Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

North Korea's secret IT workforce bypasses security checks by paying Americans to act as "facilitators." These individuals host company-issued laptops in the US, allowing overseas workers to remote-in and appear as domestic employees, creating a critical vulnerability in remote hiring and IT security protocols.

Related Insights

A sophisticated threat involves state-sponsored actors from the DPRK using AI interview tools and virtual backgrounds to pass hiring processes. They get hired, receive company laptops, and then operate as insider threats, creating a significant and often undetected security risk for organizations.

Restricting advanced AI models to U.S. citizens is a flawed security strategy. The policy is easily circumvented by hiring a "traitorous American" to leak access or faking citizenship, making it more of a symbolic gesture than an effective control against determined adversaries.

The problem of fake job applicants has escalated from an HR nuisance to a national security issue. State actors, like North Korea, are weaponizing AI to submit thousands of applications for remote IT jobs to infiltrate corporate systems, forcing companies to treat recruitment screening as a security function.

Amidst complex AI-driven infiltration tactics by state actors posing as remote employees, CrowdStrike's CEO says a top best practice is shockingly simple: meet every new hire in person once. This single step can deter bad actors who rely on anonymity and can't risk revealing their identity, solving the problem before it starts.

Beyond typical IP theft, North Korea runs a program where state-backed operators secure remote tech jobs in Western companies. Their goal is not just espionage but also earning salaries to directly fund the regime, representing a unique and insidious state-sponsored threat.

Beyond official agreements for data access, governments recruit insiders within tech firms. They create informal channels by exploiting personal vulnerabilities, such as offering medical treatment for a family member in exchange for cooperation.

CrowdStrike has found hundreds of North Korean state actors getting hired as remote developers at US companies to gain insider access and steal trade secrets. They are so effective that one manager asked if they had to fire the operative because "he did such good work," highlighting a severe remote work vulnerability.

CrowdStrike is seeing a rise in state-sponsored actors successfully passing job interviews to become remote employees. They are then shipped a company laptop, giving them complete, trusted access inside the corporate network, bypassing all perimeter defenses.

When trying to access a fortified system, the cheapest vector is human intelligence. Recruiting an insider with loose morals or personal vulnerabilities is typically far more cost-effective than developing a complex technological exploit.

While technology enables global remote work, geopolitical factors are creating new restrictions. National security concerns are leading to stricter rules on cross-border data transfer, where data is stored, and which employees can access specific systems, undermining the "digital nomad" promise.