Security/ north korea · cybersecurity · remote work · nation-state

North Korean IT Workers Are Behind Half of Tech Sector Hacks

North Korean operatives posing as remote IT workers and recruiters drove roughly half of all tech-sector attacks last year, per CrowdStrike.

North Korean IT Workers Are Behind Half of Tech Sector Hacks

North Korea accounts for roughly half of all cyberattacks targeting the tech industry over the past 12 months, according to CrowdStrike.

The security firm found that North Korean operatives have been gaining access to U.S., European, and Asian companies by posing as remote IT contractors and recruiters. They are not finding vulnerabilities to exploit. They are getting hired. Once inside, they have access that most external attackers spend months trying to reach. At roughly half of all tracked tech-sector attacks over the year, this reads as an organized, sustained campaign rather than isolated fraud.

The tactic exploits something most security teams are not paid to guard: the hiring process itself. Traditional defenses assume the attacker is trying to breach a perimeter; these operatives sign offer letters instead. That asymmetry is hard to patch.

North Korea's remote-worker scheme has drawn public warnings from Western governments for years. That CrowdStrike is still reporting it at this scale suggests the industry has not taken those warnings seriously enough.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →