KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an AI-enhanced stock photo.
Social Engineering Examples·10 sources
In mid-2024, KnowBe4, a cybersecurity awareness training vendor, posted an opening for a Principal Software Engineer on its internal IT AI team. It received an application, conducted standard screening (resume review, four separate video-conference interviews, a background check, and reference verification), and hired the candidate. The candidate was, in reality, a North Korean IT worker using a valid but stolen US citizen's identity, whose application photo was an AI-enhanced image derived from a stock photo.
KnowBe4 shipped the new hire a company Mac workstation. The moment the device was received, it began loading malware. On July 15, 2024 at 9:55pm EST, KnowBe4's EDR and Security Operations Center detected suspicious activity: session-history manipulation, transfer of potentially harmful files, execution of unauthorized software, and use of a Raspberry Pi to help download an infostealer.
When the SOC called the new hire, he offered an implausible excuse (troubleshooting his router), refused to join a video call, and went unresponsive; SOC contained the device by about 10:20pm EST, roughly 25 minutes after the first alert. KnowBe4 shared findings with Mandiant and the FBI, who corroborated the North Korean attribution. KnowBe4 publicly disclosed the incident on July 23, 2024 via a company blog post, followed by an FAQ on July 25 (updated July 27) and a further update on October 19, 2024 detailing hiring-process changes.
A real North Korean operative applied for a Principal Software Engineer role on KnowBe4's internal IT AI team using a valid but stolen US identity (name, background, and other credentials belonging to an actual US citizen). The application photo was an AI-enhanced image generated from a stock photograph, engineered to consistently match the person appearing on camera.
KnowBe4's HR team conducted four separate video-conference interviews on different occasions, and the interviewee's live appearance was checked against the (AI-doctored) application photo each time, passing all four rounds. A standard background check, reference checks (via email), and other standard pre-hire screening came back clean because the underlying identity was a real, valid, stolen identity rather than a fabricated one; inconsistent aliases were a red flag missed.
After hire, KnowBe4 shipped the new employee a corporate Mac workstation to the address provided, following the sector-wide North Korean IT-worker playbook of shipping equipment to a US-based 'laptop farm' address so the device physically resides in the US while the actual worker VPNs in remotely from North Korea or over the border in China (often working a US-daytime-aligned night shift).
The moment the device was received on July 15, 2024, malware-loading activity began.
The lure was a fully legitimate-seeming job candidate: real (stolen) identity documents, a photo that consistently matched across four separate live video interviews, coherent responses under background and reference checks, and normal onboarding communication. The 'tell' that eventually gave it away was entirely post-hire and behavioral, not visual: on July 15, 2024 at 9:55pm EST, KnowBe4's EDR flagged suspicious activity: the user was manipulating session-history files, transferring files, and executing unauthorized software (using a Raspberry Pi to help pull down malware).
When confronted by phone, the 'employee' gave an implausible excuse (following a router troubleshooting guide), then refused a video call and went silent/unresponsive, at which point SOC contained the device (~10:20pm EST). Retrospective red flags KnowBe4 flagged: use of VOIP phone numbers with no digital footprint, inconsistent names/aliases in different records, address and date-of-birth discrepancies across documents, an odd shipping address that didn't match the claimed residence, and reliance on email-only (rather than live phone/video) reference checks.
No breach occurred: KnowBe4 states unequivocally that no malware executed (blocked by security tooling), no customer data, source code, production systems, or KnowBe4 confidential information were ever accessed, and the new hire's account had never completed onboarding or been granted platform access (gated via Okta). The device was fully contained about 25 minutes after the first SOC alert.
KnowBe4 shared its findings with Mandiant and the FBI to corroborate the North Korea attribution; the matter became (and KnowBe4 says remains) an active FBI investigation, limiting further public detail. KnowBe4 published the incident publicly on July 23, 2024 as a Public Service Announcement/organizational learning moment (not a breach disclosure), followed by an FAQ (July 25, updated July 27, 2024) addressing press mischaracterization, and a 10/19/2024 update listing ten concrete hiring-process changes the company implemented as a result.
This is one of the most detailed, first-party-documented cases of a North Korean state-linked operative passing a full corporate hiring pipeline, including live video interviews, using an AI-enhanced photo layered over a stolen but valid US identity, explicitly to secure insider access to a target company (in this instance, itself a leading security-awareness vendor, underscoring that no organization is immune).
It demonstrates that background checks and reference verification, when the underlying identity is genuinely stolen (not fabricated), often fail regardless of screening rigor, and that AI-based photo manipulation can now defeat 'does the face match the ID/interview' verification at scale. It also demonstrates that the same defense-in-depth principles that stop external attackers (least-privilege new-hire access, EDR, 24/7 SOC monitoring, network segmentation for onboarding accounts) are what actually stopped this insider-vector attack, since the hiring-process controls alone did not.
The incident, alongside the DOJ's related May 2024 indictments (US v. Christina Chapman et al.), helped establish North Korean fake-remote-worker fraud as a recognized, large-scale (300+ victim companies, $6.8M+) national security and corporate risk category, prompting FBI/Mandiant guidance and widespread changes to remote-hiring verification practices across industry.
