Insider Threat

Malicious insiders, negligent employees, credential misuse, and privilege abuse.

The New Hire Who Never Existed

For three years, a woman in Arizona kept company laptops running in her spare bedroom for North Korean operators she'd never met. Three hundred and nine US companies hired the people on the other end. None of them noticed.

The Headhunter on LinkedIn Is a Chinese Intelligence Officer

On June 4, the Five Eyes intelligence alliance published its first-ever joint bulletin titled "Safeguarding Our Secrets," warning that China's military intelligence services are systematically impersonating headhunters on LinkedIn to recruit sources inside government, defense, media, and any organization with access to trade secrets or sensitive technology. The fake recruiters operate through front companies with storefronts in Singapore and New York. They offer cash for "articles" and "market insights," requests that sound like consulting work until the questions narrow to classified programs, proprietary processes, or deal timelines. Payments arrive through PayPal, Wise, Zelle, and cryptocurrency.

What Your Law Firm Knows About You

Your outside counsel knows your acquisition targets, your deal timing, and your pricing strategy. Your incident response firm knows your insurance limits, your negotiating position, and your network architecture. Your compliance auditor knows where your security controls are weakest. You handed all of it over voluntarily because the relationship required it.

The Responders Were the Attack

Two cybersecurity professionals hired to defend companies against ransomware were running it against them instead. On April 30, Ryan Goldberg, a former incident response manager at Sygnia, and Kevin Martin, a former ransomware negotiator at DigitalMint, were each sentenced to four years in federal prison for deploying BlackCat ransomware against multiple US victims during a six-month spree in 2023.

Tony, Danny, and Eighty People Who Were Not There

State of the Threat readers have followed this story all year. February 21: we covered the shift from fake LinkedIn profiles to stolen real identities. March 8: nearly every Fortune 500 CISO admitting they had unknowingly hired at least one DPRK IT worker. March 22: Treasury sanctions on the facilitators. This week, the prosecutions arrive.

China's Kill Chain Is 15 Years Long

A Chinese businessman stole F-35 blueprints in 2008. A former F-35 instructor was just arrested for training the pilots who will fly against them.