Mastodon
Your Next Cyberattack Could Start with a Job Application

Your Next Cyberattack Could Start with a Job Application

The return of To Catch a Thief is a timely reminder that trust has become part of your security perimeter.

What if your next cyberattack didn't begin with a phishing email, an unpatched server or stolen credentials?

What if it started with a job application?

About 15 months ago, I wrote about one of the most fascinating cybersecurity stories I'd seen in years. A software engineer named "Steven Smith" interviewed for a remote position at cryptocurrency exchange Kraken. On paper, he looked like an outstanding candidate. In reality, investigators believed he was part of a North Korean operation attempting to infiltrate a U.S. company under a false identity.

Rather than simply rejecting the applicant, Kraken continued the interview process. What followed became a masterclass in identity verification.

Simple questions about local restaurants, Halloween traditions, and the candidate's own background quickly exposed inconsistencies that no resumé, technical assessment, or AI-generated cover letter could hide.

The recent release of Season 2 of Rubrik's To Catch a Thief podcast reminded me just how relevant that story still is.

Since publishing my original article, I've heard variations of the story in books, podcasts, and conference hallways. Instead of fading away, the problem has only become more sophisticated as AI lowers the barrier to creating believable digital identities.

Cryptocurrency companies and financial services organizations may have been among the earliest high-profile targets, but healthcare, manufacturing, technology companies, government contractors, and many other industries have all reported similar attempts.

The technology has changed.

The threat hasn't.

The Hiring Process Is Now Part of Your Security Perimeter

For years, cybersecurity focused on technical ways of keeping attackers out.

Firewalls, multi-factor authentication, endpoint protection, email security.

Today, another attack surface deserves just as much attention.

Your hiring process.

The North Korean IT worker campaign demonstrated that sometimes the easiest way into an organization isn't through a software vulnerability.

It's through a job application.

AI Raises the Stakes

When I published The Spy Who Applied to Code in May 2025, generative AI was already changing the hiring landscape.

Fifteen months later, the challenge has become even greater.

Today, attackers can use AI to:

  • Write convincing, customized resumés.

  • Generate professional-looking headshots.

  • Polish interview responses.

  • Translate conversations in real time.

  • Clone voices.

  • Create increasingly convincing synthetic video.

The barrier to creating a believable professional identity has never been lower.

That doesn't mean every remote applicant should be viewed with suspicion.

It does mean organizations should treat identity verification during hiring as a cybersecurity control, not simply an HR process or hiring checklist.

HR and Security Need to Work Together

Hiring managers know how to evaluate talent.

Security teams know how to evaluate risk.

Neither team can solve this problem alone.

As remote work continues to evolve, HR and cybersecurity need to collaborate on identity verification practices that protect both the organization and legitimate candidates.

Trust Is the New Perimeter

The North Korean IT worker campaign isn't really a story about North Korea.

It's a story about trust.

For decades, cybersecurity focused on preventing attackers from breaking into our organizations.

Today, one of the most effective attacks may begin when we unknowingly invite them inside.

Firewalls, multi-factor authentication, endpoint protection, and identity management all remain essential. But in an era of remote work and AI-assisted deception, one of the most important security decisions your organization makes may happen long before an account is created.

Cybersecurity no longer begins when someone logs in.

It begins when you decide to hire them.


Additional Resources

If you missed my original article, The Spy Who Applied to Code, I encourage you to give it a read.

It walks through Kraken's interview with "Steven Smith," shares practical techniques for spotting suspicious applicants, and explains why this attack caught so many organizations by surprise.

If you'd like to dive deeper into North Korea's cyber operations, I also recommend:

Enjoyed this article?

Subscribe to Between The Hacks for practical cybersecurity, real-world stories, and fresh perspectives on the technologies shaping our digital future.

The Jurassic Park Moment for AI Security: When AI Starts Testing the Fence

The Jurassic Park Moment for AI Security: When AI Starts Testing the Fence

0
Mastodon Bluesky X LinkedIn Facebook