An FBI official has said the bureau identified a North Korean remote IT worker who had been working for a US federal agency. The agency wasn't named, and the FBI hasn't said how the person was hired, how long they were there or what they could reach.
This scheme has been running for years against private companies. Workers use stolen or fabricated identities, and people in other countries receive company laptops on their behalf so the location checks out.
Why a Cardiff practice should care
Remote CAD technicians, BIM modellers and overseas drafting support are common in our sector, and the roles come with access to project files, client data and sometimes the CDE. That's exactly what these operations want.
Before you hire remotely
- Verify identity, previous employment and location, ideally on a live video call with ID.
- Send company equipment only after those checks are complete, and to the address that matches.
- Give access to the systems the role needs, not the whole tenant, and review it after 90 days.
Hiring remote employees or contractors? We can set up limited, monitored access so a bad hire can't become a bad breach.
Want a hand with this? Talk to us.
Source: TechCrunch: North Korean remote IT staffer worked for US government agency, says FBI