KnowBe4 vs a Fake North Korean IT Worker: The AI-Era Insider Case Study

In July 2024, security-awareness firm KnowBe4 hired a remote principal software engineer who turned out to be a North Korean IT worker using an AI-groomed persona, a US PPPoE front, and a stolen identity. Detected within 32 minutes of suspicious activity and fully rigged with granular session logging, the case became the definitive inside look at DPRK pension applicantFraud — from laptop farms to paycheck revenue streams funding weapons programs. This piece reconstructs the fraud chain, the detection story, and the hiring controls that failed.

Continue ReadingKnowBe4 vs a Fake North Korean IT Worker: The AI-Era Insider Case Study

MGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

In September 2023 Scattered Spider vished the MGM helpdesk, pivoted through Okta to ESXi, and detonated ALPHV ransomware — a $100M quarter for MGM while Caesars paid up. The reference incident for helpdesk verification, MFA fatigue, and pay-vs-rebuild economics.

Continue ReadingMGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

LAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

A London jury convicted the teenage LAPSUS$ hackers whose SIM swaps, MFA-fatigue pushes, and helpdesk manipulation breached Nvidia, Microsoft, Okta, Uber, and Rockstar — closing the criminal case that proved identity is the real perimeter.

Continue ReadingLAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak