Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

KnowBe4 says it hired a software engineer using a stolen U.S. identity in July 2024. After the new employee received a company Mac, the account began suspicious activity, including attempts to load malware and run unauthorized software. Endpoint security alerted the company, which isolated the device within about 25 minutes. KnowBe4 reported no illegal access to its systems and no data loss, compromise, or exfiltration: this was an attempted infiltration, not a confirmed breach.

What happened at KnowBe4?

KnowBe4 sells security-awareness training and simulated-phishing products. The irony of a security company hiring a fraudulent applicant is striking, but the incident is better understood as a layered-defense case: identity and recruiting checks failed, while controls on the issued device detected suspicious behavior and helped limit exposure. KnowBe4’s account of the incident is available in its incident report and public warning.

The sequence

  1. Application: KnowBe4 was recruiting a software engineer for its internal IT AI team. The applicant provided identity information belonging to a real U.S. citizen. Standard background checks came back clean; they did not establish that the applicant was the rightful holder of that identity.
  2. Interviews: The candidate completed four video interviews. KnowBe4 said the person on camera looked sufficiently like the supplied photograph to pass. A live video interview can help assess a candidate, but does not by itself prove identity or rule out a proxy.
  3. Equipment: The company sent the new hire a Mac workstation. KnowBe4 says the device was provisioned with little or no sensitive data and had endpoint-security and device-management tools installed. The equipment appears to have reached the operator through a domestic intermediary or laptop-farm arrangement.
  4. Alert and containment: Soon after receiving the machine, the account began loading malware or potentially harmful files, manipulating session-history files, transferring files, and executing unauthorized software. KnowBe4’s endpoint detection and response (EDR) system raised an alert; the company says it locked down the laptop within roughly 25 minutes of that alert.
  5. Investigation: KnowBe4 shared information with Mandiant and the FBI. The company concluded that the hire was a North Korean fake IT worker using a stolen U.S. identity.

The reported actions establish an attempt to use the new workstation for suspicious activity. KnowBe4’s public account does not establish that the actor accessed customer data, bypassed the company’s internal controls, or exfiltrated information. The company says no illegal system access or loss, compromise, or exfiltration of data occurred; see its incident FAQ.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did background checks and video interviews not stop the hire?

The central gap was identity assurance. A records-based background check can confirm that an identity and its associated records exist; it cannot necessarily prove that the applicant is the person entitled to use them. The FBI’s 2024 advisory describes the broader use of stolen identities and U.S.-based facilitators in schemes targeting businesses.

#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
Check or control What it can establish What it does not establish on its own
Background and records checks Whether submitted information matches records associated with an identity. Whether the applicant is the legitimate identity holder.
Live video interview Whether a person can participate in a live conversation and answer questions. That the person is the named applicant, is not being assisted, or will be the sole device operator.
Technical assessment Whether the candidate can demonstrate relevant skills in the assessment. Legal identity, trustworthiness, or who will perform the job after hiring.
Location and equipment checks Whether shipping, work location, and technical signals are consistent with expected arrangements. That a domestic address or device host is trustworthy in isolation.
Endpoint monitoring Suspicious behavior on an enrolled device, such as unauthorized software activity. Fraud-free hiring or prevention of every intrusion before it begins.

KnowBe4 reported that the photograph was AI-enhanced or manipulated, but the identity itself belonged to a real U.S. person and the person in the interviews was apparently real. That is not evidence that AI generated the entire identity. Video remains useful; it simply needs to sit alongside identity checks, live skill verification, controlled equipment delivery, and technical monitoring.

What is a laptop farm, and why does it matter?

A laptop farm is an arrangement in which a local intermediary receives and hosts a company computer while the actual worker connects to it remotely. The employer may see a device and shipping address in the expected country even though the person operating it is elsewhere. This can make apparent location, network traffic, shipping records, and working hours look more consistent with a stolen identity. KnowBe4 discusses this model in its FAQ and a company white paper.

The concern is not that every shared address or remote connection is suspicious. Distributed teams may legitimately use shared homes or coworking spaces. Risk rises when address, identity, device, network, payment, or interview signals conflict, or when multiple applicants appear tied to the same infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

Why do North Korean operatives seek remote IT jobs?

U.S. government advisories describe remote IT work as a way for North Korean operatives and facilitators to generate revenue while concealing workers’ locations and evading sanctions. The arrangement can also create opportunities for data theft, extortion, intellectual-property theft, or later intrusion. The FBI’s 2024 alert explains the use of identity fraud and U.S.-based individuals; the Justice Department has described coordinated actions against the broader scheme in its announcement.

This case concerns a suspected North Korean fake IT worker, but the defensive lesson is not limited to one country. Any fraudster, criminal proxy, insider, or state-sponsored operator may exploit stolen identity information and remote-access arrangements. The risk is identity fraud and concealed control of a worker or device—not a person’s nationality or ethnicity.

What should employers change in hiring and onboarding?

No single check reliably proves identity, capability, location, and trustworthy device control. Use checks that address different failure modes, then keep access limited while monitoring behavior.

