KnowBe4 mistakenly hires North Korean hacker, faces infostealer attack (www.bleepingcomputer.com)
from fne8w2ah@lemmy.world to technology@lemmy.world on 25 Jul 2024 16:58
https://lemmy.world/post/17946549

#technology

threaded - newest

AlternateRoute@lemmy.ca on 25 Jul 2024 17:15 next collapse

This report makes it sound like they had a video call with camera on, vs other reports where they recommend people have camera on because they didn’t

also used AI tools to create a profile picture and match that face during the video conference calls.

This doesn’t sounds like the video was on / faked only that they had a call where the profile picture was used.

octopus_ink@lemmy.ml on 25 Jul 2024 17:52 next collapse

It’s a little bit ironic to me that the security company formerly run by the man who literally wrote the book on social engineering may have fallen victim to a social engineering attack.

Evotech@lemmy.world on 25 Jul 2024 18:35 next collapse

And makes it’s living on telling other companies how to increase their security posture

cheese_greater@lemmy.world on 25 Jul 2024 20:20 collapse

The grift has come fulk circle

radivojevic@discuss.online on 25 Jul 2024 20:32 collapse

We learn more lessons by failing than succeeding.

octopus_ink@lemmy.ml on 25 Jul 2024 21:21 collapse

True, but Kevin certainly had his share of both.

GildorInglorion@lemmy.world on 25 Jul 2024 20:33 next collapse

(blog.knowbe4.com/how-a-north-korean-fake-it-worke…) They are saying they caught the guy before he had access to anything important.

Landless2029@lemmy.world on 26 Jul 2024 00:57 collapse

He made it though onboarding and got a company laptop with creds. Got flagged by SEC because he got malware day 1. Also they dug in and he was connected to the states with a VPN.

HR failed. SEC caught it. Now SEC/CIO yell at HR.

YeetPics@mander.xyz on 25 Jul 2024 20:38 next collapse

Boy, I bet they wish they… (drumroll) KnewBe4

TimeSquirrel@kbin.melroy.org on 25 Jul 2024 20:39 collapse

Guess they didn't KnowBe4.