The Guardrail That Failed Was One Sentence: "This Is a Test."
Six companies got breached the same way: someone told an AI coding assistant it had permission, and the assistant didn't ask twice.
Malicious insiders, negligent employees, credential misuse, and privilege abuse.
Six companies got breached the same way: someone told an AI coding assistant it had permission, and the assistant didn't ask twice.
For three years, a woman in Arizona kept company laptops running in her spare bedroom for North Korean operators she'd never met. Three hundred and nine US companies hired the people on the other end. None of them noticed.
On June 4, the Five Eyes intelligence alliance published its first-ever joint bulletin titled "Safeguarding Our Secrets," warning that China's military intelligence services are systematically impersonating headhunters on LinkedIn to recruit sources inside government, defense, media, and any organization with access to trade secrets or sensitive technology. The fake recruiters operate through front companies with storefronts in Singapore and New York. They offer cash for "articles" and "market insights," requests that sound like consulting work until the questions narrow to classified programs, proprietary processes, or deal timelines. Payments arrive through PayPal, Wise, Zelle, and cryptocurrency.
Your outside counsel knows your acquisition targets, your deal timing, and your pricing strategy. Your incident response firm knows your insurance limits, your negotiating position, and your network architecture. Your compliance auditor knows where your security controls are weakest. You handed all of it over voluntarily because the relationship required it.
Two cybersecurity professionals hired to defend companies against ransomware were running it against them instead. On April 30, Ryan Goldberg, a former incident response manager at Sygnia, and Kevin Martin, a former ransomware negotiator at DigitalMint, were each sentenced to four years in federal prison for deploying BlackCat ransomware against multiple US victims during a six-month spree in 2023.
State of the Threat readers have followed this story all year. February 21: we covered the shift from fake LinkedIn profiles to stolen real identities. March 8: nearly every Fortune 500 CISO admitting they had unknowingly hired at least one DPRK IT worker. March 22: Treasury sanctions on the facilitators. This week, the prosecutions arrive.
North Korea stole $2 billion in crypto with 74% fewer attacks. That got the headlines. What didn't: nearly every Fortune 500 CISO admits to unknowingly hiring at least one North Korean IT worker.
A Chinese businessman stole F-35 blueprints in 2008. A former F-35 instructor was just arrested for training the pilots who will fly against them.