Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

KnowBe4 AI media incident — Oct 2026

A North Korean hacker used AI-generated visuals and a stolen identity to infiltrate KnowBe4 as a software engineer, attempting to deploy malware.

Reported date
Oct 6, 2026
Target
KnowBe4

The exact incident date was not established. This entry is dated by its source report.

Updated Oct 7, 2026 · 1 min read

In a high-profile security incident, a North Korean hacker successfully bypassed hiring protocols at KnowBe4 by posing as a U.S.-based software engineer. The attacker utilized a stolen identity, including a misappropriated Social Security number and an AI-doctored photograph, to secure a remote position at the cybersecurity firm. This incident highlights the growing threat of organized actors using sophisticated digital deception to gain unauthorized access to corporate networks.

What happened

The perpetrator leveraged advanced AI-generated visuals to pass multiple rounds of video interviews and background checks. By masking their true appearance and location, the individual successfully convinced the company of their legitimacy. However, the deception was short-lived; shortly after being hired, the "employee" began attempting to inject malware into the company's internal systems. KnowBe4’s security team identified the suspicious activity, leading to an investigation that traced the actor back to a North Korean hacking operation. The attacker had utilized an "IT mule" address to receive company hardware and accessed the network via VPN, mimicking U.S. working hours to avoid detection. This case serves as a critical warning that even security-focused organizations are vulnerable to deepfake-enabled infiltration, prompting broader industry concerns regarding the use of remote hiring as a vector for nation-state espionage.

Sources