Large firm gets infiltrated, blackmailed by North Korean who landed a remote IT job
The National Cyber Security Centre (NCSC) has advised employers to carry out face-to-face interviews after a recent case of a North Korean citizen landing a remote IT contractor job at a New Zealand business.
The NCSC revealed the case in its Cyber Threat Report 2026, saying the North Korean worker used a false persona, including fake identity documents, to gain employment and later blackmail the company into paying him.
"To mitigate the risk of employing North Korean IT workers, organisations should consider interviewing potential staff face-to-face and require new staff to pick up IT equipment personally," the NCSC said in the report.
It also told employers to be vigilant for other risk factors, such as requests to be paid in cryptocurrency, refusal to participate in video-conference meetings, and the recording of unusual working hours.
North Korean lands remote IT job
In this case, the NCSC said the North Korean worker used a New Zealand address as a contact point, and even recruited a New Zealand citizen to receive and operate the company's laptop.
The employer eventually became suspicious of the worker's identity and reported it to the NCSC and the police, who identified the worker as being from North Korea after an investigation.
"The New Zealand business immediately terminated the employment of the North Korean worker and refused to pay for their services," the report read.
"The worker then claimed to have obtained commercially sensitive information and threatened to release this if not paid."
North Korean nationals are prohibited from obtaining work visas as their state is subject to United Nations sanctions, which are in effect in New Zealand.
Other restrictions include a prohibition on the export of data and software to, for use in, or for the benefit of North Korea.
But the NCSC warned that North Korea operates a coordinated programme of using remote IT workers to generate revenue for the regime.
"These workers often operate under front companies overseen by the North Korean state apparatus. The IT workers use identity masking technology to hide their North Korea identity when securing contracts for remote work," the NCSC said.
What can employers do?
While face-to-face recruitment is advisable, it cannot be a blanket solution for organisations, especially for those hiring for remote roles.
Security awareness training provider KnowBe4, which also became a target of a North Korean poser, previously advised employers to educate staff involved in the hiring process.
"[Organisations should] consider various mitigation tactics such as updating the organisation's hiring process to include asking the candidate to submit fingerprints for identity verification purposes, threat model the organisation's hiring process, and more," KnowBe4 CEO Stu Sjouwerman previously said.
The company also advised employers to improve CV screening for career inconsistencies, get applicants on video camera, and ask them about the work they are doing. Other tips from KnowBe4 include:
- Scanning remote devices to ensure no one accesses them remotely
- Vetting more thoroughly to ensure that applicants and employees are physically where they are supposed to be
- Treating a laptop shipping address that differs from where the worker is supposed to live or work as a red flag
Increasing severity of cybercrime
In New Zealand, NCSC head Catriona Robinson reminded employers that they are "responsible" for the cyber security of their organisations.
"Government cannot protect every organisation from every cyber threat," Robinson said. "Those who prepare now will be best placed to manage the challenges of frontier AI."
She made the remarks as the NCSC's Cyber Threat Report 2026 showed that, of the 369 incidents of potential national significance handled by the centre during 2025/26, 162 were linked to criminal or financially motivated actors.
"The severity of incidents has increased," Robinson said. "During 2025/26 the NCSC recorded four incidents classified as C2, or Highly Significant. That's as many in one year as were recorded over the previous ten years."
She further warned that cybercriminals are becoming more "persistent, aggressive, and effective" in their pursuit of payment through extortion and data theft.
"Boards, chief executives, and senior leaders need to consider whether their businesses or organisations have the people, processes and resources needed to respond to a faster-moving cyber threat environment," Robinson said.