{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:51.644Z","total":2,"returned":2,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Kraken advanced a North Korean fake job applicant to unmask his tradecraft","date":"2025-05","date_precision":"month","victim_org":"Kraken (Payward, Inc.)","sector":"Cryptocurrency","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss. The candidate was never hired; Kraken advanced him through the process deliberately to collect intelligence.","records_affected":null,"threat_actor":"DPRK-linked fake IT worker network","summary":"Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.","how_it_worked":"The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.","lessons":"Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.","confidence":"Confirmed","sources":[{"title":"How we identified a North Korean hacker who tried to get a job at Kraken","url":"https://blog.kraken.com/news/how-we-identified-a-north-korean-hacker","publisher":"Kraken"},{"title":"Kraken tells how it spotted North Korean hacker in job interview","url":"https://cointelegraph.com/news/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"},{"title":"Munchables loses $62.5M to a developer it hired who was linked to North Korea","date":"2024-03-26","date_precision":"day","victim_org":"Munchables (NFT game on Blast)","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Insider Access"],"loss_usd":62500000,"loss_note":"About $62.5 million in ether at the time of the exploit. All funds were recovered after the developer surrendered the private keys without a ransom being paid.","records_affected":null,"threat_actor":"A developer using the GitHub handle 'Werewolves0493', assessed by investigator ZachXBT as North Korea-linked","summary":"Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.","how_it_worked":"This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.","lessons":"Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.","confidence":"Reported","sources":[{"title":"Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 Firm","url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","publisher":"CoinDesk"},{"title":"Explained: The Munchables Hack (March 2024)","url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"}]}