FBI warns North Korean operatives exploit weak identity checks in hiring and onboarding
The FBI has repeatedly flagged that North Korean IT workers are using fraudulent or stolen identity documents, proxy infrastructure and US-based facilitators to pass remote hiring processes and gain access to corporate networks. Rather than stealing existing credentials, these attackers get organizations to create new credentials for them during onboarding, exploiting the fact that Zero Trust and MFA controls assume an identity already exists. The FBI now recommends verifying identity both during hiring and continuously throughout remote employment.