/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Mandiant says dozens of Fortune 100 companies have unwittingly hired North Korean IT workers in a scheme, active since 2018, operated by group UNC5267

It's difficult to imagine a bigger hiring blunder.  —  Google said it has been contacted by several major U.S. companies recently …

The Record Jonathan Greig

Context & Ripple Effects

This report adds named threat-group attribution and a long operating window to an issue U.S. authorities had already framed as a large remote-work fraud operation: the FBI and DOJ warning about thousands of workers using false identities connected the practice to wages flowing back to North Korea.

The breadth beyond a single sector matters. Subsequent reporting that crypto companies also passed fraudulent candidates through interviews and checks suggests ordinary recruiting controls—not merely industry-specific gaps—were being exploited.

First-order effects

  • Companies that employed UNC5267-linked workers must assess whether identities, access privileges, code contributions, and payment flows require review; recruiting and security teams become immediate stakeholders.
  • Mandiant’s attribution gives large employers a concrete threat label and behavioral pattern to incorporate into hiring-screening and insider-risk investigations.

Second-order effects

  • Remote-work vendors, recruiters, and identity-verification providers face pressure to demonstrate that their checks can catch coordinated use of false identities rather than only validate routine applicant documents.
  • Employers may add more verification and access controls for remote technical hires, increasing onboarding friction for legitimate candidates and contractors.

Third-order effects

  • If such operations continue to clear standard hiring processes, employment becomes a more prominent route for state-linked actors to obtain revenue and potential access inside private companies, alongside conventional intrusion methods.
  • The pattern points toward convergence between HR controls and cybersecurity controls: durable defenses will likely require coordinated identity, payroll, endpoint, and access governance rather than isolated background checks.

The trend: Coordinated fraudulent remote hiring is turning workforce identity assurance into a core component of enterprise cyber-risk and sanctions compliance.

Discussion

  • @aptwhatnow @aptwhatnow on x
    The crew is Sleeting on 5267 Chollimas. They're rage quitting them some DPRK IT Workers. The word is out and companies are starting to unravel their schemes slowly but surely. Hopefully a guide like this can help some more. Great work all involved. https://cloud.google.com/...
  • @jinx_soda Joe on x
    DPRK's UNC5267 operations have expanded greatly over the past few years. It is essential to be proactive and detect them in your environment. These operations directly fund North Korea by diverting the paychecks they obtain back to the regime. https://cloud.google.com/...