Announcing our $5M seed roundLearn more

When a bad hire becomes an insider threat

When a bad hire becomes an insider threat


3 minute read

Table of Contents

When a company hires a North Korean IT worker, the salary is the smallest part of the cost. The bigger cost is the access that comes with the job, because from the day the offer is signed the worker receives everything a normal employee does: login credentials, source code, internal systems, and customer data. In effect, the company has taken on an insider threat and handed it every permission a trusted employee would have. 

That access is what the operation is really after, and it is what makes this different from an ordinary security threat.

For years the damage tended to end with the salary, but that is no longer true. As more companies catch these workers and let them go, the workers have begun using their access as leverage. 

The hire creates the access

Remote engineers need access to code repositories, cloud environments, internal systems, and sometimes production infrastructure. Once the hiring process is complete, that access is usually granted based on the identity established during interviews and background checks.

In a 2025 federal case, four North Korean nationals were hired as remote developers by a blockchain company. After gaining their managers’ trust, two were assigned to projects that gave them control over company cryptocurrency.

Getting hired gave the group the access it needed to carry out the theft.

How the threat escalates

Once inside, a fraudulent employee can use legitimate access against the company.

The FBI warned in January 2025 that North Korean IT workers had copied company code into personal repositories and cloud accounts. Some also collected passwords and active login sessions that could preserve access after termination.

Because developers regularly move code and use cloud tools, this activity can resemble normal work and may not be detected until the information has already left the company.

The FBI also reported that some workers later used stolen code and data to extort former employers, threatening to release the information if the company refused to pay. Firing the worker may stop future access, but it does not recover what was already copied.

The risk can also become direct financial theft. In one case, individual thefts reached approximately $175,000 and $740,000, with total losses exceeding $900,000. One of the workers allegedly changed the code of two smart contracts to redirect the funds.

Why this is a hiring problem

Most security tools are designed to stop outsiders. A fraudulent employee, however, has valid credentials, an approved device, and company-issued permissions, essentially making them an insider threat. 

They do not need to bypass the security perimeter because the hiring process has already placed them inside it.

By the time the company detects the fraud, code may have been copied, credentials collected, or data moved elsewhere. Removing access cannot undo that damage and may trigger an extortion attempt.

The strongest point of prevention is therefore before the offer, not after the employee has entered the system.

Stop the threat before access is granted

Tofu verifies that each candidate is a real, distinct person before they are hired. This helps companies detect identity fraud and impersonation before a candidate receives credentials, code access, or customer data.

For teams hiring remote engineers, candidate verification is not only a hiring control. It is a way to make sure there is no insider threat. 

See how Tofu works.

« Back to Blog