{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:39:09.399Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"KnowBe4 hired a North Korean fake IT worker who loaded malware on day one","date":"2024-07-15","date_precision":"day","victim_org":"KnowBe4","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.","records_affected":null,"threat_actor":"DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI","summary":"Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.","how_it_worked":"The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.","lessons":"Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.","confidence":"Confirmed","sources":[{"title":"How a North Korean Fake IT Worker Tried to Infiltrate Us","url":"https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us","publisher":"KnowBe4"},{"title":"KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware","url":"https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/","publisher":"SecurityWeek"},{"title":"Cyber firm KnowBe4 hired a fake IT worker from North Korea","url":"https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"}]}