For many security teams, the expected route into the corporate network begins with a phishing email or exploited vulnerability. Certain techniques differ, exploiting the hiring process to gain legitimate access.
In July, the US Department of State released an alert warning of North Korean IT workers impersonating nationals of other countries for the purpose of obtaining work. Once employed, those workers then send their salaries back to parent agencies in North Korea.
The FBI has also warned that fraudulent workers may use their access to copy source-code repositories, exfiltrate proprietary information and support other cybercriminal activity. After being discovered or dismissed, some have attempted to extort their employers by threatening to publish stolen code and data.
These operations expose a gap between checking an identity and proving who is using an account. For instance, a résumé may appear credible, and a laptop may arrive at a domestic address. But, neither of those controls, on its own, proves that the person interviewed is the person who receives the device, or the person who ultimately signs in.
The challenge for service desk agents is how they can confirm the person requesting access is both real and a legitimate new hire.









