North Korean IT worker schemes exploit onboarding security gaps
The FBI has warned that North Korean IT workers are exploiting gaps in onboarding security by using fake or stolen identities to secure remote roles at companies, gaining legitimate access to corporate networks. These attacks bypass Zero Trust measures by targeting points where trust is established for new hires, before strong authentication is in place. The agency recommends robust identity verification not only for access, but also during the hiring process and remote employee onboarding.
- North Korean attackers use false identities for onboarding
- Fake workers pass hiring, gaining real accounts
- FBI urges strong initial and ongoing identity checks
- Onboarding is a prime target for social engineering
- Credential bootstrapping exposes enterprises to attacks
Sources covering this
More in Cybersecurity
Police arrest alleged 16-year-old leader of KillSec ransomware group
An international law enforcement operation has arrested a 16-year-old suspected of leading the KillSec ransomware gang, seized its leak…
New device claims to freeze iPhones to bypass Apple security
A leaked video shows Magnet Forensics, seller of the popular GrayKey hacking tool, claiming its new device can bypass Apple's 72-hour…
Chinese hackers targeted AI policy experts with phishing
Researchers report that a China-linked hacking group used phishing emails to impersonate AI experts and policy officials, targeting…
GrayKey tool reportedly bypasses iPhone Inactivity Reboot
GrayKey, a forensic tool from Magnet Forensics, can reportedly bypass the iPhone's Inactivity Reboot feature, which is designed to…