Audio By Carbonatix
A company has been hacked after accidentally hiring a North Korean cyber criminal as a remote IT worker.
The unidentified firm hired the technician after he faked his employment history and personal details.
Once given access to the company’s computer network, the hacker downloaded sensitive company data and sent a ransom demand.
The firm which is based in the UK, US or Australia did not want to be named.
It has allowed cyber responders from SecureWorks to report the hack to spread awareness and warn others.
It is the latest in a string of cases of western remote workers being unmasked as North Koreans.
Secureworks said the IT worker, thought to be a man, was hired in the summer as a contractor.
He used the firm’s remote working tools to log into the corporate network.
He then secretly downloaded as much company data as possible as soon as he had gained access to internal systems.
He worked for the firm for four months collecting a salary.
Researchers say this was likely redirected to North Korea in a complex laundering process to evade Western sanctions on the country.
After the company sacked him for poor performance, it received ransom emails containing some of the stolen data and a demand to be paid a six-figure sum in cryptocurrency.
If the company did not pay, the hacker said they would publish or sell the stolen information online.
The firm did not disclose whether the ransom was paid.
Firms duped
Since 2022, authorities and cyber defenders have warned about the rise of secret North Korean workers infiltrating Western companies.
The US and South Korea accused North Korea of tasking thousands of staff to take on multiple well-paid Western roles remotely to earn money for the regime and avoid sanctions.
In September cyber security company Mandiant said dozens of Fortune 100 companies have been found to have accidentally hired North Koreans.

But secret IT workers turning on their employers with cyber attacks is rare, according to Rafe Pilling, Director of Threat Intelligence at Secureworks.
"This is a serious escalation of the risk from fraudulent North Korean IT worker schemes," he said.
"No longer are they just after a steady pay check, they are looking for higher sums, more quickly, through data theft and extortion, from inside the company defences?"
The case comes after another North Korean IT worker was caught attempting to hack their employer in July.
The IT worker was hired by the cyber company KnowBe4, which quickly disabled access to their systems when it noticed strange behaviour.

"We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person," the firm wrote in a blog post.
"We sent them their Mac workstation and the moment it was received, it immediately started to load malware (malicious software)."
Authorities are warning employers to be vigilant about new hires if they are fully remote.
Latest Stories
-
Underfunding and GH¢12bn arrears crippling education delivery – Ntim Fordjour
17 minutes -
I am not troubled; we didn’t cheat – Nyindam responds as Kpandai poll heads for re-run
19 minutes -
Investment in data production strengthens governance – Deputy Finance Minister
35 minutes -
High Court ruling on Kpandai will stand unless overturned by Supreme Court- Berekum West MP
40 minutes -
Ghana’s public debate too emotional, not driven by data – Prof Bokpin
45 minutes -
Arthur Kennedy writes on President Kufuor              Â
47 minutes -
Today’s Front pages: Tuesday, December 9, 2025
1 hour -
IMANI files RTI request seeking details on new nationwide SIM registration
1 hour -
Bawumia will perform better in 2026 NPP primaries, his popularity has actually risen – Nana Akomea
2 hours -
Ghana Education crisis deepens as WASSCE Results expose systemic gaps
2 hours -
NAIMOS ramps up Eastern Region clampdown, shuts major galamsey sites on Akyem Oda stretch
2 hours -
Prof. H. Kwasi Prempeh urges constitutional overhaul to fix OSP challenges
2 hours -
NYA CEO Osman Ayariga highlights need for skilled, disciplined Yango couriers at 2025 Conference
2 hours -
Ace Ankomah calls for merger of OSP, DPP, and EOCO to build a truly independent prosecution system
2 hours -
Mahama to receive final Bawku peace mediation report on December 11
2 hours
