← Back to The Signal THREAT INTELLIGENCE

The threat was on the payroll.

Aug 6, 2026 · 6 min read

The most dangerous insider on your network didn't steal a credential or exploit a bug. They filled out the onboarding paperwork. They passed the video interview — with a real-time deepfake face on the call. They cleared the background check on a stolen identity, got shipped a company laptop, and started collecting a salary. And they work for a hostile nation-state.

This isn't a hypothetical. It's one of the largest active infiltration campaigns in the world, and if you employ remote engineers, there's a real chance you've already met one.

What the eleven nations just warned about

On July 31, 2026, the governments of eleven allied countries — the US, Japan, South Korea, and, for the first time, France, Germany, Italy, and the Netherlands — issued a coordinated alert: North Korean IT operatives are now using real-time AI deepfakes to impersonate real people during live job interviews. The scheme is enormous. Researchers estimate roughly 100,000 operatives generating on the order of $500–800 million a year funneled directly into Pyongyang's weapons programs. And the reach is staggering: analysis suggests nearly the entire Fortune 500 has interacted with — and in some cases inadvertently hired — DPRK IT workers.

The tradecraft is disciplined. Operatives sitting in North Korea, China, or Russia use stolen or fabricated identities, AI tools like Faceswap to paste their faces onto genuine-looking ID documents, and US-based "laptop farms" run by paid facilitators — so the worker appears to your systems as a domestic employee at a home-office IP, while the human is in Pyongyang. The company ships the laptop, pays the salary, and never meets the worker. Once inside, the objectives are data exfiltration, source-code and IP theft, cryptocurrency theft, and a quiet foothold in your environment.

Every perimeter control asks the same question: are you authorized? For a hired employee, the answer is always yes. The identity is real. The access is granted. The threat is the human behind it — and none of your access controls are looking at the human.

Why this defeats almost everything

Think about what a fake employee bypasses. There's no exploit, so there's nothing for your EDR to flag. There's no stolen credential, because the credential was issued to them on their first day. There's no failed login, no malware on the endpoint, no phishing email — at least not at first. They badge in through the front door your HR team opened. Every tool built to catch an intruder is looking for a break-in that never happens.

MFA doesn't help — they have the second factor; it's their phone. Zero-trust doesn't help — they're a verified, enrolled identity. The background check didn't help — it validated a stolen name. This is the blind spot at the center of identity-first security: we've gotten very good at verifying that a login is authorized, and almost no good at asking whether the authorized person is who and what they claim to be.

The tell is in the behavior, not the credentials

The evidence that something is wrong does exist — it's just behavioral, quiet, and scattered. The laptop reports a US home office, but the session behaves like it's being driven through a proxy from the other side of the world. Work happens at hours that don't match the stated time zone. A "front-end developer" starts pulling entire source repositories, reaching into secrets managers, and touching customer data that has nothing to do with their tickets. Access patterns drift toward staging and exfiltration. Data leaves in volumes a normal contributor never moves.

Individually, every one of those is explainable — a developer working late, pulling a big repo, using a VPN. None of them, alone, is worth an escalation. The insider threat lives only in the combination: this identity, doing these things, from these places, at these times, in a pattern that quietly contradicts who they're supposed to be. And that correlation — across identity, access, and data movement, over days — is exactly what a human SOC buried in legitimate activity cannot assemble in time.

Watch what the trusted identity actually does

This is the case for judging identities by behavior, at machine speed. n0limit treats every action a user takes as something to investigate against what's actually true about that person — not something to trust because they're an enrolled, authorized employee. When a valid identity behaves in ways that contradict its own established baseline — impossible geography behind the stated location, access reaching far outside its role, data movement that doesn't fit the work — those signals are enriched, correlated across the whole estate, and resolved to a verdict in under 500 microseconds, with a reasoning trail an operator can audit.

The nation-state on your payroll has defeated your hiring process, your perimeter, your MFA, and your background check — all by being granted legitimate access. The only thing left that can catch them is the layer that never assumed "authorized" meant "safe": the one watching what the trusted identity actually does, correlating the quiet contradictions, and reaching a verdict fast enough to act before the source code and the secrets are gone. When the adversary is a verified employee, "they're authorized" and "they're a threat" are no longer mutually exclusive — and only one of those facts shows up in your access logs.

Related from The Signal

THREAT INTELLIGENCE You patched SharePoint. They're still inside. THREAT INTELLIGENCE Cl0p doesn't encrypt anymore. It just takes. THREAT INTELLIGENCE Weekly threat briefing: April 13–20, 2026

Authorized isn't the same as safe.

n0limit judges every identity by what it actually does — correlating behavioral contradictions to a verdict in under 500 microseconds, so a hostile insider is caught by their actions, not their access badge.

Book a demo →