Security-training firm KnowBe4 hired a remote software engineer who passed video interviews, background checks and reference checks — but was actually a North Korean threat actor using a stolen US identity and an AI-enhanced profile photo built from stock imagery. Once his company laptop arrived, he immediately began loading malware and manipulating session-history files.
AIC-0023 S3 · Serious
KnowBe4 unknowingly hires North Korean operative using AI-enhanced fake identity
- Harm
- Attempted infrastructure compromise and part of a wider DPRK scheme that funneled millions to North Korea via fraudulent IT employment; no customer data reached.
- Detection
- KnowBe4's EDR flagged anomalous activity within minutes; the laptop was contained ~25 minutes after the alert on 2024-07-15.
- Outcome
- Access locked down; KnowBe4 published a warning. Aligns with US DOJ charges/seizures targeting the DPRK fake-IT-worker pipeline.
A documented entry in the AI Crime Registry, a Defici non-profit initiative. Sourced from public reporting; corrections: [email protected].