Identity

How to catch what background checks aren’t built to see

Insider threats

COMMENTARY: The insider threat model that most security teams carry was built around a specific scenario: an employee already inside the organization — disgruntled, negligent, or compromised — who misuses access they legitimately hold. That model still holds, but a second one has emerged, where the access itself becomes the fraud, not something misused after it's granted.

Earlier this month, the FBI confirmed it’s investigating a North Korean remote IT worker who was employed by a federal agency, adding a government target to a campaign that has quietly embedded operatives inside hundreds of private-sector companies. The FBI estimates thousands of these operatives are actively applying for remote roles across the United States; The U.N. puts the scheme’s revenue between $250 million and $600 million annually.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

In a recent documentary, the Wall Street Journal traced a single cell of North Korean workers through browser history, emails, calendars, and never-before-seen screen recordings — that one cell alone applied to more than 1,000 companies in roughly three months. Using stolen identities, AI-generated credentials, U.S.-based accomplices running laptop farms, and VPN-masked locations, DPRK operatives applied for and won remote jobs, funneled hundreds of millions of dollars back to Kim Jong Un's weapons programs, and in several cases exfiltrated sensitive data on their way out.

Our own threat intelligence team has a direct view into this activity. Over the past 18 months, Abnormal AI flagged roughly 3,500 fraudulent applicants and conducted deeper intelligence gathering on about 1,000 more. That includes DPRK operatives as well as candidates tied to Nigerian, Pakistani, and other threat actors, with direct collaboration observed between some of these groups.

This has become the new insider threat. The operatives are inside, have access, and work against the organization. But everything that matters happened before they were hired. The threat walked right in the front door through the hiring funnel.

Why existing controls don't see it

The vetting process that most organizations rely on wasn't designed to catch this. The response architecture built around the conventional insider threat model has been oriented toward monitoring. Traditional tooling includes behavioral analytics on existing employees, DLP at egress points, privilege reviews, and investigation workflows triggered by anomalies in accounts provisioned months or years ago, but nothing that keeps an eye on the front door.

Background checks are aimed at the front door, but weren't built for that either because they work against documented history. For example, an identity that has been carefully fabricated with a plausible name, manufactured employment history, a U.S.-based phone number and address, and a consistent social footprint passes through those checks reliably. It's designed that way.

These operatives build identities engineered to look clean, so the signals that actually matter never surface in standard HR screening. One candidate with a VoIP burner number, a recycled resume template, and inconsistent IP address pattern doesn’t necessarily scream infiltration on its own — to the organization evaluating that candidate, these “tells” simply show up as an unremarkable phone number, a tidy work history, and a single location.

AI has become central to the campaign at every stage. From generating convincing resumes and identity documents, to enabling deepfakes during video interviews and helping operatives perform as competent employees throughout the engagement. A background check that confirms a fabricated identity confirms that the fabrication was successful, not a vetting failure.

The perimeter has moved

Security teams have spent years extending their detection surface, from the network perimeter to the email inbox and from SaaS applications to cloud workloads. The North Korean IT worker campaign has pushed that same extension into new territory: the hiring stage.

The challenge is that no individual organization sees enough of this campaign to recognize it. One company sees one resume, one application, and one candidate who clears screening and receives device access. In isolation, nothing looks wrong. But across organizations, the campaign has fingerprints.

My team has observed these patterns specifically: one operator interviewing under multiple identities at the same company, candidates who rejoin a video call under a different name after getting disconnected, and resumes with cloned career summaries and identical phone numbers applied to completely different organizations weeks apart.  Each instance looks unremarkable on its own, but together, they reveal a coordinated operation. That's where behavioral and threat intelligence signals start to matter, applied not to internal user behavior but to the identities entering the organization from outside.

Behavioral AI applied at the point of entry operates on different logic than traditional insider risk tooling: understanding what a legitimate identity looks like and surfacing patterns inconsistent with that baseline before access ever gets granted. A background check confirms someone’s identity. Behavioral AI has been built to see through who they're pretending to impersonate.

What practitioners should do now

The incidents making headlines are not rare enough to treat as outliers. Instead of asking "could this happen to us?" security teams need to ask "would we know if it already had?"

A few points worth examining:

  • Understand what the company’s hiring funnel exposes. IT support, software development, and any remote role with early access to cloud systems, codebases, or internal tools are the primary targets. Roles where provisioning happens quickly in the employment process deserve specific scrutiny.
  • Add security review to the hiring workflow. HR and recruiting teams aren't built to run identity threat analysis because this isn't what their tools are designed to catch. Security teams need a seat in that workflow.
  • Look for campaign-level signals, not individual-level ones. It’s easy to miss a single suspicious application and easy to explain away. A cluster of similar personas appearing in the same hiring window, sharing infrastructure or resume patterns, represents a coordinated campaign. Teams actually need detection that connects those dots across candidates, rather than evaluating each in isolation.

Security teams that extend their detection to the hiring funnel, and bring the same rigor to incoming identities that they apply to existing users, are positioned to catch what background checks aren't built to see. Companies need to act before onboarding, and for most organizations, it’s a window that’s still open.

Mick Leach, Field CISO, Abnormal AI

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

You can skip this ad in 5 seconds