case file 02north korean it scamJuly 2024Clearwater, Florida
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
4
video interviews passed
25 min
from delivery to malware
0
data lost
what happened
KnowBe4 is a security awareness company. Its entire business is teaching organizations to recognise when somebody is not who they claim to be. In July 2024 it hired a principal software engineer for its internal IT and AI team, and the person it hired was a North Korean operative using a stolen but valid American identity and a profile photo that had been AI-enhanced from a stock image.
The candidate cleared four video interviews. He cleared a background check, because the identity behind it was a real American's. He cleared reference checks. The company shipped a Mac to the address on file, which turned out to be a laptop farm.
About 25 minutes after the machine came online, the worker began loading malware onto it using a Raspberry Pi. Endpoint detection alerted at 9:55 pm. The security operations team called him. He said he was unavailable, then went silent. The device was contained by 10:20 pm.
“This was a real person using a valid but stolen US-based identity. The picture was AI 'enhanced.'”
Stu Sjouwerman, KnowBe4 chief executive
how it was caught
By endpoint monitoring after the hire, not by the hiring process. That is the point of the case. Every hiring control the company had, and it had good ones, passed the candidate through.
KnowBe4 then did something unusual: it published the entire incident, including the parts that made it look bad, so other companies would know what the failure mode looks like.
what it cost
Nothing, in data terms. No information was lost and no systems were compromised. The cost was the recruiting cycle, the onboarding, the hardware, and the incident response.
The broader cost is the lesson: a company whose product is detecting impostors could not detect one through video interviews and background checks alone.
the tells
signals that were visible, in hindsight, before anyone was hired.
- A profile photo that had been AI-enhanced from a stock image.
- A laptop shipping address that was not the address on the identity documents.
- Almost no verifiable online footprint for a supposedly senior engineer.
- Remote-access and unfamiliar tooling on the corporate device within minutes of delivery.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
The stolen identity was real and passed the background check. Matching the live face on the interview against the identity presented is what a background check structurally cannot do.
Everything documentary about this candidate was genuine, which is why every documentary control passed. aperture evaluates the interview itself, which is the one place the real person has to show up.
Coached and scripted answers survive a fixed question list. They come apart when each question is built from the answer just given, because there is nothing to prepare.
sources
- [1]How a North Korean fake IT worker tried to infiltrate us
KnowBe4 · firsthand account · July 23, 2024
A security company published its own near-miss in full: video interviews, background check and references all passed. Written by CEO Stu Sjouwerman.
- [2]AI fakers: how deepfaked candidates got deep into a startup's hiring pipeline
The Pragmatic Engineer · firsthand account · March 11, 2025
Gergely Orosz's account of Vidoc Security. The hand-in-front-of-face test that broke the filter came from co-founder Dawid Moczadlo.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · June 2025
29 laptop farms, 16 states, one week
In June 2025 the Justice Department searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and charged the American facilitators making the whole thing possible.
north korean it scam · July 2026
inside a federal agency
In July 2026 an FBI deputy assistant director told a government technology panel that the Bureau had identified, that week, a North Korean remote IT worker employed as a contractor at a U.S. federal agency.