US-based security vendor KnowBe4 says it unwittingly hired a North Korean hacker who then unsuccessfully attempted to load malware into the company's network
KnowBe4, which provides security awareness training, was fooled by stolen ID. — KnowBe4, a US-based security vendor …
Ars Technica Jon Brodkin
Related Coverage
- View article KnowBe4
- Security biz KnowBe4 hired fake North Korean techie, who got straight to work ... on evil The Register · Laura Dobberstein
- Security Firm Discovers Remote Worker Is Really a North Korean Hacker PCMag · Michael Kan
- KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware SecurityWeek · Ryan Naraine
- Cyber firm KnowBe4 hired a fake IT worker from North Korea CyberScoop · Mbracken
- KnowBe4 mistakenly hires North Korean hacker, faces infostealer attack BleepingComputer · Bill Toulas
- North Korean Hackers Targeted Cybersecurity Firm KnowBe4 with Fake IT Worker Infosecurity · James Coker
- North Korean Fake IT Worker FAQ KnowBe4 Security … · Stu Sjouwerman
- North Korean workers infiltrate cyber industry Axios · Sam Sabin
- KnowBe4 Uncovers Fake Employee: How a North Korean Hacker Was Hired into the Team The Cyber Express · Avantika
- US Cybersecurity Firm Accidentally Hires North Korean Hacker Tech.co · Adam Rowe
- North Korean Fake IT Worker Dupes Security Firm: A Wake-Up Call For Employers Forbes · Alonzo Martinez
- CrowdStrike Explains How ‘Unexpected Exception’ Crashed Nearly Nine Million Windows Machines Metacurity · Cynthia B Brumfield
- Cybersecurity Firm KnowBe4 Tricked into Hiring North Korean Hacker as IT Pro Hackread · Waqas
- A US security firm was tricked into hiring a North Korean hacker who installed malware TechSpot · Rob Thubron
- Security Firm Accidentally Hires North Korean Hacker, Did Not KnowBe4 Dark Reading · Elizabeth Montalbano
- KnowBe4 Unknowingly Hired Fake North Korean IT Worker Security Boulevard · Jeffrey Burt
- KnowBe4 targeted by fake North Korean IT worker SC Media · Laura
- How The Whole World Now Knows About Fake North Korean IT Workers KnowBe4 Security Awareness … · Stu Sjouwerman
- Wild, true story from the security awareness and training company KnowBe4 that details how they inadvertently hired a North Korean hacker who was posing as a Western tech worker. — Kudos to them for publishing this. If it can happen to a security awareness company, it can happen to anyone (full disclosure: they've been an advertiser on my site for ages). … @briankrebs@infosec.exchange · BrianKrebs
- I think it's time for an InfoSecIsGoingJustGreat account. — https://arstechnica.com/... #infosecisgoingjustgreat @postmodern@infosec.exchange
- Huh, this is interesting from KnowBe4 on how a Fake IT worker working out of North Korea attempted an insider threat attack. — The company states “No illegal access was gained, and no data was lost or compromised”. — “KnowBe4 needed a software engineer for our internal IT AI team. … @dannyjpalmer@infosec.exchange · Danny Palmer
- KnowBe4 hired a software engineer. As soon as they received their laptop the SOC light up like a christmas tree because of the malware it was loading up. — Working with Mandian and the FBI, it turned out it was a fake IT worker from N. Korea. — https://blog.knowbe4.com/... @Javvad@infosec.exchange
- KnowBe4: How a North Korean Fake IT Worker Tried to Infiltrate Us — A software engineer newly hired for KnowBe4's internal AI team triggered SOC alerts for loading malware onto their Mac workstation. Upon questioning the remote employee, it was discovered that he was a North Korean IT worker using a stolen U.S. identity. … @screaminggoat@infosec.exchange
- Absolute epic fail 🤦♂️ — “KnowBe4 needed a software engineer for our internal IT AI team. We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person. … @elgg@indieweb.social
- “How a North Korean Fake IT Worker Tried to Infiltrate Us” — https://blog.knowbe4.com/... This is all sorts of yikes. Both on the malware actor side and the prospective employer. @baldur@toot.cafe · Baldur Bjarnason
- The wild story of how KnowBe4 hired a software engineer, shipped him a MacBook Pro, immediately found malware on it, and then quickly discovered that they had actually hired a North Korean fake IT worker https://blog.knowbe4.com/... @micahflee@infosec.exchange · Micah Lee
