North Korean IT workers infiltrating US companies and government agencies points at a threat model most security teams still aren’t built for: the attacker doesn’t break in, they get hired. Once someone clears interviews and onboarding, they inherit the same trust as any other employee, and almost nobody re-verifies that trust after week one.
The State Department put out (yet another) warning about this here: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers – United States Department of State
In the warning there’s this:
Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.).
Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:
“This isn’t a hacking story. It’s a hiring failure with a nation-state attached. North Korean IT workers are getting through interviews, background checks, and onboarding because most companies still treat identity verification as a one-time gate instead of continuous evidence. Once that person is on payroll, they inherit the same trust as every other employee, and almost nobody re-checks that trust after day one.
The real gap is systemic. Organizations verify a document once, verify a face on a video call once, and then assume the risk is closed. It isn’t. Identity is not static and access should not be either. A hire that looked clean in week one can still be sitting on infrastructure tied to a sanctioned state a year later, and nobody is watching for it because nobody built a control for it.
The fix isn’t a smarter background check vendor. It’s treating high-access hiring as a compliance surface with ongoing evidence, not a one-time HR checkbox. Location consistency, device behavior, and access patterns need to be monitored the same way you’d monitor a production system, because at this point, that new hire effectively is one.”
North Koreans are here today and it is time to kick them out today. Because if they are still present tomorrow, it is one day too many.
Related
This entry was posted on August 13, 2026 at 12:48 pm and is filed under Commentary with tags North Korea. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The North Korea Hiring Problem
North Korean IT workers infiltrating US companies and government agencies points at a threat model most security teams still aren’t built for: the attacker doesn’t break in, they get hired. Once someone clears interviews and onboarding, they inherit the same trust as any other employee, and almost nobody re-verifies that trust after week one.
The State Department put out (yet another) warning about this here: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers – United States Department of State
In the warning there’s this:
Companies operating online platforms should continue to strengthen their countermeasures, such as enhancing identity verification procedures (strict review of identification documents, requirement of in-person interviews, etc.) and detecting suspicious accounts (introduction of systems that notify anomalous information entries, etc.).
Justin Beals, CEO & Founder, Strike Graph, an AI-native GRC and compliance automation platform had this to say:
“This isn’t a hacking story. It’s a hiring failure with a nation-state attached. North Korean IT workers are getting through interviews, background checks, and onboarding because most companies still treat identity verification as a one-time gate instead of continuous evidence. Once that person is on payroll, they inherit the same trust as every other employee, and almost nobody re-checks that trust after day one.
The real gap is systemic. Organizations verify a document once, verify a face on a video call once, and then assume the risk is closed. It isn’t. Identity is not static and access should not be either. A hire that looked clean in week one can still be sitting on infrastructure tied to a sanctioned state a year later, and nobody is watching for it because nobody built a control for it.
The fix isn’t a smarter background check vendor. It’s treating high-access hiring as a compliance surface with ongoing evidence, not a one-time HR checkbox. Location consistency, device behavior, and access patterns need to be monitored the same way you’d monitor a production system, because at this point, that new hire effectively is one.”
North Koreans are here today and it is time to kick them out today. Because if they are still present tomorrow, it is one day too many.
Share this:
Like this:
Related
This entry was posted on August 13, 2026 at 12:48 pm and is filed under Commentary with tags North Korea. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.