• Wion
  • /World
  • /Company hacked after accidentally hiring North Korean cyber criminal for a remote IT role

Company hacked after accidentally hiring North Korean cyber criminal for a remote IT role

Company hacked after accidentally hiring North Korean cyber criminal for a remote IT role

(Representative Image) Increasing cyber crimes from North Korea

An unidentified firm fell prey to a North Korean cyber criminal who got hired as a remote IT worker and hacked the company's system, the BBC reported. The company which is based in the UK, US and Australia did not want to be named.

The company hired the North Korean technician online, who faked his employment history and personal details.

Once given access to the company’s computer network, the hackerdownloaded sensitive data and sent a ransom demand.

Add WION as a Preferred Source

This is the latest case in a series of such cyber crimes where a North Korean has been masked as western remote worker.

Also Read |India: 373 govt websites hacked in past 5 years; house panel calls for strengthening digital infrastructure

The firm allowed cyber responders from SecureWorks to report the hack to spread awareness and warn others. Secureworks said the IT worker, thought to be a man, was hired in the summer as a contractor. He used the firm’s remote working tools to log into the corporate network.

He then downloaded as much company data as possible as soon as he had gained access to internal systems. The man worked with the firm for four months and even collected his salary.

Researchers say this was likely redirected to North Korea in a complex laundering process to evade western sanctions on the country.

Watch |‘Cyber Crime Is The New Geopolitical Weapon:’ Ex-Foreign Affairs Secretary Shyam Saran

After the firm sacked him for poor performance, it received ransom emails containing some of the stolen data with a demand of a six-figure sum, to be paid in cryptocurrency.

The man threatens to publish or sell all the stolen information online if his demands aren’t met. The firm did not disclose whether it paid the ransom.

Fraudulent North Korean IT worker schemes

This case was not an isolated incident - cybersecurity authorities have been warning about the rise of North Korean infiltrators since 2022.

The US and South Korea have accused North Korea of tasking thousands of staff to take on multiple well-paid western roles remotely to earn money for the regime and avoid sanctions.

In September cyber security company Mandiant said dozens of Fortune 100 companies have been found to have accidentally hired North Koreans. However, cases of North Korean employees hacking their employers remain rare.

Also Read |GPS spoofing that disrupts aircraft rose by 400 per cent. Will it cause a serious accident?

"This is a serious escalation of the risk from fraudulent North Korean IT worker schemes," Rafe Pilling, Director of Threat Intelligence at Secureworks, was quoted as saying by the BBC.

"No longer are they just after a steady paycheck, they are looking for higher sums, more quickly, through data theft and extortion, from inside the company defences."

(With inputs from agencies)