On Demand Webinar

North Korean Hires and
Help Desk Impersonators

A CISO’s Guide to Identity Impersonation Defense

Watch on Demand

The tools to find impersonators – and the power to shut them down at first contact

Impersonation detection & prevention

Detect and prevent impersonation and social engineering attacks on every communications channel.

Digital forensic metric analysis

Advanced analysis takes it one step further. Looking beyond standard metrics to the forensic network, device and digital identity markers – cross-referenced with unique organizational knowledge that hackers would never know. 

Not just detecting and verifying user identities. Scanning every interaction for suspicious activity.

Real-time alerts and support

You need to know you’re talking to a hacker – before they get into your systems. 
imper.ai scans every communication as it happens and alerts you as soon as it spots a scammer.

Let imper.ai shut it down

End the conversation in one click, with help from imper.ai.

Take control

Choose to keep talking or shut the conversation down manually or automatically with imper.ai

Voice phishing is now the #1 initial infection vector for cloud compromises, per Mandiant M-Trends 2026. The reason it works is that it doesn’t touch the login. Scattered Spider calls the help desk and walks out with a password reset. DPRK IT workers operate from attacker-controlled infrastructure during live interviews and land roles inside Fortune 500 engineering teams. In both cases, no authentication control was bypassed because no authentication control was in the path.

Hear from Sean Sosnowski (SACR Research), Fred Hamilton (CISO, BHG Inc.), and Noam Awadish (CEO, imper.ai) on:

  • what’s actually working against these attacks
  • where verification is breaking down across Security, IT, HR, and Talent Acquisition
  • and what the controls being built for this layer look like in practice.
  • A practitioner’s view from Fred Hamilton on defending the help desk and the hiring pipeline inside a real security program
  • Sean Sosnowski’s framing of Social Engineering Identity Defense (SEID), the workflow-layer category SACR is tracking as authentication continues to push attackers toward recovery and onboarding paths
  • A specific look at why document-and-selfie verification missed the four DPRK-affiliated candidates imper.ai detected across 600 remote interviews in Q1 2026, and what infrastructure-layer detection surfaces during a live session

This discussion was crafted for CISOs, IAM and IT leaders, and security architects defining how workforce identity verification fits into their stack.

Watch on Demand