KnowBe4 attributes the successful catch to its EDR (endpoint detection and response) tooling and 24/7 SOC monitoring, plus a least-privilege new-hire onboarding model: new employees are granted only minimal access (email inbox, Slack, Zoom) on a factory-new, locked-down laptop with no company data, and are barred from KnowBe4's platform, production systems, customer data, source code, or cloud infrastructure until onboarding/training is complete (access is gated through Okta).
This meant that even though the fake hire began loading an infostealer within minutes of receiving the machine, the security tooling blocked execution and the SOC was able to isolate the device roughly 25 minutes after the first alert with no lateral movement possible. Post-incident (blog updated 10/19/2024), KnowBe4 announced ten hiring-process changes: stricter/live identity verification instead of email-only reference checks, requiring camera-on interviews with liveness checks, cross-referencing name/address/DOB consistency across documents, flagging VOIP numbers and thin digital footprints, watching for shipping-address/residence mismatches, and shipping new-hire equipment only to a nearby UPS Store requiring photo ID rather than a home address.
Broader mitigations recommended by KnowBe4, the FBI, and Mandiant for the sector-wide DPRK IT-worker scheme include treating remote-hire onboarding as a zero-trust process, scanning for unauthorized remote-access/KVM software on company devices, and coordinating with law enforcement (FBI, Mandiant/Google Cloud Threat Intelligence) when patterns are detected.
Social Engineering Examples. “KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity”. Accessed 19 September 2026. https://socialengineeringexamples.com/knowbe4-fake-north-korean-it-worker-2024
Consistent with FBI and Mandiant reporting on the broader DPRK IT-worker scheme (tracked as UNC5267), the operative likely obtained a stolen but valid US citizen identity, including name, background, and supporting documents, through a state-directed facilitator network rather than through open-source research alone.
Facilitator-sourced stolen identities are largely invisible to the hiring company at this stage; the realistic control is downstream, cross-referencing identity documents against independent sources like E-Verify and watching for VOIP numbers or a thin digital footprint, as the FBI's advisory and KnowBe4's post-incident changes both recommend.
A stock photograph was run through AI image-enhancement tooling to produce a synthetic headshot engineered to plausibly match the operative's real face, intended to defeat photo-to-application and photo-to-video-interview matching.
Reverse-image-search screening of submitted photos and requiring active liveness checks on video calls (for example, asking a candidate to turn their head or hold ID next to their face) can catch a static AI-enhanced photo that a simple side-by-side match would miss.
The operative applied through KnowBe4's normal applicant tracking system for a fully remote Principal Software Engineer role, consistent with the DPRK scheme's documented preference for remote-eligible US tech positions that never require in-person presence.
Flagging resumes for career-history inconsistencies and treating fully-remote-only availability plus a rushed timeline as a risk signal, per KnowBe4's own recommended process improvements.
The operative sat for four separate live video-conference interviews, relying on the AI-doctored photo and rehearsed, resume-consistent answers to pass HR's photo-match and technical screening each time.
Training interviewers to ask spontaneous, location- and detail-specific questions, which the FBI advisory notes genuine applicants answer easily but scripted operatives struggle with, rather than relying on photo-match alone.
Because the underlying identity was a real, valid, stolen US identity rather than a fabricated one, standard background checks and email-based reference verification came back clean; inconsistent aliases and a thin digital footprint were red flags nobody was checking for at the time.
Replacing email-only reference checks with live phone or video verification, and cross-checking name, address, and date-of-birth consistency across all submitted documents, both of which KnowBe4 adopted as hiring-process changes after this incident.
The operative requested the company-issued Mac workstation be shipped to a US address that functioned as an 'IT mule laptop farm,' consistent with the FBI's May 2024 advisory describing US-based facilitators who receive and remotely host company hardware so North Korean workers can VPN in while appearing to be US-based.
Shipping new-hire equipment only to a staffed pickup location requiring photo ID (KnowBe4 moved to a local UPS Store model) instead of a self-reported home address, and flagging any mismatch between the shipping address and the claimed residence.
Immediately upon receiving the laptop, the operative began manipulating session-history files, transferring files, and using a Raspberry Pi to help download infostealer malware, likely attempting to establish persistent remote access or harvest credentials before onboarding restrictions could tighten.
Endpoint detection and response tooling plus 24/7 SOC monitoring, paired with a least-privilege new-hire onboarding model gating platform, source-code, and production access behind Okta until training completes, is exactly what caught and contained this device within about 25 minutes.
revenue extraction for the DPRK regime: Per FBI and Mandiant reporting on the wider scheme this operative was part of, the end goal was to collect a legitimate US tech salary over time and funnel a large share of it back to North Korea to fund sanctioned weapons and regime programs; at KnowBe4 specifically, this final stage was never reached because the device was contained before onboarding completed.
Once a device is contained and a new hire never receives platform, source-code, or customer-data access, the revenue-extraction objective is already denied; the real backstop for this stage is the network segmentation and access-gating described in Stage 7, not any control specific to payroll or offboarding.
Browse by what this case has in common with others in the library.
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.
Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…