TL;DR: Investigators say nearly every Fortune 500 company may have unknowingly hired at least one North Korean IT operative, with 100,000+ operatives, about $500 million a year routed to Pyongyang, and valid enterprise credentials obtained from day one, according to Abnormal AI. The case shows that identity security can verify the account while still missing the person, so hiring, access, and behavioural signals must be governed together.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Insider Threat That Passed the Background Check”.
Key questions
Q: How should security teams verify that a new hire is legitimate before provisioning access?
A: Security teams should combine identity proofing, hiring record validation and manager attestation before granting production access.
Q: Why can a fraudulent employee still look normal in IAM systems?
A: Because IAM systems authenticate accounts and entitlements, not intent.
Q: What are the signs that a fake hire is accumulating access?
A: Look for access growth that does not match role expectations, unusual communication patterns, and SaaS notifications tied to payroll or export changes.
Practitioner guidance
- Tighten pre-boarding identity proofing Require stronger evidence before a new hire receives production access, especially where remote onboarding, document checks and recruiter workflows are separated across teams.
- Correlate HR events with identity issuance Join hiring records, directory creation, SaaS provisioning and payroll changes so access issuance can be reviewed against the actual employment trail.
- Baseline first-week behaviour by role Compare early communication patterns, system touchpoints and access growth against peer cohorts to flag hires whose activity does not match the role.
Bottom line: The article describes a workforce fraud pattern where valid credentials and legitimate permissions can coexist with a fraudulent hire.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Hiring trust is now an identity control surface: The article shows that workforce onboarding can no longer be treated as a pure HR process. If a person can enter with valid credentials and legitimate permissions while remaining fraudulent, then identity governance has failed before access review even starts. The implication is that joiner controls must include proof-of-person, not just proof-of-document.
A question worth separating out:
Q: Who should own fraudulent hire detection in a joiner process?
A: It should be shared across IAM, HR, security operations and hiring managers because no single team sees the full picture. IAM issues the access, HR owns the employment record, and security must correlate the signals when the two diverge.
👉 Read our full editorial: North Korean IT worker fraud exposes identity blind spots in hiring