The FBI is investigating how an unidentified federal agency was recently swept up in a yearslong campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations. The North Korean campaign has been notorious for using remote IT contract jobs to infiltrate both Fortune 500 companies and smaller private sector firms. But experts contacted for this story said it’s not surprising the public sector has been implicated as well. They said the incident highlights a new kind of insider threat, as well as potential gaps in the government and industry vetting processes, especially for jobs like IT support work. During a panel discussion at a July 28 conference hosted by the Digital Government Institute in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, was asked whether the North Korean remote IT worker issue had impacted government. “Without getting into ongoing investigations, we identified just this past week a [Democratic People’s Republic of Korea] remote IT worker that was working for the federal government,” Hemmen said. “Still kind of unpacking that recent case. It’s actually a little bit baffling to me, not understanding this particular agency’s process. But the short answer is yes, we are seeing remote IT workers not just in the private sector – although a vastly higher proportion in the private sector – but we’re also seeing this impact the government to a degree.” The FBI declined to comment further on the story. It’s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. It’s highly likely Hemmen was referring to a remote IT employee doing contract work on behalf of an agency, experts confirmed, given extensive background investigation and identity proofing requirements needed to get a federal job. Such a
FBI investigating North Korean remote IT staffer working for US agency
Read the original article
federalnewsnetwork.com →