Skip to main content

Private Threat Briefing

Inside the North Korean IT Worker Operation

How Nation-State Actors Attempt to Infiltrate Organizations Through the Hiring Funnel

Abnormal's threat intelligence team is tracking an ongoing operation in which North Korea-linked actors pose as job seekers and attempt to join companies as seemingly legitimate employees. Their strategy: apply for a role, pass the interview, get hired, and operate from inside the badge. No phishing required.

  • The five-stage hiring-fraud lifecycle, from identity creation to authorized insider access
  • How stolen and synthetic identities, persona reuse, and deepfakes defeat standard screening
  • The indicators and detection opportunities that surface before access is granted
Date
Monday, September 28, 2026
Time
11:00 AM ET
Location
Virtual

Event starts in

Event starts in.

Save Your Seat

Reserve your place for this private threat briefing.

In This Briefing

What You'll Learn

The Hiring-Fraud Lifecycle

The five-stage hiring-fraud lifecycle, from identity creation to authorized insider access.

Defeating Standard Screening

How actors use stolen and synthetic identities, persona reuse, and deepfake- and proxy-backed interview activity to defeat standard screening.

Linking 100+ Actors

How Abnormal's threat intelligence team linked more than 100 actors through reused infrastructure, lexicon patterns, network egress, and persona artifacts.

Indicators & Detection

Key indicators of a targeted hiring pipeline and detection opportunities that surface before access is granted.

Your Hosts

Speakers

Mike Britton

Mike Britton

Chief Information Officer, Abnormal AI

Piotr Wojtyla

Piotr Wojtyla

Director, Threat Intelligence, Abnormal AI