As a follow-up to our August post on North Korean “laptop farms” and IT-worker infiltration schemes, the FBI has published a number of excellent, common-sense steps businesses and other organizations can take to reduce the risk of unknowingly employing a North Korean operative.
The recommendations are practical. But they also require employers to look beyond traditional hiring practices. Following each FBI recommendation below, IP Probe adds some additional context.
Scrutinize Identity Verification Documents
The FBI recommends checking identity documents for misspellings and inconsistencies and cross-referencing photographs and contact information—including phone numbers, addresses and email addresses—with social media profiles, portfolio websites and payment platforms.
This remains important, but it may not be as effective as it once was. Artificial intelligence provides sophisticated operatives with increasingly effective tools for identifying spelling errors and inconsistencies before documents are submitted.
Employers should therefore look beyond the document itself. Does the address exist? Does it correspond with what the applicant claims? Does the individual’s online history make sense? A simple Google Maps search, reverse-image search or examination of an applicant’s digital footprint may reveal inconsistencies worth investigating.
Verify Prior Employment and Education
The FBI recommends verifying prior employment and higher-education history directly with businesses and educational institutions.
The key word is directly.
Do not automatically rely upon telephone numbers, email addresses or websites supplied by the applicant. An operative can provide contact information leading to an accomplice—or to someone impersonating a legitimate company or university.
Independently locate the organization’s official contact information and make the inquiry yourself.
Require In-Person Meetings When Possible
When feasible, the FBI recommends in-person drug testing, fingerprinting or other procedures that help verify an applicant’s identity and claimed location.
For virtual meetings, employers should require video, ask that backgrounds remain unobscured and consider asking the individual to point the camera out a window while answering questions about the location.
The FBI also suggests asking the individual to wave a hand in front of his or her face, which may expose problems with AI-generated video.
These are clever techniques, although this is an area employers will need to continually reassess. AI-generated imagery and video are improving rapidly. It is not difficult to imagine technology eventually generating a convincing outdoor scene consistent with an address supplied by an operative.
“Today’s verification technique may not be tomorrow’s.”
Capture Images of Individuals
The FBI recommends capturing images during interviews for comparison during subsequent meetings.
This addresses an important vulnerability: the person who interviews for a position may not be the person who ultimately performs the work.
An accomplice—sometimes even an American citizen—could participate in an interview or otherwise help an operative establish a fraudulent identity. Comparing images from interviews, onboarding and subsequent meetings provides another relatively simple layer of verification.
“The person who interviews for a position may not be the person who ultimately performs the work.”
Analyze Payment Methods
Employers should compare employee payment information and look for accounts established using similar documentation or identical banking information.
This is where technology can work in the employer’s favor. Analytical software can identify connections between accounts, addresses, telephone numbers and other data associated with supposedly unrelated employees.
Repeated changes in banking information should also receive attention, particularly if accounts are repeatedly closed or replaced.
The FBI additionally warns employers about requests for payment in virtual currency. Cryptocurrency can facilitate rapid international transfers and has repeatedly been used by state-sponsored actors and organized criminal groups to move and obscure funds.
None of these factors alone proves wrongdoing. Patterns, however, matter.
Control the Shipment of Work Materials
If laptops, documents or other work-related equipment are shipped to remote employees, the FBI recommends sending them only to the address appearing on the employee’s verified identification.
Requests to ship equipment elsewhere should trigger additional verification.
Just as importantly, companies should not grant access to sensitive systems until background and identity checks have been completed.
“A laptop is not simply office equipment. In the wrong hands, it can become the doorway into an organization’s network.”
Closely Examine Contracted IT Workers
Third-party IT contractors deserve particular attention because contract employment has been a significant avenue for North Korean IT workers seeking access to American companies.
Employers should determine exactly what screening procedures recruitment and staffing companies use.
One practical approach would be to develop a written questionnaire requiring vendors to identify their procedures: Do they independently verify identification? Education? Employment history? Physical location? Banking information? Do they conduct live video interviews?
Don’t simply assume the staffing company has done it.
Final Thoughts
These recommendations amount to something more than an enhanced background check. They represent a different way of thinking about hiring in an era of remote employment, artificial intelligence and increasingly sophisticated identity fraud.
Companies can no longer afford to accept a résumé, identification document and video interview at face value.
They need to dig deeper, connect the dots and, when necessary, get into the weeds.
And don’t dismiss intuition.
If something doesn’t look right, follow up. If information doesn’t fit, verify it independently. If an applicant’s story changes, ask why.
A legitimate applicant may consider the additional scrutiny inconvenient. That is preferable to discovering months later that the person given remote access to your network was never who you thought they were.
“The objective is not simply to prevent an operative from getting hired. It is to prevent that operative from gaining access to your organization’s most valuable assets.”
Additional Reading & Resources
- Know Your Researcher: Academic Espionage & Trade Secrets Theft — IP Probe
- Remote Job Interviews and Application Fraud — The Wall Street Journal
- North Korean IT Worker Threats to U.S. Businesses — FBI
- Hidden in Plain Sight: Labor, Employment and Cybersecurity Risks — Holland & Knight
- Alert Regarding North Korean IT Workers — U.S. Department of State
- Tornado Cash Founders Linked to North Korea Indicted for Laundering Over $1 Billion in Criminal Proceeds — IP Probe
- NFT Collectors Beware: North Korean Hackers Are Phishing in Your Waters — IP Probe
Disclaimer: IPProbe.Global is a service to the professional IP community. While every effort has been made to check the information in this blog, we provide no guarantees or warranties, express or implied, regarding the content provided in IPProbe.Global. We disclaim all liability and responsibility for the qualification or accuracy of representations made by the contributors or for any disputes that may arise. It is the responsibility of the readers to independently investigate and verify the credentials of such persons and the accuracy and validity of the information provided by them. This blog is for general information only and is not intended to provide legal or other professional advice.
