Case Library / Deepfake & Synthetic Media / KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity

KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity

KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an AI-enhanced stock photo and a stolen US identity; malware began loading the moment his company laptop arrived, but EDR and the SOC detected and contained the device within about 25 minutes.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In mid-2024, KnowBe4, a cybersecurity awareness training vendor, posted an opening for a Principal Software Engineer on its internal IT AI team. It received an application, conducted standard screening (resume review, four separate video-conference interviews, a background check, and reference verification), and hired the candidate. The candidate was, in reality, a North Korean IT worker using a valid but stolen US citizen's identity, whose application photo was an AI-enhanced image derived from a stock photo. KnowBe4 shipped the new hire a company Mac workstation. The moment the device was received, it began loading malware. On July 15, 2024 at 9:55pm EST, KnowBe4's EDR and Security Operations Center detected suspicious activity: session-history manipulation, transfer of potentially harmful files, execution of unauthorized software, and use of a Raspberry Pi to help download an infostealer. When the SOC called the new hire, he offered an implausible excuse (troubleshooting his router), refused to join a video call, and went unresponsive; SOC contained the device by about 10:20pm EST, roughly 25 minutes after the first alert. KnowBe4 shared findings with Mandiant and the FBI, who corroborated the North Korean attribution. KnowBe4 publicly disclosed the incident on July 23, 2024 via a company blog post, followed by an FAQ on July 25 (updated July 27) and a further update on October 19, 2024 detailing hiring-process changes.

How the Attack Worked

A real North Korean operative applied for a Principal Software Engineer role on KnowBe4's internal IT AI team using a valid but stolen US identity (name, background, and other credentials belonging to an actual US citizen). The application photo was an AI-enhanced image generated from a stock photograph, engineered to consistently match the person appearing on camera. KnowBe4's HR team conducted four separate video-conference interviews on different occasions, and the interviewee's live appearance was checked against the (AI-doctored) application photo each time, passing all four rounds. A standard background check, reference checks (via email), and other standard pre-hire screening came back clean because the underlying identity was a real, valid, stolen identity rather than a fabricated one; inconsistent aliases were a red flag missed. After hire, KnowBe4 shipped the new employee a corporate Mac workstation to the address provided, following the sector-wide North Korean IT-worker playbook of shipping equipment to a US-based 'laptop farm' address so the device physically resides in the US while the actual worker VPNs in remotely from North Korea or over the border in China (often working a US-daytime-aligned night shift). The moment the device was received on July 15, 2024, malware-loading activity began.

The Lure & the Tell

The lure was a fully legitimate-seeming job candidate: real (stolen) identity documents, a photo that consistently matched across four separate live video interviews, coherent responses under background and reference checks, and normal onboarding communication. The 'tell' that eventually gave it away was entirely post-hire and behavioral, not visual: on July 15, 2024 at 9:55pm EST, KnowBe4's EDR flagged suspicious activity: the user was manipulating session-history files, transferring files, and executing unauthorized software (using a Raspberry Pi to help pull down malware). When confronted by phone, the 'employee' gave an implausible excuse (following a router troubleshooting guide), then refused a video call and went silent/unresponsive, at which point SOC contained the device (~10:20pm EST). Retrospective red flags KnowBe4 flagged: use of VOIP phone numbers with no digital footprint, inconsistent names/aliases in different records, address and date-of-birth discrepancies across documents, an odd shipping address that didn't match the claimed residence, and reliance on email-only (rather than live phone/video) reference checks.

Outcome

No breach occurred: KnowBe4 states unequivocally that no malware executed (blocked by security tooling), no customer data, source code, production systems, or KnowBe4 confidential information were ever accessed, and the new hire's account had never completed onboarding or been granted platform access (gated via Okta). The device was fully contained about 25 minutes after the first SOC alert. KnowBe4 shared its findings with Mandiant and the FBI to corroborate the North Korea attribution; the matter became (and KnowBe4 says remains) an active FBI investigation, limiting further public detail. KnowBe4 published the incident publicly on July 23, 2024 as a Public Service Announcement/organizational learning moment (not a breach disclosure), followed by an FAQ (July 25, updated July 27, 2024) addressing press mischaracterization, and a 10/19/2024 update listing ten concrete hiring-process changes the company implemented as a result.

