The recent attacks on companies, such as the well-known case of “Jordan,” have highlighted a significant shift in the infiltration tactics of cybercriminals. It is no longer just about traditional risks like phishing; direct infiltrations during hiring processes represent a growing threat. A recent report revealed more than 320 cases of North Korean operatives posing as remote IT workers, using false identities and advanced technologies like deepfakes.
May the fight against online crime continue!
The adoption of remote work has eliminated many of the natural protections of in-person interviews, thus increasing the vulnerability of organizations to sophisticated threats. According to experts, identity has become the new security perimeter. This means that identity verification now requires a much more rigorous approach, as criminals can forge references and use artificial intelligence techniques to impersonate identities.
The case of “Jordan” illustrates this issue, where an adversary managed to access sensitive resources of a company after being warmly welcomed as if they were a new employee. Instead of following more recognizable attack paths like phishing, infiltration through hiring procedures is more effective and, at the same time, harder to detect.

Organizations are beginning to adopt the approach of “never trust, always verify”, which involves validating every access request, even from existing employees. Additionally, the concept of “zero standing privileges” (ZSP) is being implemented, which promotes that employees only have access to what they really need and only temporarily. This not only ensures that adversaries like “Jordan” do not maintain prolonged access to critical resources, but also seeks to balance security with productivity.