Case file · KNOWBE4 2024

How a security training company hired a North Korean fake IT worker

Published 2026-09-29 · 4 min read · Missing control: Identity proofing during remote hiring

In July 2024 a company that trains other businesses to spot scams found it had hired a North Korean operative as a senior engineer, after 4 video interviews and a clean background check.[1][3] This case file covers how the fake hire got through, how his new laptop gave him away within minutes, and the one control that would have kept him out.

What happened

KnowBe4, which sells security awareness training, was hiring a principal software engineer for its internal IT team working on AI. The candidate interviewed over video on 4 separate occasions, and the company checked that the person on screen matched the photo on the application. Background checks and references came back clear.[1][3]

The company shipped the new hire a Mac laptop. As soon as it arrived, the new employee began loading malicious software onto it. At 9:55 p.m. Eastern on July 15, 2024, the company's security software flagged unusual activity, and its security operations center, the team that watches for alerts around the clock, called the new hire. He said he was fixing a slow router, then stopped responding.[1][2]

By about 10:20 p.m. the laptop was cut off from the network, roughly 25 minutes after the first alert.[2][4] KnowBe4 shared its findings with the FBI and the security firm Mandiant, and concluded the worker was operating from North Korea.[4] On July 24 the company published what had happened as a warning to others.[4]

How they got in

The identity was real, which is why the background check passed. It belonged to a U.S. person and had been stolen. The photo was a stock image altered with AI so that it resembled the man who showed up on the video calls.[1][4]

KnowBe4 described how this kind of scheme generally works. The fake worker asks for the company laptop to be sent to a U.S. address that is really a so-called laptop farm, where a helper keeps company machines powered on. The worker then connects to that laptop remotely from North Korea or China, works overnight so it looks like U.S. business hours, and does real work for a real paycheck. Much of that pay is sent back to fund the North Korean state.[1][2] The Justice Department has warned that such earnings help pay for the country's weapons programs.[3]

In this case the operative did not wait for payday. He used a small add-on computer to bring malicious files onto the laptop, tried to cover his tracks in its activity history and tried to run software the company had not approved.[1][2]

How it was caught

The company's endpoint security tools, software that watches what happens on each laptop, raised the alarm the same night the activity began.[1] The security team did not just note the alert. It called the employee, and when the explanation did not hold up, it isolated the machine.[2]

What it cost

Very little, as it turned out. KnowBe4's chief executive said no access was gained and no data was lost, compromised or stolen.[2][4] The new hire had not been given access to customer data, private networks or confidential information.[3]

The company did pay a reputational price, and it changed its process. It said it now looks harder for name mismatches in background checks, checks references beyond an email reply, looks for unexplained gaps in resumes, and treats a laptop shipping address that differs from the employee's home as a red flag.[1]

The missing control

The missing control: identity proofing during remote hiring. That means confirming that the person you are hiring is the real owner of the identity on the paperwork, not just that the identity exists and has a clean record.

A background check answers the question of whether a name has a problem. It does not answer whether the person on the video call owns that name. Checking a government ID against a live face, sending the laptop only to a verified home address or to a pickup point that requires photo ID, and calling references on numbers you found yourself would each have made this persona much harder to use.[1][3] The company's monitoring saved it this time. Proper identity proofing would have meant the laptop never shipped.

What to do in your business

Watch the case
A Security Training Company Hired a Fake IT WorkerDrops 2026-11-14
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More insider risk cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. KnowBe4: How a North Korean fake IT worker tried to infiltrate us
  2. SecurityWeek: KnowBe4 hires fake North Korean IT worker, catches new employee planting malware
  3. Dark Reading: Security firm accidentally hires North Korean hacker, did not KnowBe4
  4. CyberScoop: Cyber firm KnowBe4 hired a fake IT worker from North Korea