Cryptocurrency exchange Kraken reported on a thwarted infiltration attempt by a North Korean hacker who used a job application strategy.
How the Infiltration Attempt Began
The attacker applied for an engineering position at Kraken. Due to suspicious behavior, the security and IT teams were able to identify him as part of a state-supported operation.
Issues During the Interview Process
The candidate showed up to the first video interview under a different name and changed his name during the conversation. Recruiters also noticed voice changes, indicating potential real-time coaching.
Takeaways and Recommendations from Kraken
Further investigation revealed that the email address used was linked to a North Korean hacker network. Nick Percoco, Kraken's Director of Security, stated: 'Verify, don’t trust.' The team chose to continue the hiring process as a controlled intelligence operation to learn about the tactics used.
This incident highlights the threat of cyberattacks not only in the cryptocurrency space but in the hiring process, emphasizing the need for preparedness at all levels.