KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an AI-enhanced stock photo and a stolen US identity; malware began loading the moment his company laptop arrived, but EDR and the SOC detected and contained the device within about 25 minutes.
Reviewed by the Social Engineering Examples team.
In mid-2024, KnowBe4, a cybersecurity awareness training vendor, posted an opening for a Principal Software Engineer on its internal IT AI team. It received an application, conducted standard screening (resume review, four separate video-conference interviews, a background check, and reference verification), and hired the candidate. The candidate was, in reality, a North Korean IT worker using a valid but stolen US citizen's identity, whose application photo was an AI-enhanced image derived from a stock photo. KnowBe4 shipped the new hire a company Mac workstation. The moment the device was received, it began loading malware. On July 15, 2024 at 9:55pm EST, KnowBe4's EDR and Security Operations Center detected suspicious activity: session-history manipulation, transfer of potentially harmful files, execution of unauthorized software, and use of a Raspberry Pi to help download an infostealer. When the SOC called the new hire, he offered an implausible excuse (troubleshooting his router), refused to join a video call, and went unresponsive; SOC contained the device by about 10:20pm EST, roughly 25 minutes after the first alert. KnowBe4 shared findings with Mandiant and the FBI, who corroborated the North Korean attribution. KnowBe4 publicly disclosed the incident on July 23, 2024 via a company blog post, followed by an FAQ on July 25 (updated July 27) and a further update on October 19, 2024 detailing hiring-process changes.
A real North Korean operative applied for a Principal Software Engineer role on KnowBe4's internal IT AI team using a valid but stolen US identity (name, background, and other credentials belonging to an actual US citizen). The application photo was an AI-enhanced image generated from a stock photograph, engineered to consistently match the person appearing on camera. KnowBe4's HR team conducted four separate video-conference interviews on different occasions, and the interviewee's live appearance was checked against the (AI-doctored) application photo each time, passing all four rounds. A standard background check, reference checks (via email), and other standard pre-hire screening came back clean because the underlying identity was a real, valid, stolen identity rather than a fabricated one; inconsistent aliases were a red flag missed. After hire, KnowBe4 shipped the new employee a corporate Mac workstation to the address provided, following the sector-wide North Korean IT-worker playbook of shipping equipment to a US-based 'laptop farm' address so the device physically resides in the US while the actual worker VPNs in remotely from North Korea or over the border in China (often working a US-daytime-aligned night shift). The moment the device was received on July 15, 2024, malware-loading activity began.
The lure was a fully legitimate-seeming job candidate: real (stolen) identity documents, a photo that consistently matched across four separate live video interviews, coherent responses under background and reference checks, and normal onboarding communication. The 'tell' that eventually gave it away was entirely post-hire and behavioral, not visual: on July 15, 2024 at 9:55pm EST, KnowBe4's EDR flagged suspicious activity: the user was manipulating session-history files, transferring files, and executing unauthorized software (using a Raspberry Pi to help pull down malware). When confronted by phone, the 'employee' gave an implausible excuse (following a router troubleshooting guide), then refused a video call and went silent/unresponsive, at which point SOC contained the device (~10:20pm EST). Retrospective red flags KnowBe4 flagged: use of VOIP phone numbers with no digital footprint, inconsistent names/aliases in different records, address and date-of-birth discrepancies across documents, an odd shipping address that didn't match the claimed residence, and reliance on email-only (rather than live phone/video) reference checks.
No breach occurred: KnowBe4 states unequivocally that no malware executed (blocked by security tooling), no customer data, source code, production systems, or KnowBe4 confidential information were ever accessed, and the new hire's account had never completed onboarding or been granted platform access (gated via Okta). The device was fully contained about 25 minutes after the first SOC alert. KnowBe4 shared its findings with Mandiant and the FBI to corroborate the North Korea attribution; the matter became (and KnowBe4 says remains) an active FBI investigation, limiting further public detail. KnowBe4 published the incident publicly on July 23, 2024 as a Public Service Announcement/organizational learning moment (not a breach disclosure), followed by an FAQ (July 25, updated July 27, 2024) addressing press mischaracterization, and a 10/19/2024 update listing ten concrete hiring-process changes the company implemented as a result.
This is one of the most detailed, first-party-documented cases of a North Korean state-linked operative passing a full corporate hiring pipeline, including live video interviews, using an AI-enhanced photo layered over a stolen but valid US identity, explicitly to secure insider access to a target company (in this instance, itself a leading security-awareness vendor, underscoring that no organization is immune). It demonstrates that background checks and reference verification, when the underlying identity is genuinely stolen (not fabricated), often fail regardless of screening rigor, and that AI-based photo manipulation can now defeat 'does the face match the ID/interview' verification at scale. It also demonstrates that the same defense-in-depth principles that stop external attackers (least-privilege new-hire access, EDR, 24/7 SOC monitoring, network segmentation for onboarding accounts) are what actually stopped this insider-vector attack, since the hiring-process controls alone did not. The incident, alongside the DOJ's related May 2024 indictments (US v. Christina Chapman et al.), helped establish North Korean fake-remote-worker fraud as a recognized, large-scale (300+ victim companies, $6.8M+) national security and corporate risk category, prompting FBI/Mandiant guidance and widespread changes to remote-hiring verification practices across industry.
KnowBe4 attributes the successful catch to its EDR (endpoint detection and response) tooling and 24/7 SOC monitoring, plus a least-privilege new-hire onboarding model: new employees are granted only minimal access (email inbox, Slack, Zoom) on a factory-new, locked-down laptop with no company data, and are barred from KnowBe4's platform, production systems, customer data, source code, or cloud infrastructure until onboarding/training is complete (access is gated through Okta). This meant that even though the fake hire began loading an infostealer within minutes of receiving the machine, the security tooling blocked execution and the SOC was able to isolate the device roughly 25 minutes after the first alert with no lateral movement possible. Post-incident (blog updated 10/19/2024), KnowBe4 announced ten hiring-process changes: stricter/live identity verification instead of email-only reference checks, requiring camera-on interviews with liveness checks, cross-referencing name/address/DOB consistency across documents, flagging VOIP numbers and thin digital footprints, watching for shipping-address/residence mismatches, and shipping new-hire equipment only to a nearby UPS Store requiring photo ID rather than a home address. Broader mitigations recommended by KnowBe4, the FBI, and Mandiant for the sector-wide DPRK IT-worker scheme include treating remote-hire onboarding as a zero-trust process, scanning for unauthorized remote-access/KVM software on company devices, and coordinating with law enforcement (FBI, Mandiant/Google Cloud Threat Intelligence) when patterns are detected.
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake…
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…