The FBI is warning that North Korean IT workers at American companiesare abusing their access to systems and stealing source code to blackmail their employers.

Public and private sector organizations in the United States and around the world should be cautious about their hiring practices . According to the FBI, North Korea’s IT military is engaging in malicious activities being leaked online stolen from their employers’ networks from
“ North Korean IT workers have copied company code repositories to their own profiles and personal cloud accounts. While not uncommon among software developers, this activity can lead to the theft of corporate code ,” the FBI said
See also: US: Sanctions on North Korean IT workers
North Korean hackers could harvest sensitive corporate credentials and session cookies to initiate work sessions from non-corporate devices. From there, they can continue their malicious activities.
The FBI advises companies to implement the principle of least privilege by disabling local administrator accounts and limiting permissions for remote desktop applications. It also recommends monitoring for unusual network traffic, especially for remote connections.
Experts also recommend checking network logs and browser sessions for possible data theft via shared drives, cloud accounts, and private code repositories.
As mentioned above, companies should be very careful when hiring new staff , especially when it is done remotely. Various methods of verifying the identity of prospective employees should be implemented during interviews. Also, HR systems should cross-reference applicants with similar resume content or contact information.
See also: US: North Korean hackers stole $659 million worth of crypto in 2024
Given that North Korean IT workers use artificial intelligence technology and face-swapping to hide their identities during interviews, HR staff and hiring managers need to take steps to avoid this risk. Additionally, monitoring changes to payment platforms and contact information is crucial, as these individuals often reuse email addresses and phone numbers on resumes.

Other measures that will help identify North Korean IT worker fraudsters include:
- Questions, during the interview, that ask applicants for specific details about their location or educational background (IT workers from North Korea often claim they have studied at educational institutions outside the USA),
- Checking resumes for typographical errors and unusual names,
- Completion of as large a portion as possible of the hiring process in person.
“We are increasingly seeing North Korean IT workers infiltrate larger organizations to steal sensitive data and blackmail their employers. It is possible that we will see them expand their operations into Europe to replicate their success,” Michael Barnhart, principal analyst at Mandiant, told BleepingComputer.
In recent years, government agencies in South Korea and Japan have also issued warnings about North Koreans deceiving private companies into hiring them for remote IT work.
See also: DMM Bitcoin: North Korean hackers behind $308 million crypto theft
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The issue of cyberattacks and data breaches has become increasingly prevalent in recent years, with hackers constantly finding new ways to infiltrate systems and steal valuable information. The involvement of North Korean IT workers is just one example of the ongoing threat businesses face in today's digital landscape.
Businesses are urged to work with law enforcement to combat these threats and protect themselves from the theft of sensitive data. It is vital for companies to take immediate action to avoid the risk emanating from North Korea. The FBI’s warning serves as a reminder that cybersecurity must be taken seriously in today’s digital world.
Source: www.bleepingcomputer.com
