Blog.Barracuda North Korean Fake Worker Scam Targets US Companies
Article Content
- •North Korean operatives are infiltrating US companies using fake identities.
- •The scam has reportedly cost organizations hundreds of millions since 2017.
- •DPRK's cyber operations are linked to over $2 billion in cryptocurrency theft in 2025.
North Korean operatives are infiltrating US companies by posing as foreign IT specialists, exploiting trust and business processes to gain legitimate access. These fake workers often secure remote employment under false identities, with reports indicating that they have cost organizations hundreds of millions since 2017. The US government issued warnings about these tactics, highlighting that North Korean operatives are often recruited through third-party specialists. The DPRK's cyber operations are linked to significant financial crimes, including over $2 billion in cryptocurrency theft in 2025 alone. As sanctions limit North Korea's access to resources, the regime increasingly relies on sophisticated cyber tactics to generate revenue and conduct espionage. Security teams must collaborate with HR and legal departments to mitigate these insider threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Andariel, TraderTraitor and Bangladesh Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korea's Lazarus Group Divided into Six Cyber Clusters Recent analysis by Sekoia and Kudelski Security reveals that North Korea's Lazarus Group operates through six distinct cyber clusters, focusing on espionage, financial activities, and sanctions evasion. The clusters include TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, each…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…