Why It Matters

This is one of the most detailed, first-party-documented cases of a North Korean state-linked operative passing a full corporate hiring pipeline, including live video interviews, using an AI-enhanced photo layered over a stolen but valid US identity, explicitly to secure insider access to a target company (in this instance, itself a leading security-awareness vendor, underscoring that no organization is immune). It demonstrates that background checks and reference verification, when the underlying identity is genuinely stolen (not fabricated), often fail regardless of screening rigor, and that AI-based photo manipulation can now defeat 'does the face match the ID/interview' verification at scale. It also demonstrates that the same defense-in-depth principles that stop external attackers (least-privilege new-hire access, EDR, 24/7 SOC monitoring, network segmentation for onboarding accounts) are what actually stopped this insider-vector attack, since the hiring-process controls alone did not. The incident, alongside the DOJ's related May 2024 indictments (US v. Christina Chapman et al.), helped establish North Korean fake-remote-worker fraud as a recognized, large-scale (300+ victim companies, $6.8M+) national security and corporate risk category, prompting FBI/Mandiant guidance and widespread changes to remote-hiring verification practices across industry.

Defenses

KnowBe4 attributes the successful catch to its EDR (endpoint detection and response) tooling and 24/7 SOC monitoring, plus a least-privilege new-hire onboarding model: new employees are granted only minimal access (email inbox, Slack, Zoom) on a factory-new, locked-down laptop with no company data, and are barred from KnowBe4's platform, production systems, customer data, source code, or cloud infrastructure until onboarding/training is complete (access is gated through Okta). This meant that even though the fake hire began loading an infostealer within minutes of receiving the machine, the security tooling blocked execution and the SOC was able to isolate the device roughly 25 minutes after the first alert with no lateral movement possible. Post-incident (blog updated 10/19/2024), KnowBe4 announced ten hiring-process changes: stricter/live identity verification instead of email-only reference checks, requiring camera-on interviews with liveness checks, cross-referencing name/address/DOB consistency across documents, flagging VOIP numbers and thin digital footprints, watching for shipping-address/residence mismatches, and shipping new-hire equipment only to a nearby UPS Store requiring photo ID rather than a home address. Broader mitigations recommended by KnowBe4, the FBI, and Mandiant for the sector-wide DPRK IT-worker scheme include treating remote-hire onboarding as a zero-trust process, scanning for unauthorized remote-access/KVM software on company devices, and coordinating with law enforcement (FBI, Mandiant/Google Cloud Threat Intelligence) when patterns are detected.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Identity and persona sourcing: Consistent with FBI and Mandiant reporting on the broader DPRK IT-worker scheme (tracked as UNC5267), the operative likely obtained a stolen but valid US citizen identity, including name, background, and supporting documents, through a state-directed facilitator network rather than through open-source research alone.
Countering Stage 1: Facilitator-sourced stolen identities are largely invisible to the hiring company at this stage; the realistic control is downstream, cross-referencing identity documents against independent sources like E-Verify and watching for VOIP numbers or a thin digital footprint, as the FBI's advisory and KnowBe4's post-incident changes both recommend.
2
AI-enhanced photo preparation: A stock photograph was run through AI image-enhancement tooling to produce a synthetic headshot engineered to plausibly match the operative's real face, intended to defeat photo-to-application and photo-to-video-interview matching.
Countering Stage 2: Reverse-image-search screening of submitted photos and requiring active liveness checks on video calls (for example, asking a candidate to turn their head or hold ID next to their face) can catch a static AI-enhanced photo that a simple side-by-side match would miss.
3
Application and targeting: The operative applied through KnowBe4's normal applicant tracking system for a fully remote Principal Software Engineer role, consistent with the DPRK scheme's documented preference for remote-eligible US tech positions that never require in-person presence.
Countering Stage 3: Flagging resumes for career-history inconsistencies and treating fully-remote-only availability plus a rushed timeline as a risk signal, per KnowBe4's own recommended process improvements.
4
Interview infiltration: The operative sat for four separate live video-conference interviews, relying on the AI-doctored photo and rehearsed, resume-consistent answers to pass HR's photo-match and technical screening each time.
Countering Stage 4: Training interviewers to ask spontaneous, location- and detail-specific questions, which the FBI advisory notes genuine applicants answer easily but scripted operatives struggle with, rather than relying on photo-match alone.
5
Background and reference-check evasion: Because the underlying identity was a real, valid, stolen US identity rather than a fabricated one, standard background checks and email-based reference verification came back clean; inconsistent aliases and a thin digital footprint were red flags nobody was checking for at the time.
Countering Stage 5: Replacing email-only reference checks with live phone or video verification, and cross-checking name, address, and date-of-birth consistency across all submitted documents, both of which KnowBe4 adopted as hiring-process changes after this incident.
6
Laptop-farm logistics: The operative requested the company-issued Mac workstation be shipped to a US address that functioned as an 'IT mule laptop farm,' consistent with the FBI's May 2024 advisory describing US-based facilitators who receive and remotely host company hardware so North Korean workers can VPN in while appearing to be US-based.
Countering Stage 6: Shipping new-hire equipment only to a staffed pickup location requiring photo ID (KnowBe4 moved to a local UPS Store model) instead of a self-reported home address, and flagging any mismatch between the shipping address and the claimed residence.
7
Post-hire endpoint compromise attempt: Immediately upon receiving the laptop, the operative began manipulating session-history files, transferring files, and using a Raspberry Pi to help download infostealer malware, likely attempting to establish persistent remote access or harvest credentials before onboarding restrictions could tighten.
Countering Stage 7: Endpoint detection and response tooling plus 24/7 SOC monitoring, paired with a least-privilege new-hire onboarding model gating platform, source-code, and production access behind Okta until training completes, is exactly what caught and contained this device within about 25 minutes.
8
Objective: revenue extraction for the DPRK regime: Per FBI and Mandiant reporting on the wider scheme this operative was part of, the end goal was to collect a legitimate US tech salary over time and funnel a large share of it back to North Korea to fund sanctioned weapons and regime programs; at KnowBe4 specifically, this final stage was never reached because the device was contained before onboarding completed.
Countering Stage 8: Once a device is contained and a new hire never receives platform, source-code, or customer-data access, the revenue-extraction objective is already denied; the real backstop for this stage is the network segmentation and access-gating described in Stage 7, not any control specific to payroll or offboarding.
Quick Facts
Victim
KnowBe4, Inc.
Location
United States (KnowBe4 headquartered in Clearwater, Florida); worker operated remotely, assessed as based in North Korea or over the border in China
Date
2024-07-15 (malware detected/contained); hiring process preceded this in mid-2024; publicly disclosed 2024-07-23
Impact
No confirmed financial loss, data breach, or exfiltration at KnowBe4 itself; the company states explicitly this was not a data-breach event and no customer data, source code, or production systems were touched. The only public dollar figures relate to the broader North Korean IT-worker fraud ecosystem this incident is part of, not KnowBe4 specifically: DOJ/FBI describe a related May 2024 case (US v. Christina Chapman et al.) involving more than 60 stolen US identities, over 300 victim companies (some listed on the Fortune 500), and at least $6.8 million in fraudulent revenue generated for North Korea between roughly October 2020 and October 2023.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cybersecurity Industry
Threat Actor
Nation-State / APT
Related

Related Cases

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…

Incident 2024Read →

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake…

Incident 2024Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →