By The Most Secure Man Alive | WISECLICK Ambassador
A company whose entire job is spotting fakes hired one anyway. The how is a better story than the who — and quietly, it's a story about the rest of us.
In the middle of last year, an American company posted a job for a senior software engineer. Nothing unusual in that. What's unusual is the company: KnowBe4, a security‑awareness firm whose whole business is teaching other people how to spot a con. If anyone on earth was going to catch a fake, it was them.
They did it all properly. They posted the role, sorted through the résumés, ran four separate video interviews, checked the background, called the references. The candidate was personable and sharp, the experience checked out, the face matched the CV. So they hired him, and they did the ordinary, decent thing an employer does for a new remote starter: they posted him a laptop.
Hold on that laptop for a moment, because it's the hinge the whole story turns on, and it's easy to read straight past. Sending a new hire a company computer is not a security decision. It's a kindness. It's the most ordinary act in modern work — here's your machine, welcome aboard, see you Monday. Which is precisely why it was the plan all along.
The laptop arrived at the address on file. It was switched on. And in KnowBe4's own words, the moment it was received, it immediately started to load malware. Their security team got an alert at four minutes to ten that night. By twenty past — about twenty‑five minutes later — they'd cut the machine off the network. In that small window the device had been busy: software run that shouldn't have been, files moved, session history quietly doctored to cover the tracks.
Here's what they pieced together afterwards. The man they'd hired didn't exist. The identity was a real American's, stolen and worn like a coat. The friendly face from the interviews was a stock photo an AI had been used to touch up. And the laptop hadn't gone to his home, because there was no him — it had gone to what investigators call a "laptop farm": an ordinary‑looking house, in this case run by a woman in Arizona, where rows of company laptops sat humming on shelves, each one kept switched on and online so that a worker on the other side of the planet could log in through it and appear, to payroll and IT, to be sitting in suburban America. He was, by KnowBe4's assessment — later shared with Mandiant and the FBI — a North Korean operative. He was an employee, alright. Just not theirs.
This is not a story about one clever fake
That Arizona house was not a one‑off. When the U.S. courts unwound it, the numbers were difficult to sit still through: the operation had placed North Korean workers into more than three hundred American companies, using dozens of stolen identities, funnelling something north of seventeen million dollars back home. The woman who ran the farm was sentenced to more than eight years. And hers was one of dozens of such farms pulled apart across the country in a single coordinated sweep.
It is, in other words, an industry. There is a recruitment pipeline. There are invented people — faces, histories, portfolios, references — manufactured at scale and sent out to apply for genuine jobs at genuine companies. Security researchers have watched these candidates use AI to smooth a profile photo, draft a cover letter, even soften their face on a live video call. One investigator's favourite trick for flushing them out, half‑joking, is to ask the candidate to say something unflattering about North Korea's leader and watch what happens — though even he admits it doesn't always work. The defences and the disguises are both getting cleverer. That's the shape of the thing now.
And before this files itself neatly under fascinating, but that's enormous companies with HR departments — look at what actually let it happen. Nobody broke in. No wall was scaled, no password cracked. The intruder was interviewed four times, reference‑checked, and welcomed. The front door was opened from the inside, because every box on the form had a tick beside it. The laptop was simply the most vivid way in. It is not the only one.
Because most businesses never post a freelancer a laptop. They hand over something lighter and far more useful: a login. The bookkeeper brought on at month‑end, the developer who came in a little cheaper, the virtual assistant with the tidy profile and the warm reviews — they're given a seat in the inbox, a shared drive, the keys to the rooms the business actually lives in. No hardware changes hands. It doesn't need to. The access does the same quiet work the malware did, from the inside, wearing a face nobody had a real way to check. The con that fooled a company of professional fake‑spotters and the risk sitting in an ordinary freelance hire are the same gap — one just has a bigger budget behind it.
The reassuring part
None of this rewards panic, and panic was never going to help anyway.
Here's the quiet good news buried in it. KnowBe4 lost nothing. No data taken, no real damage done — and not because they spotted the fake at the door, because they didn't. They were saved by something far more ordinary: the new starter simply hadn't been handed the keys to everything yet. His access was limited, the blast radius was small, and twenty‑five minutes was enough. The thing that protected a security company from a state‑sponsored operative wasn't genius. It was good housekeeping.
That's the whole lesson, and it scales all the way down to one person at a kitchen table. The Australian government now warns local businesses about exactly this — its advisory names Fiverr, Freelancer and LinkedIn as the places these workers reach Australian companies — and the advice underneath, the same dull, dependable advice you'll hear from cyber authorities in Britain and the United States, has nothing to do with being technical and nothing to buy.
