KnowBe4 AI media incident — Oct 2026
A North Korean hacker used AI-generated visuals and a stolen identity to infiltrate KnowBe4 as a software engineer, attempting to deploy malware.
- Reported date
- Oct 6, 2026
- Target
- KnowBe4
The exact incident date was not established. This entry is dated by its source report.
In a high-profile security incident, a North Korean hacker successfully bypassed hiring protocols at KnowBe4 by posing as a U.S.-based software engineer. The attacker utilized a stolen identity, including a misappropriated Social Security number and an AI-doctored photograph, to secure a remote position at the cybersecurity firm. This incident highlights the growing threat of organized actors using sophisticated digital deception to gain unauthorized access to corporate networks.
What happened
The perpetrator leveraged advanced AI-generated visuals to pass multiple rounds of video interviews and background checks. By masking their true appearance and location, the individual successfully convinced the company of their legitimacy. However, the deception was short-lived; shortly after being hired, the "employee" began attempting to inject malware into the company's internal systems. KnowBe4’s security team identified the suspicious activity, leading to an investigation that traced the actor back to a North Korean hacking operation. The attacker had utilized an "IT mule" address to receive company hardware and accessed the network via VPN, mimicking U.S. working hours to avoid detection. This case serves as a critical warning that even security-focused organizations are vulnerable to deepfake-enabled infiltration, prompting broader industry concerns regarding the use of remote hiring as a vector for nation-state espionage.