Do You Really Know Who You Are Hiring?
- Richard Sypniewski

- 1 day ago
- 4 min read
Imagine your company has hired a much-needed, very talented software engineer.
Their resume is impressive and interviews go well. References appear legitimate and all of the required docs are in order. The employee gets hired, is issued a company laptop, and begins contributing to projects alongside colleagues.
Months later, you discover that the remote employee doesn’t live a few states away. In fact, they never worked from the USA at all. Instead, they were operating from a foreign adversary nation, using a stolen identity to gain legitimate access to your systems.
This sounds like the plot of a NYT best-selling spy novel. But according to cybersecurity expert Nicole Perlroth, companies (including Amazon and major defense contractors) have already encountered versions of this scheme. What started as an improbable idea has evolved into a sophisticated operation targeting Fortune 500 companies across multiple industries.
What if Vulnerability Begins with a Job Application?
U.S. law enforcement agencies are warning that foreign adversaries have been using stolen identities, fabricated credentials, and sophisticated deception techniques to obtain legitimate remote IT jobs with American companies. Once hired, these individuals can gain access to sensitive systems, proprietary information, and critical infrastructure—all while appearing to be trusted employees.
Historically, insider threats were viewed as disgruntled employees or shady contractors who abused their own legitimate access. Today's threat landscape is evolving alongside AI, just like everything else. According to the FBI, North Korean IT workers have successfully secured remote positions at U.S. companies by using:
stolen or synthetic identities
falsified documentation
AI-enhanced profile photos
voice-changing technology during virtual interviews
How serious is this problem?
According to Perlroth on the On with Kara Swisher podcast , during an investigation with one cybersecurity firm, researchers intentionally hired a suspected North Korean IT worker and monitored the operation. By gaining visibility into the group's communications, they discovered that a single network of just 22 individuals had submitted approximately 160,000 job applications to U.S. employers in only three months. The objective wasn't to target a single company; it was to cast the widest possible net until someone, somewhere said yes.
I want to reiterate: this isn’t a rumor or some sort of urban legend; it’s based on real reporting from organizations like the FBI and the Google Threat Intelligence Group.
These aren’t your everyday cyberattacks and we need to move beyond thinking of them that way. They’re actually business process attacks that exploit trust, workflow gaps, and ramped-up remote-work policies.
Don’t Blame Technology; Look at Business Processes
Normally, cybersecurity falls firmly in the tech group’s wheelhouse. However, the current working landscape aligned with the latest technology makes it easier than ever for cybercriminals to exploit any crack where employees are concerned.
As Perlroth notes in the interview, these schemes expose weaknesses in hiring, identity verification, and onboarding just as much as weaknesses in technology. Organizations often assume that if a candidate passes a virtual interview, clears a background check, and receives a company laptop, they can surely be trusted. That makes sense; it’s been that way for decades.
But these days, those assumptions deserve another look. Cybersecurity has become a shared responsibility between HR, IT, legal, operations, finance, and executive leadership. Every business area requires a much higher degree of digital confidence, not just IT.
Think of each function that touches a new employee:
Human Resources verifies identities
IT provisions devices and access
Managers supervise remote employees
Finance processes payroll
Leadership establishes risk tolerance and governance
When these departments operate in silos (which is all too common), it creates real gaps that cybercriminals are ready to take advantage of. But when they work together, it creates multiple layers of verification that make infiltration a lot harder.
Sophisticated Attacks Don’t Require Sophisticated Attackers
The usual threats are still there but getting stronger. Adversaries will keep adapting their tactics, AI is going to make identity fraud easier and more convincing, and remote work isn’t going anywhere. These circumstances combine to create a perfect storm, one that’s ideal for cybercrime.
To be clear: AI didn’t create this threat. But, AI is absolutely lowering the cost, skill, and time required to execute sophisticated deception. As one expert on Kara Swisher’s podcast stated, “The problem is now these models can do what only previously the Tier 1 elite nation state intelligence or their contractors could do.” In other words, capabilities that once belonged primarily to sophisticated intelligence services are becoming increasingly accessible.
The concern isn't just that nation-state actors are using AI. It's that those same technologies are lowering the barrier to entry for less sophisticated criminals, allowing them to execute more convincing and scalable attacks than ever before.
In some instances, ordinary people unknowingly became part of an attack infrastructure. FBI reporting shows that threat actors recruited low-income individuals in rural communities, offering to pay their utility bills or provide a weekly stipend in exchange for receiving and connecting company-issued laptops to their home internet. Unbeknownst to these “facilitators”, their homes effectively become U.S.-based access points, helping overseas operators to pass as legitimate domestic employees.
Finally, many organizations discovered individuals using stolen identities who appeared to be productive software developers or IT professionals. Their immediate objective wasn't sabotage—it was collecting a legitimate paycheck that ultimately funded foreign government operations. Only after the companies began identifying and terminating these workers did some of them allegedly pivot toward activities like data theft and extortion.
Preparing for a New Generation of Threats
When I said this isn’t just a typical tech problem, that’s what I meant. We need everyone on board, using a new way of thinking about recruiting, onboarding (and trusting) employees–especially remote ones. The organizations poised to avoid these threats aren’t the ones with the best security tools. It will come down to which business leaders recognize the threats that go beyond technology and into every area of the company.
Your best line of defense may not come down to another firewall or endpoint detection platform–though those are still crucial measures. You might find that a better defined hiring process with multi-functional verifications layered in is what saves you from tomorrow’s threats.
At SAGIN, we help organizations strengthen not only their technology environments, but also the governance, operational processes, and leadership practices that support them. Ask us about how we help companies to build resilient, secure systems where trust is earned and processes are protected, no matter how much the tech world changes.



Comments