- #NorthKorean #hacker got hired by US #security vendor, immediately loaded #malware https://arstechnica.com/... @PrivacyDigest@mas.to
- The stunning naivete of KnowBe4 and Stu, their CEO: — They get breached by a DPRK-aligned actor, and the conclusion they draw is that the person was just doing remote work scam. — Why would someone who's just here to fund the government install malware and risk calling all kinds of attention to themselves? … @chrismerkel@infosec.exchange · Chris Merkel
- KnowBe4 hired a software engineer. As soon as they received their laptop the SOC light up like a christmas tree because of the malware it was loading up. … Javvad Malik
- Wow! The infiltrators are amongst us! — What a story from KnowBe4's own Blog of a “Trojan Horse” applying for a job! — Add that to your Supply Chain Assurance Process! … Shaun van Niekerk
- One the best parts of the KnowBe4 culture is the radical transparency from our CEO, Stu Sjouwerman, SACP, especially when it's a learning opportunity. … James McQuiggan
- Wild, true story from the security awareness and training company KnowBe4 that details how they inadvertently hired a North Korean hacker who was posing as a Western tech worker. … Brian Krebs
- How a North Korean Fake IT Worker Tried to Infiltrate Security Awareness Firm KnowBe4 Beehaw
- How a North Korean Fake IT Worker Tried to Infiltrate Us Lobsters
Discussion
-
@waldoj@mastodon.social
Waldo Jaquith
on mastodon
My takeaway from this story: remote identity proofing is, indeed, well and truly busted. https://arstechnica.com/...
-
@gcluley@mastodon.green
Graham Cluley
on mastodon
US-based KnowBe4 thought they were hiring a Western software engineer. Turned out he was actually a North Korean hacker, using a valid but stolen identity and an AI-enhanced mugshot. — Kudos to KnowBe4 for talking about it, and a warning to others. — https://blog.knowbe4.com…
-
@jsrailton
John Scott-Railton
on x
WILD: Security awareness training firm @KnowBe4 was tricked into hiring a North Korean. Passed all employment checks & video interviews. Used AI-manipulated photo. Company says: caught early when someone started loading malware onto work issued laptop. Says no data lost or [image…
-
@malwarejake
Jake Williams
on x
The wildest thing about the KnowBe4 “we accidentally hired a North Korean threat actor as an engineer” story is that the SOC immediately caught it, followed their instincts, and escalated immediately. In post mortems for most serious incidents, there's an ignored alert.
-
@vxunderground
@vxunderground
on x
Yesterday KnowBe4 disclosed a cyber-security-incident where a North Korean national successfully infiltrated KnowBe4 ... by applying for a job there, interviewing, and getting hired. Their blog post highlights North Korean identity fraud techniques. https://blog.knowbe4.com/...
-
@joetidy
Joe Tidy
on x
Wow. This is amazing from @KnowBe4 - How a North Korean Fake IT Worker Tried to Infiltrate Us. “We sent them their Mac workstation, and the moment it was received, it immediately started to load malware.” https://blog.knowbe4.com/...
-
@knowbe4
@knowbe4
on x
Want to know how a North Korean Fake IT Worker tried to infiltrate us? Learn all about this new story on the blog: https://blog.knowbe4.com/...
-
@racheltobac
Rachel Tobac
on x
Whoa — a North Korean attacker attempted to hack KnowBe4 and gain access through their employment process. I talked about my employment based social engineering attacks in @DarknetDiaries in case you want to hear more about that attack vector below! https://blog.knowbe4.com/...
-
r/cybersecurity
r
on reddit
North Korean hacker got hired by US security vendor, immediately loaded malware | Ars Technica
-
r/cybersecurity
r
on reddit
Breaking: KnowBe4 North Korean IT Worker Infiltration
-
r/nottheonion
r
on reddit
North Korean hacker got hired by US security vendor, immediately loaded malware
-
r/technology
r
on reddit
North Korean hacker got hired by US security vendor, immediately loaded malware
-
r/nottheonion
r
on reddit
North Korean hacker got hired by US security vendor, immediately loaded malware