Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

KnowBe4 says a person using a stolen U.S. identity passed its hiring process for a principal software engineer role, then tried to install password-stealing malware on the company-issued Mac workstation. Its endpoint detection and response (EDR) software alerted the security team, which isolated the laptop about 25 minutes after the first alert. KnowBe4 says no customer or confidential data was accessed or lost. The detailed account is the company’s own; the reviewed sources do not establish a public final FBI finding identifying the actor.

How the fake employee passed KnowBe4’s hiring process

KnowBe4 says it recruited a principal software engineer for its internal IT and AI team. The applicant presented the identity of a real U.S. person whose identity had been stolen. The company says the candidate passed references and standard background checks, and took part in four video interviews on separate occasions. KnowBe4 also says the application image was AI-enhanced from stock photography. KnowBe4’s account describes its own hiring and investigation; it does not establish a general failure rate for background checks or video interviews.

The distinction is important: verifying that records match a real person is not the same as proving that the applicant is that person. Video interviews can help assess a candidate, but KnowBe4’s account shows that interviews alone did not resolve the identity misrepresentation in this case.

What happened when the company laptop was turned on

KnowBe4 says the newly issued Mac workstation began showing suspicious activity on July 15, 2024, after it was received and powered on. The actor allegedly used a Raspberry Pi-based setup to download malware and access the machine, attempted to install password-stealing malware, and tried to manipulate session-history records. KnowBe4’s EDR software generated an alert for its security operations center (SOC).

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The company says the SOC contacted the new hire and received an explanation that the person was troubleshooting a router. The SOC then could not reach the person on an audio call. The alert arrived at 9:55 p.m. EST, and KnowBe4 says the laptop was isolated around 10:20 p.m. EST—about 25 minutes later. That is the reported timeline for this incident, not a general measure of detection or response performance.

KnowBe4 CEO Stu Sjouwerman wrote in the company’s July 23, 2024 account: “First of all: No illegal access was gained, and no data was lost, compromised, or exfiltrated on any KnowBe4 systems.” The company said the new hire had restricted access during onboarding and that no customer or confidential data was viewed, compromised, or exfiltrated. These are KnowBe4’s statements, not an independent public forensic finding. The company said disclosure was limited while the FBI investigation was active. TechTarget’s report also attributes details and comments to KnowBe4 executives.

What KnowBe4 meant by an “IT mule laptop farm”

KnowBe4 described a setup in which equipment is shipped to a local intermediary, who turns it on and configures remote access; the purported worker then connects to that device. The arrangement can make access logs appear to come from the expected country and machine. This description is attributed to KnowBe4 and its CISO in TechTarget’s reporting; it should not be treated as proof that every remote worker or applicant is suspicious.

KnowBe4 also said the workstation was shipped to an address different from the one represented in the application. An address discrepancy does not by itself prove wrongdoing, but it can be a useful reason to verify where company equipment will be received and operated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What each hiring and security control can—and cannot—address

Control Problem it addresses Practical implication
Identity assurance Whether the applicant is the person they claim to be Do not equate a valid identity record with proof that the person presenting it owns that identity.
References and background checks Whether work history and records can be corroborated Useful checks can still validate information tied to a stolen identity, as KnowBe4 says happened here.
Equipment shipping and location checks Where equipment is sent and where it may be operated Review unexpected shipping-address or location mismatches and verify them through an appropriate process.
Least-privilege onboarding What a new account can access Limit access while a new hire is onboarding and trust is being established. KnowBe4 says the employee had restricted access and no access to customer data during initial training.
EDR and SOC monitoring What suspicious activity is detected after device or account access Monitoring and an active response process can provide an alert and support containment; KnowBe4 credits its EDR alert and SOC response in this incident.

These measures address different parts of the risk. None, on its own, guarantees that an identity-fraud attempt will be stopped. KnowBe4’s account illustrates why organizations should combine identity checks, reference verification, equipment and location review, restricted initial access, and endpoint monitoring rather than treating one check as decisive.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A separate DPRK-linked campaign targeting developers

In a June 2026 article, Kudelski Security described a separate DPRK-linked “Contagious Interview” campaign. It said operators posed as recruiters on LinkedIn, WhatsApp, and Discord and tried to persuade job-seeking developers to run malicious code during fake interviews. Kudelski labels some evidence in its report low confidence. This is a different reported attack pattern; the available sources do not connect that campaign to the KnowBe4 hiring incident. Read Kudelski Security’s report.

Quick Recap

SaleBestseller No. 2
SaleBestseller No. 4
SaleBestseller No. 5
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Lightweight, Classic fit, Double-needle sleeve and bottom hem
$15.29
Best Value
Sale
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
  • This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
  • Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.