{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"},"incident":{"title":"Kraken advanced a North Korean fake job applicant to unmask his tradecraft","date":"2025-05","date_precision":"month","victim_org":"Kraken (Payward, Inc.)","sector":"Cryptocurrency","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss. The candidate was never hired; Kraken advanced him through the process deliberately to collect intelligence.","records_affected":null,"threat_actor":"DPRK-linked fake IT worker network","summary":"Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.","how_it_worked":"The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.","lessons":"Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.","confidence":"Confirmed","sources":[{"title":"How we identified a North Korean hacker who tried to get a job at Kraken","url":"https://blog.kraken.com/news/how-we-identified-a-north-korean-hacker","publisher":"Kraken"},{"title":"Kraken tells how it spotted North Korean hacker in job interview","url":"https://cointelegraph.com/news/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"}}