Incident response guide
What to Do If You Suspect a North Korean IT Worker
Treat a suspected DPRK IT worker as a potential security incident, not only an HR issue. Preserve evidence, understand the worker’s access, coordinate the right teams and make risk-based decisions before taking actions that could destroy evidence or alert the operator.
Your exact response depends on risk, legal advice and active access. A sudden employment or account action can destroy evidence or cause an operator to change behavior. Coordinate security, legal and HR first when circumstances allow.
First response steps
The sequence should be adapted to the worker’s level of access and your incident-response process.
Escalate as a security incident
Bring in security operations or incident response, insider risk, legal and HR. Add identity, IT, Help Desk and finance as needed.
Preserve evidence
Retain relevant endpoint, network, identity, interview, onboarding, shipping, payment and support records. Document what you know and when you learned it.
Map the worker’s access
Identify accounts, devices, repositories, cloud services, credentials, privileged access, code stores and other systems the worker could reach.
Investigate device and network activity
Look for remote-access software, VPNs, proxies, foreign or impossible-travel sign-ins, data movement, personal cloud storage and persistence.
Contain based on risk
Reset credentials, revoke sessions, isolate devices or remove access when the investigation and risk level justify it. Coordinate timing so evidence is preserved.
Report and expand the investigation
For U.S. organizations, report suspected DPRK IT worker activity to the FBI / IC3. Review related candidates, addresses, staffing vendors, accounts and infrastructure for connected activity.
Evidence to preserve
The objective is to preserve the facts needed to understand who operated the account, from where, and what they could access.
Endpoint
Disk and memory evidence where appropriate, installed RMM tools, browser history, persistence, local accounts and recent file activity.
Identity & access
Sign-in logs, MFA events, session tokens, account recovery, privilege changes, SaaS and cloud access.
Network
Source IPs, VPN / proxy activity, remote connections, DNS, egress, impossible travel and unusual data transfer.
Hiring & HR
Applications, resumes, interview recordings, identity documents, background checks, references and staffing-vendor records.
Logistics
Laptop shipping address, reshipment requests, device serials, enrollment history and support tickets.
Payments
Bank-account changes, matching payment details, payroll destination, virtual-currency requests and vendor invoices.
Who should be in the room?
Reporting suspected activity
The FBI recommends that U.S. organizations report suspected North Korean IT worker activity to the Internet Crime Complaint Center and evaluate network activity from the suspected worker and assigned devices.
IC3 also maintains a victim-information process for organizations already identified by the FBI as potential victims of the North Korean Remote IT Worker scheme.
FBI victim information form →After containment: look for the wider pattern
Search applicant and employee records for reused resumes, phone numbers, emails, references and identity details.
Look for common shipping addresses, device destinations, facilitators or staffing vendors.
Hunt for the same VPNs, proxies, IPs, RMM software, remote-access methods and payment patterns elsewhere.
Incident response FAQ
Should we immediately fire the suspected employee?
Not automatically. Employment decisions should be coordinated with legal and HR, while security considers evidence preservation, active access and containment risk. The right sequence depends on the circumstances.
Should we immediately wipe or collect the laptop?
A wipe can destroy useful evidence. Incident response should decide whether to isolate, image, monitor or collect the device based on the investigation and legal guidance.
What should we review first?
Start with the worker’s accounts, assigned devices, sign-in activity, remote-access tools, network origin, source-code and cloud access, plus hiring, shipping and payment records.
Do we need to report to the FBI?
The FBI recommends reporting suspected North Korean IT worker activity to IC3 or a local FBI field office. Organizations outside the United States should follow the relevant national reporting guidance.
Should we investigate other employees and candidates?
Yes, when evidence suggests shared personas, addresses, infrastructure, staffing vendors, payment details or other common indicators. These operations can involve multiple identities and facilitators.
Reduce the chance the investigation starts after access is granted
imper.ai analyzes device, network, virtualization, remote-control and behavioral signals during hiring, onboarding and other high-risk workforce interactions.
