{"id":2641,"date":"2024-10-16T13:10:32","date_gmt":"2024-10-16T13:10:32","guid":{"rendered":"https:\/\/260web.com\/news\/firm-hacked-after-accidentally-hiring-north-korean-cyber-criminal\/"},"modified":"2024-10-16T13:10:32","modified_gmt":"2024-10-16T13:10:32","slug":"firm-hacked-after-accidentally-hiring-north-korean-cyber-criminal","status":"publish","type":"post","link":"https:\/\/260web.com\/news\/firm-hacked-after-accidentally-hiring-north-korean-cyber-criminal\/","title":{"rendered":"Firm hacked after accidentally hiring North Korean cyber criminal"},"content":{"rendered":"<p>Firm hacked after accidentally hiring North Korean cyber criminal<\/p>\n<div data-component=\"image-block\" class=\"ssrcss-1b5y2ub-ComponentWrapper-FullWidthWrapper ey0461q0\">\n<figure class=\"ssrcss-1vfya96-StyledFigure e34k3c22\">\n<div class=\"ssrcss-ab5fd8-StyledFigureContainer e34k3c21\"><span class=\"ssrcss-rqy76r-Placeholder etlorgc0\"><picture><source srcset=\"https:\/\/ichef.bbci.co.uk\/ace\/standard\/240\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 240w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/320\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 320w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/480\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 480w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/624\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 624w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/800\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 800w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/976\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg.webp 976w\" type=\"image\/webp\"><img decoding=\"async\" alt=\"A man in a suit offering a handshake, with the North Korea flag in the background\" loading=\"eager\" src=\"https:\/\/260web.com\/news\/wp-content\/uploads\/2024\/10\/dhK8IR.jpg\" srcset=\"https:\/\/ichef.bbci.co.uk\/ace\/standard\/240\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 240w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/320\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 320w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/480\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 480w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/624\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 624w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/800\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 800w, https:\/\/ichef.bbci.co.uk\/ace\/standard\/976\/cpsprodpb\/55b8\/live\/30f2d0b0-8bac-11ef-b6b0-c9af5f7f16e4.jpg 976w\" width=\"2048\" height=\"1356.667606958157\" class=\"ssrcss-11yxrdo-Image edrdn950\"><\/picture><\/span><span role=\"text\" class=\"ssrcss-tvuve5-StyledFigureCopyright e34k3c20\">Getty Images<\/span><\/div>\n<\/figure>\n<\/div>\n<div data-component=\"byline-block\" class=\"ssrcss-1hbb5i-BylineComponentWrapper e8mq1e90\">\n<div class=\"ssrcss-qt5zqv-BylineWrapper e8mq1e917\">\n<div class=\"ssrcss-h3c0s8-ContributorContainer e8mq1e916\">\n<div class=\"ssrcss-1u2in0b-Container-ContributorDetails e8mq1e913\">\n<div class=\"ssrcss-68pt20-Text-TextContributorName e8mq1e96\">Joe Tidy<\/div>\n<div class=\"ssrcss-84ltp5-Text e8mq1e910\">Cyber Correspondent, BBC World Service<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ssrcss-jlwt2c-Divider e8mq1e915\"><\/div>\n<\/div>\n<div data-component=\"metadata-block\" class=\"ssrcss-xza2yt-ComponentWrapper ep2nwvo1\">\n<div>\n<ul role=\"list\" class=\"ssrcss-1ik71mx-MetadataStripContainer eh44mf03\">\n<div class=\"ssrcss-13nu8ri-GroupChildrenForWrapping eh44mf02\">\n<li role=\"listitem\" class=\"ssrcss-30fcoe-MetadataStripItem eh44mf01\">\n<div class=\"ssrcss-m5j4pi-MetadataContent eh44mf00\"><span class=\"ssrcss-1pvwv4b-MetadataSnippet e4wm5bw3\"><span class=\"ssrcss-1if1g9v-MetadataText e4wm5bw1\"><time data-testid=\"timestamp\" datetime=\"2024-10-16T12:38:30.706Z\">22 minutes ago<\/time><\/span><\/span><\/div>\n<\/li>\n<\/div>\n<\/ul>\n<\/div>\n<\/div>\n<div data-component=\"text-block\" class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\"><b class=\"ssrcss-1xjjfut-BoldText e5tfeyi3\">A company has been hacked after accidentally hiring a North Korean cyber criminal as a remote IT worker.<\/b><\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The unidentified firm hired the technician after he faked his employment history and personal details.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Once given access to the company\u2019s computer network, the hacker downloaded sensitive company data and sent a ransom demand.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The firm which is based in the UK, US or Australia did not want to be named. <\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">It has allowed cyber responders from Secureworks to report the hack to spread awareness and warn others.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">It is the latest in a string of cases of western remote workers being unmasked as North Koreans.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Secureworks said the IT worker, thought to be a man, was hired in the summer as a contractor.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He used the firm\u2019s remote working tools to log into the corporate network.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He then secretly downloaded as much company data as possible as soon as he had gained access to internal systems.<\/p>\n<div class=\"ssrcss-1o5f7ft-BulletListContainer e5tfeyi0\">\n<ul role=\"list\">\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Lazarus Heist: The intercontinental ATM theft that netted $14m in two hours<\/p>\n<\/li>\n<li>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">North Korea hackers trying to steal nuclear secrets, US and UK warn<\/p>\n<\/li>\n<\/ul>\n<\/div>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He worked for the firm for four months collecting a salary.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Researchers say this was likely redirected to North Korea in a complex laundering process to evade western sanctions on the country.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">After the company sacked him for poor performance, it received ransom emails containing some of the stolen data and a demand to be paid a six-figure sum in cryptocurrency.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">If the company did not pay, the hacker said they would publish or sell the stolen information online. <\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The firm did not disclose whether the ransom was paid.<\/p>\n<\/div>\n<\/div>\n<div data-component=\"subheadline-block\" class=\"ssrcss-19w8cxh-ComponentWrapper-HeadlineComponentWrapper egtrm1f0\">\n<h2 id=\"Firms-duped\" tabindex=\"-1\" class=\"ssrcss-pbttu9-Heading e10rt3ze0\"><span role=\"text\">Firms duped<\/span><\/h2>\n<\/div>\n<div data-component=\"text-block\" class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Since 2022, authorities and cyber defenders have warned about the rise of secret North Korean workers infiltrating western companies.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The US and South Korea accuse North Korea of tasking thousands of staff to take on multiple well-paid western roles remotely to earn money for the regime and avoid sanctions.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">In September cyber security company Mandiant said dozens of Fortune 100 companies have been found to have accidentally hired North Koreans.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">But secret IT workers turning on their employers with cyber attacks is rare, according to Rafe Pilling, Director of Threat Intelligence at Secureworks.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;This is a serious escalation of the risk from fraudulent North Korean IT worker schemes,&#8221; he said. <\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;No longer are they just after a steady pay check, they are looking for higher sums, more quickly, through data theft and extortion, from inside the company defences.&#8221;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The case comes after another North Korean IT worker was caught attempting to hack their employer in July.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The IT worker was hired by the cyber company KnowBe4, which quickly disabled access to their systems when it noticed strange behaviour.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person,&#8221; the firm wrote in a blog post. <\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;We sent them their Mac workstation, and the moment it was received, it immediately started to load malware (malicious software).&#8221;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Authorities are warning employers to be vigilant about new hires if they are fully remote.<\/p>\n<\/div>\n<\/div>\n<div data-component=\"topic-list\" class=\"ssrcss-1qmkvfu-TopicListWrapper etw6iwl1\">\n<div class=\"ssrcss-113c0cq-StyledTagContainer ed0g1kj1\">\n<div class=\"ssrcss-50vlbt-TopicListHeaderWrapper etw6iwl0\">\n<h2 type=\"normal\" class=\"ssrcss-ad2rmd-Heading e10rt3ze0\">Related topics<\/h2>\n<\/div>\n<div class=\"ssrcss-17ehax8-Cluster e1ihwmse1\">\n<ul role=\"list\" spacing=\"2\" class=\"ssrcss-1ujonwb-ClusterItems e1ihwmse0\">\n<li>Cyber-crime<\/li>\n<li>Cyber-security<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<p>Published at Wed, 16 Oct 2024 12:38:30 +0000<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Firm hacked after accidentally hiring North Korean cyber criminal Getty Images Joe Tidy Cyber Correspondent, BBC World Service 22 minutes ago A company has been hacked after accidentally hiring a North Korean cyber criminal as a remote IT worker. The unidentified firm hired the technician after he faked his employment history and personal details. Once&hellip; <a class=\"more-link\" href=\"https:\/\/260web.com\/news\/firm-hacked-after-accidentally-hiring-north-korean-cyber-criminal\/\">Continue reading <span class=\"screen-reader-text\">Firm hacked after accidentally hiring North Korean cyber criminal<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":2640,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[5],"tags":[],"class_list":["post-2641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","entry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts\/2641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/comments?post=2641"}],"version-history":[{"count":0,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/posts\/2641\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/media\/2640"}],"wp:attachment":[{"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/media?parent=2641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/categories?post=2641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/260web.com\/news\/wp-json\/wp\/v2\/tags?post=2641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}