Before the interview

  • Verify employment history and references using contact details found independently, not only the details provided by the applicant.
  • Compare the résumé, professional profiles, references, public records, work authorization information, and claimed location for inconsistencies.
  • Look for reused phone numbers, email addresses, résumé language, or application materials across candidates.
  • Treat a clean background check as one input, not proof that the applicant controls the identity.
  • Set a documented risk tier for roles that would have privileged access, source-code access, production credentials, financial authority, or sensitive customer data.

The FBI’s 2025 advisory provides current warning signs and mitigation guidance for organizations dealing with suspected North Korean IT-worker activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

During interviews and assessments

  • Use multiple live interviews with different interviewers and ask unscripted, role-specific questions.
  • For technical roles, ask candidates to explain or modify code, troubleshoot a problem, or navigate a work environment live.
  • Where legally appropriate, use identity-verification technology, but do not treat facial matching or a video call as conclusive.
  • Pay attention to mismatches between the claimed background and technical, language, or location signals; investigate discrepancies rather than treating any one signal as proof.
  • Train HR, recruiters, and hiring managers as well as security staff. The first opportunity to catch a mismatch is often in the hiring workflow.

At onboarding and before granting access

  • Verify identity again at onboarding and confirm that the person receiving the equipment is the person hired.
  • Use controlled, auditable equipment delivery. Investigate third-party residences, forwarding services, or other unexpected destinations in context; a domestic address alone is not proof of fraud.
  • Require secure device enrollment into management and endpoint-security systems before access is granted.
  • Start with a minimally provisioned workstation and grant access only as needed, using least privilege, just-in-time access, strong multifactor authentication, and separate administrative accounts.
  • Block unauthorized remote-control software where practical and monitor for unexpected remote sessions.
  • Review device location, network, VPN, identity-provider, and authentication anomalies against the employee’s expected work arrangement.

Signals to review across the process

  • Work history, references, résumé, or online profiles do not align.
  • Applicants reuse contact details, résumé language, or communication accounts.
  • A candidate avoids live interaction, relies unusually heavily on scripted or written communication, or appears to receive assistance.
  • Apparent location conflicts with technical, logistics, payroll, or employment records.
  • Several workers appear connected to the same address, device, VPN, or remote-access infrastructure.
  • A worker requests unusual payment arrangements or asks for funds to pass through intermediaries.
  • A new account immediately attempts to disable security tools, change logs, install unauthorized software, or reach services unrelated to the job.
  • Records checks pass, but the applicant cannot convincingly demonstrate control of the identity and employment credentials being used.

These are indicators to investigate, not a checklist for inferring nationality. KnowBe4 also published hiring-process recommendations after the incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did KnowBe4’s controls limit the incident?

The public account describes several layers that constrained risk: a minimally provisioned workstation, device-management and endpoint-security tooling, and a response team able to isolate the device after an alert. These controls did not prevent the fraudulent hire; they reduced what a newly issued device could reach and helped detect suspicious behavior after onboarding.

  • Least privilege and minimal provisioning reduce the systems and data a new account can reach before trust is established.
  • EDR and device management can flag malware-related actions, unauthorized execution, and suspicious endpoint behavior, then support isolation.
  • Identity and session controls make it possible to restrict access, require strong authentication, and revoke active sessions when an account is suspect.
  • Recruiting and equipment controls address the earlier identity and physical-device gaps that endpoint monitoring cannot solve.

EDR is a backstop, not a hiring-fraud detector. It may act only after an operator has obtained a foothold, and poorly tuned alerts can overwhelm responders. Identity verification, technical assessment, and device controls also have costs: recruiting friction, false positives, privacy and retention obligations, and jurisdiction-specific legal requirements. Technical ability does not prove identity, and no identity check guarantees that the verified person remains the device’s only operator.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

What should a company do when a suspicious employee device is detected?

  1. Isolate the device while preserving evidence. Avoid wiping it before incident responders determine what volatile evidence must be collected.
  2. Restrict the account. Suspend access as appropriate and revoke active sessions, tokens, API keys, and credentials that may be exposed.
  3. Preserve relevant records. Secure endpoint, identity-provider, VPN, email, cloud, and file-access logs.
  4. Investigate device control. Determine whether the machine was remotely controlled or hosted by a third party.
  5. Look for related activity. Review associated identities, addresses, phone numbers, payment accounts, devices, and other applicants.
  6. Engage the right responders. Contact internal legal counsel, incident response, and relevant law-enforcement contacts; the FBI’s 2025 advisory asks organizations to report suspected activity promptly to the Internet Crime Complaint Center.
  7. Assess notification duties from established facts. Notify customers or regulators when required by applicable law and confirmed incident facts, rather than assuming either that a breach occurred or that no notification is needed.

The FBI’s 2025 guidance covers response and reporting considerations for suspected activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this incident does—and does not—show

It shows that conventional background checks and several video interviews can fail to establish who is actually applying, and that a local equipment host can obscure where a remote worker is operating. It also shows why limited initial access and endpoint monitoring matter: KnowBe4 says those controls detected suspicious workstation activity and the company contained it before a confirmed breach.

It does not show that KnowBe4’s customer information was stolen, that all remote hiring is unsafe, or that video interviews are worthless. KnowBe4 reported no illegal access to its systems and no data lost, compromised, or exfiltrated. The FBI’s advisories and the Justice Department’s enforcement announcement establish that the wider remote-worker scheme is a real concern, but they should not be read as independently verifying every detail of KnowBe4’s account.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.