And if you've ever taken someone on from a marketplace on the strength of a good profile and a friendly call — that isn't carelessness. It's how the modern world hires. The work came back fine, and it nearly always does. The point was never to be suspicious of every freelancer; the overwhelming majority are exactly who they say. The point is only that "the work came back fine" was never the same thing as knowing who they were.
The small part that's yours
Against a hire who might not be who they claim, there are two defences that actually work. Neither is technical. Neither costs a thing.
One — try hard to know who you're dealing with, before they're in. A live video call, an actual one, and a question their CV can't answer for them. Reach a reference through a channel you found yourself, not just the number they handed you. And if a face on the call seems oddly smooth or a half‑beat behind, trust the itch — there's even serious advice going around to ask a video candidate to wave a hand across their face, because a faked feed can stutter when they do. None of it is rude. The honest ones expect it.
Two — assume you might be wrong anyway, and give them one room, not the building. This is the one that matters most, because it's the only defence that still works after the first one fails. A new person — staff or freelancer — gets access to the thing they were actually hired for, and nothing else. Not the bank, not every client file, not the keys to everything. Remember KnowBe4: they did the vetting properly and the fake still got through — and they walked away unharmed for one reason only, that the new hire had barely been given anything yet, so there was nothing within reach worth taking. Start everyone in a small room, and widen it as the trust earns itself. It's the most reassuring habit in security, because it means being fooled doesn't have to cost you much.
One thing worth doing alongside those, though it guards a different door: put two‑step login on the access you hand out. It won't stop a hire who turns out to be dishonest — you gave them the key yourself, and they walk through every lock with it. What it stops is an outsider who steals or buys an honest freelancer's password and tries to slip in wearing their name. Most freelancers are exactly who they say, so that's a real and common risk, and the fix is free and takes a minute. Do it — just know it's a side door, not the one this story walked through.
That's the welcome — every kind of it — handled.
Knowing how to vet one new hire is a fine start. Knowing who can already reach what inside your business — which doors were left open behind someone long gone, who still holds a key to a room they no longer need — is the bigger question, and a calmer one once it's answered. That's what the Ransomware Readiness Check is for. Thirty minutes, $149, plain English, no fear — you walk out knowing the few things worth changing first. Understand your exposure. Know what matters most.
You don't need to learn the dark corners of this trade to stay clear of them. That's rather the point of having someone who already has.
See who can reach what. 30 minutes. Plain English. $149.
Take the Ransomware Readiness Check →You hold the keys. This shows you who else does.
Stay protected, my friends.
— The Most Secure Man Alive
Frequently asked questions
Would a small business really be targeted by something like this?
The people behind it aren't aiming at you — they're aiming at what you can reach, and a small business often hands over access faster than a large one. Australia's own advisory names Fiverr, Freelancer and LinkedIn as the places these workers reach local companies. Size is no protection. Habits are.
What's the simplest way to check a remote hire is genuine?
A live video conversation before any access is granted, one question their CV can't answer for them, and a reference you reach through a channel you found yourself — not only the number they handed you. Then start them with limited access and widen it as trust builds.
Isn't two‑step login overkill for a freelancer?
It depends what you're guarding against. Two‑step login won't stop a hire who turns out to be dishonest — you handed them the key yourself. What it does stop is an outsider stealing an honest freelancer's password and using it to slip into your systems as them. Most freelancers are exactly who they say, so that's a real and common risk, and the fix is free. But the defence that protects you even when a hire isn't who they claim is the bigger one: give every new person access only to what their job needs, and nothing more.
I've already given a contractor access to everything. What now?
No alarm needed — this is recoverable. Look at what they can currently reach, pull it back to only what the job needs, and change any shared passwords. If you'd like a clear read on where you stand, that's exactly what the Ransomware Readiness Check is for.
Who are Mandiant, and why does it matter that they were involved?
Mandiant are one of the most respected names in cybersecurity — the firm companies call in after a serious breach to work out what happened and who was behind it. Tracing an attack back to the group responsible is the thing they're famous for, and these days they sit inside Google Cloud as its threat‑intelligence arm. So when KnowBe4 said it shared its findings with Mandiant and the FBI, that's the detail that turns "we think this was North Korea" into a conclusion checked by the people who do this for a living — not an embarrassed company guessing.

Leave a comment
This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.