Fraudulent Worker Schemes Lead to Cyberattacks
Secureworks released a report detailing how North Korean attackers are targeting western countries with a new tactic. Attackers are fraudulently obtaining positions so they can victimize the employer!
I predict we will see more of these types of attacks where stolen or fabricated data is used to obtain a trusted position at the targeted organization. Once permissions are granted to the new employee, they use that access to steal information, upload malware, facilitate ransomware attacks, and eventually plant logic bombs & backdoors in products and infrastructure. Depending upon the role the fraudster is able to obtain, they may be able to use their position to infect partners, vendors, and even customers!
Be wary and act now to implement basic insider risk programs to prevent/minimize, detect, and respond to these attacks
The best mitigation is to thoroughly vet applicants, apply the principles of least access to new hires, and train existing employees to watch for signs of unusual activity.
Leave Fraudulent Worker Schemes Lead to Cyberattacks to:
Read more #hiring posts
Best Posts From Matthew Rosenquist
We have not curated any of mrosenquist's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From Matthew Rosenquist
- Agentic AI, the “Mythos Effect”, and the Future of Cyber Defense
- OpenAI’s Unintended Attack Against Hugging Face is a Warning of What is Coming
- Why 200,000 Cybersecurity Professionals Give Me Hope
- Japan Builds a New Intelligence Agency to Counter Russia, China, and North Korea
- The Mythos Effect on Cybersecurity and Board Engagement
- Mythos Frontier AI Model Restrictions are Lifted
- Is DIY Authorization the Right Approach for Scaling Agentic AI Systems?
- Top 10 Cybersecurity Influencers
- Cybercrime in 2026: What Compliance Leaders Need to See
- Cybersecurity Keynote at ISACA Sacramento