Share this article:

Remote worker vetting | FBI issues warning to employers after North Korean infiltration & blackmail case

FBI issues warning to employers after North Korean infiltration & blackmail case

One unexpected downside to remote working has been revealed after a US company unknowingly hired a North Korean IT worker who stole sensitive data and demanded a ransom following his dismissal.

The FBI has issued fresh warnings over a growing number of North Korean hackers infiltrating US firms under the guise of legitimate remote workers, siphoning money and information to fund the authoritarian regime’s activities.

According to Secureworks’ Counter Threat Unit (CTU), which uncovered the breach, the unnamed company was extorted by the North Korean hacker who had misrepresented his employment history and personal details to secure the position. While employed remotely, he gained access to the company’s systems, using internal tools to download a significant amount of confidential data. His employment was terminated shortly after due to poor performance, but it was then that the company began receiving threatening emails demanding a ransom in cryptocurrency.

Data used to blackmail company

The stolen data was being used to blackmail the company, with the hacker threatening to release it online or sell it on the dark web if a six-figure payment was not made. However, due to strict international sanctions against North Korea, many firms, including the targeted company, are prohibited from paying ransoms to the rogue state.

The incident highlights a growing cyber security threat from North Korean hackers, who increasingly pose as remote workers to bypass international sanctions and funnel money back to their government. FBI officials have linked such activity to financing the country’s weapons programs, with the salaries earned by hackers contributing to state revenue. The FBI has previously warned of thousands of North Korean IT workers operating under false pretenses within Western companies.

Rafe Pilling, director of threat intelligence at Secureworks’ CTU, said the incident marks a shift in tactics. “They’re no longer just after a steady paycheck,” he explained. “North Korean hackers are now seeking larger sums more quickly through data theft and extortion from within a company’s defenses.”

He urged organizations to exercise caution when hiring remote workers, recommending more stringent identity verification procedures, including video interviews and checks for suspicious activities such as the redirection of corporate equipment to non-business locations.

Firms urged to up cyber security measures

In a recent LinkedIn post one cybersecurity expert revealed that numerous Fortune 100 companies have fallen victim to similar attacks. North Korea uses US-based facilitators to obtain company laptops and run “laptop farms” from homes, where remote monitoring and management software is installed to give hackers remote access to company networks.

Experts are now urging companies to implement more robust vetting processes for remote workers and raise cyber security standards in the face of evolving international threats.

Be the first to comment.

Sign up for a FREE myGrapevine account to have your say.

Share this article:

You are currently previewing this article.Create account

This is the last preview available to you for the next 30 days.

To receive our daily newsletter and access HR features & insights, create a free account today.