial intelligence (AI) to create fake, but believable identities which get them hired and then use proxies in country to gain access to the company’s IT systems.”
KnowBe4 uncovered the deception when the company-provided laptop immediately began downloading malware upon first use. Fortunately, KnowBe4’s security measures detected the attempted attack early, and they prevented any data compromise. However, the incident has raised serious concerns about the vulnerabilities in remote hiring processes, even for companies specialising in cybersecurity.
Lessons learnt
As the digital landscape evolves, so too must our approach to safeguarding our organisations against increasingly cunning threats
The incident gave KnowBe4 a lot to think about and a chance to discuss how they could enhance their hiring process. “For a cybersecurity company like us to get caught with egg on our face was a big wake-up call,” admits Collard. “We could have kept quiet, but instead we shared our story hoping other organisations could learn from it.”
As a result, KnowBe4 implemented several process changes to catch this kind of incident earlier. “For example, in the US, we will only ship new employee workstations to a nearby UPS shop and require a picture ID,” she says.
Red flags and safeguards
Because of sophisticated technology, it’s difficult for companies who are hiring to distinguish between who is real and who is fake. “Some methods fraudsters use include fake identities and relying on AI images to evade detection. Their motive is usually to gain access to sensitive company data, either for financial gain or to support the North Korean regime (https://apo-opa.co/3X3wPOY).”
Despite what they are up against, organisations can still outfox these fraudsters, provided the right HR measures are in place.
Conclusion
The KnowBe4 incident serves as a stark reminder of the growing challenges in remote hiring and cybersecurity. As organisations continue to adapt to a global workforce, the need for robust security measures has never been more critical.
“Your HR and IT processes need to work in tandem and be watertight when recruiting,” concludes Collard. “By adopting stringent security practices and remaining vigilant, companies can mitigate the risks associated with remote hiring and protect themselves from sophisticated scams.”
This wake-up call underscores the importance of continuous improvement in security protocols, even for industry leaders. “As the digital landscape evolves, so too must our approach to safeguarding our organisations against increasingly cunning threats.
Distributed by APO Group on behalf of KnowBe4.