Skip to content

Leadership1 publisher3 min readPublished

FBI says North Korean IT workers are ransoming stolen code once employers spot them

An updated bureau alert describes hired developers copying repositories into personal cloud accounts and then demanding payment once they are found. Seven of its eleven recommendations still sit at the hiring gate.

The Board Room · Leadership desk

Illustration accompanying FBI says North Korean IT workers are ransoming stolen code once employers spot them

What happened

  • The FBI updated its guidance on North Korean IT workers, saying their activity against US-based businesses has recently included data extortion.
  • The FBI says workers have copied company code repositories such as GitHub into their own user profiles and personal cloud accounts, behaviour it notes is common among developers generally.
  • Suspected victims are asked to file with the FBI's Internet Crime Complaint Center as quickly as possible and to capture activity from the suspect's assigned devices.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision Ending the contract and cutting access is the step that brings the ransom demand, so the timing of any confrontation with a suspected hire is a decision for incident response and counsel as much as HR.
  • cost Ransom payment still leaves the code exposed: the FBI records instances of proprietary code released publicly anyway, so the loss falls on whatever commercial advantage that code held.
  • constraint An offboarding checklist built around disabling accounts may still leave access open, because the bureau flags harvested credentials and session cookies used from devices the company does not own.
  • exposure Companies that staff through third-party firms carry the verification burden themselves under this guidance. The vendors they have to verify are ones they do not employ and cannot directly discipline.

Earlier federal guidance was written for the hiring gate. Joint advisories in 2022 and 2023 set out red-flag indicators and due-diligence measures for businesses trying not to hire North Korean freelance developers [15]. The pattern in the current alert starts later: the hire has already happened, and the incident opens when the employer works out who it hired. Workers discovered on company networks have held stolen proprietary data and code hostage until ransom demands were met, and in some instances have publicly released a victim company's proprietary code [3][4].

That puts two conversations in the same week. Revoking access and ending the contract is the ordinary first response to a fraudulent hire, and on the FBI's account it is also the point at which the leverage appears, because the extortion followed discovery [3]. The bureau's post-discovery advice is to report to its Internet Crime Complaint Center as quickly as possible and to capture activity from the suspected employee's assigned devices using internal intrusion-detection software [14].

The recommendation list itself is still mostly about hiring. Four items cover data monitoring and seven cover remote hiring, 11 in all, so 7 of the 11 apply before the person starts work [18][17]. The hiring items include doing as much of hiring and onboarding in person as possible [12] and cross-checking HR systems for applicants who share resume content or contact information [10]. The FBI says workers have used artificial intelligence and face-swapping technology during video job interviews to obscure their identities [11].

One line in the alert names the detection problem. Copying company repositories such as GitHub to personal user profiles and cloud accounts is, the FBI wrote, "not uncommon among software developers", and the same activity "represents a large-scale risk of theft of company code" [5]. The signals the alert offers are behavioural: multiple logins to one account in a short period from IP addresses in different countries [6], and endpoint software that allows several concurrent audio and video calls [7]. Monitoring advice also covers browser session activity and private code repositories as exfiltration paths [20].

Account disablement is the other assumption worth testing. The FBI says the workers could attempt to harvest company credentials and session cookies in order to start work sessions from non-company devices [8]. It puts that as a possibility. The alert is silent on how many companies have been extorted or what sums were demanded [22].

Counting the bureau's own reference list, this is the fourth round of public guidance since 2022: advisories in 2022 and 2023, further FBI guidance in May 2024, and this update [19]. The current one asks employers to verify third-party staffing firms' hiring practices and to audit those practices routinely [13].

What to watch

  • Whether a later FBI update puts numbers to victim companies, ransom demands or payments.
  • Whether any US employer discloses an extortion payment made to a worker it hired remotely.
  • Whether code hosting and cloud providers add controls on copying company repositories into personal accounts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories