It’s not the resume padding or the AI-generated cover letters that worry me most. It’s that the person you think you’ve hired might not be a person at all. Or at least not the one showing up on Zoom. The WIRED piece on North Korean operatives infiltrating western companies through remote IT jobs describes a scenario that is not fringe nor rare. Corporate recruiters are operating in a cyber-espionage environment on a daily basis. Deception is now coordinated, scalable, and state-sponsored. And thanks to generative AI, even interview performance can be faked convincingly. The immediate implication I can see is that vetting isn’t just an HR function anymore; it’s a cybersecurity imperative. A software engineer with deep system access may now pose a much bigger enterprise threat than a rogue finance exec. Companies need to review their assumptions about remote work (opportunity vs risk). They also need to revisit their application assessment approach, interview process, device distribution policies, and background checks. Not just the what but the how. #TalentAcquisition #TalentSecurity #RemoteHiringRisks #CyberThreatsInHiring #HRRisk https://lnkd.in/extiZZ5U
Cybersecurity in HR
Explore top LinkedIn content from expert professionals.
Summary
Cybersecurity in HR refers to protecting the hiring and employee management processes from cyber threats, such as identity fraud and malware, that target human resources operations. As recruiting and onboarding shift online and remote, attackers are exploiting these processes with fake identities, malicious attachments, and deepfakes to gain access to sensitive company information.
- Strengthen identity checks: Always verify candidate identities using live interviews, secure platforms, and by cross-checking resumes for inconsistencies.
- Secure hiring workflows: Open resumes or attachments in isolated environments and limit access for recruiters to only what is necessary until candidates are fully vetted.
- Educate HR teams: Regularly train HR and recruitment staff to spot signs of cyber fraud, such as suspicious profiles or unusual interview behavior, and encourage collaboration with cybersecurity teams.
-
-
Cybersecurity is not just a technical issue, it’s also an economics and people issue. On the latter, the latest research from our Counter Threat Unit (CTU), now part of Sophos from our Secureworks acquisition, further reinforces that position. CTU has been tracking the North Korean IT workers scheme - which has been in operation since at least 2018 - as NICKEL TAPESTRY. Recent findings show this campaign has expanded beyond U.S. tech firms into Europe, Asia, and industries including finance, healthcare, and cybersecurity. These actors are applying for remote roles using AI-generated resumes, falsified identities, and cloned online profiles. Their goals range from salary diversion to data theft and extortion. In 2025, CTU observed a shift toward targeting cybersecurity roles and using more diverse personas. Given the level of trust and access that cybersecurity companies generally have, this becomes a large-scale keys-to-the-kingdom problem. This is not just a cybersecurity concern, it’s a general hiring hygiene concern. HR and recruitment teams are now enlisted in the front lines of organizational risk controls. Our nutshell recommendations: - Enhanced identity verification during interviews - Live or video validation of candidates - Monitoring for cloned resumes and VoIP-linked contact info - Control of remote access tools and BYOD usage post-hire This is a persistent, evolving threat. Organizations must adapt hiring and onboarding practices accordingly. Our full report: https://lnkd.in/gcruvt67
-
🧠 𝗗𝗲𝗲𝗽𝗳𝗮𝗸𝗲 𝗛𝗶𝗿𝗶𝗻𝗴: 𝗧𝗵𝗲 𝗡𝗲𝘄 𝗖𝘆𝗯𝗲𝗿 𝗘𝗻𝘁𝗿𝘆 𝗣𝗼𝗶𝗻𝘁 Cyberattacks are no longer just ransomware and malware. A new threat is targeting companies from inside by infiltrating job interviews using AI-generated identities. 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀 𝗮𝗿𝗲 𝗻𝗼𝘄 𝘂𝘀𝗶𝗻𝗴: • AI voice cloning • Deepfake video filters • Stolen resumes from real engineers • Fabricated stories that are hard to verify 𝗧𝗵𝗲 𝗴𝗼𝗮𝗹? Access internal systems, steal source code, credentials, sensitive data, or conduct silent long-term espionage. 🚩 𝗥𝗲𝗱 𝗙𝗹𝗮𝗴𝘀 𝗗𝘂𝗿𝗶𝗻𝗴 𝗜𝗻𝘁𝗲𝗿𝘃𝗶𝗲𝘄𝘀: • Lip movement not matching the voice • Unnatural or overly static camera feed • Scripted answers with no real depth • Inability to explain basics of their own experience • Continuous “technical issues” or camera refusal • Suspicious LinkedIn history or inconsistent timeline 🛡️ 𝗛𝗼𝘄 𝘁𝗼 𝗣𝗿𝗼𝘁𝗲𝗰𝘁 𝗬𝗼𝘂𝗿 𝗛𝗶𝗿𝗶𝗻𝗴 𝗣𝗿𝗼𝗰𝗲𝘀𝘀: • Use multi-stage interviews (technical + live challenges) • Verify identity through validated platforms and email domains • Avoid predictable questions use real-time problem solving • Analyze CV metadata and external footprint • Use AI anomaly-detection tools for audio/video manipulation • Apply Zero Trust for onboarding and initial access • Educate HR + Tech teams about AI-powered fraud - #CyberSecurity #Deepfake #Hiring #AIThreats #ZeroTrust #ThreatAwareness #SocialEngineering #InfoSec #CyberAwareness #HRTech #Cybercrime #DeXpose #DarkWeb #ThreatIntel
-
If your business hires people, your hiring process is part of your attack surface. The hiring process is built on trust, urgency, attachments, links, and conversations with strangers. That makes it attractive to attackers. It’s already being exploited. Recent incidents: ↪ Résumés with malicious ISO attachments are circulating. ↪ Fake candidates send links that install malware. ↪ North Korean APTs run IT worker scams. HR teams handle files from unknown people and click links to portfolios every day. That's the job. It's also the risk. Safer hiring workflows can reduce exposure: ➔ Open résumés in isolated environments. ➔ Use least-privilege access for recruiters. ➔ Verify candidate identity before any access. ➔ Educate teams on common attack methods. Hiring workflows deserve the same security attention as finance and IT admin access. Worth reading: ➢ CSO Online: "Resumes with Malicious ISO Attachments": https://lnkd.in/gVju8BuT ➢ Help Net Security: "HR Recruiters Targeted with Malware": https://lnkd.in/gkWpcGBg ➢ Dark Reading: "North Korean APTs Use AI in IT Worker Scams": https://lnkd.in/gn-AP6X4 #Cybersecurity #HRSecurity #RecruitingSecurity #PhishingAttacks #CyberRisk
-
Most people still think the CHRO and the CISO sit on opposite sides of the business. One focused on people. One focused on technology. That view is outdated. In reality, some of the most important security and resilience initiatives today sit right at the intersection of HR and cybersecurity. Because modern cyber risk is no longer just about firewalls, malware, or vulnerabilities. It’s about people, trust, access, culture, and behavior. And that’s exactly where the CHRO and CISO need to work together. Think about the issues both leaders touch every day: → Insider risk → Employee onboarding and offboarding → Privileged access → Security awareness → Background screening → Investigations → Crisis response → Remote work policies → Workforce resilience → Culture and trust They are shared business risks. One example is onboarding and offboarding. Security cares about: ✓ account creation ✓ least privilege ✓ MFA ✓ device control ✓ access removal HR cares about: ✓ role changes ✓ employee transitions ✓ termination timing ✓ policy acknowledgement ✓ workforce coordination If those processes are not aligned, risk grows fast. Access remains open. Accounts are missed. Sensitive data follows the wrong person. And gaps appear during the exact moments organizations are most exposed. Then there’s culture. This is one of the most overlooked intersections between CHROs and CISOs. Security awareness programs fail when they feel like compliance theater. They work much better when security is embedded into culture, communication, leadership behavior, and employee experience. That requires HR partnership. Because cyber resilience is not only built through tools. It’s built through people knowing: → what matters → what’s expected → how to escalate concerns → how to work safely → how to trust the system around them This is where the CHRO-CISO relationship becomes strategic. The strongest organizations are aligning these leaders across initiatives like: ✓ Insider threat programs ✓ Joiner / mover / leaver controls ✓ Workforce cyber awareness ✓ Executive crisis response planning ✓ Remote and hybrid work governance ✓ Employee privacy and monitoring decisions ✓ Third-party workforce risk ✓ Culture and resilience programs The big shift is this: Cybersecurity is no longer just a technology conversation. It’s a workforce conversation too. And HR is no longer adjacent to cyber risk. It is directly connected to it. The organizations that understand this early are the ones building stronger resilience, better trust, and fewer blind spots between people risk and cyber risk. Where do you think CHROs and CISOs need to collaborate more today: insider risk, culture, or workforce resilience? #CyberSecurity #CHRO #CISO #Leadership #InsiderThreat #RiskManagement #CyberResilience #HumanResources #SecurityCulture #WorkforceStrategy
-
This article highlights a St. Louis federal court indicted 14 North Korean nationals for allegedly using false identities to secure remote IT jobs at U.S. companies and nonprofits. Working through DPRK-controlled firms in China and Russia, the suspects are accused of violating U.S. sanctions and committing crimes such as wire fraud, money laundering, and identity theft. Their actions involved masking their true nationalities and locations to gain unauthorized access and financial benefits. To prevent similar schemes from affecting you businesses, we recommend a multi-layered approach to security, recruitment, and compliance practices. Below are key measures: 1. Enhanced Recruitment and Background Verification - Identity Verification: Implement strict verification procedures, including checking legal identification and performing background and reference checks. Geolocation Monitoring: Use tools to verify candidates’ actual geographic locations. Require in-person interviews for critical roles. - Portfolio Validation: Request verifiable references and cross-check submitted credentials or work samples with previous employers. - Deepfake Detection Tools: Analyze video interviews for signs of deepfake manipulation, such as unnatural facial movements, mismatched audio-visual syncing, or artifacts in the video. - Vendor Assessments: Conduct due diligence on contractors, especially in IT services, to ensure they comply with sanctions and security requirements. 2. Cybersecurity and Fraud Prevention - Access Control: Limit access to sensitive data and systems based on job roles and implement zero-trust security principles. - Network Monitoring: Monitor for suspicious activity, such as access from IPs associated with VPNs or high-risk countries. - Two-Factor Authentication (2FA): Enforce 2FA for all employee accounts to secure logins and prevent unauthorized access. - Device Management: Require company-issued devices with endpoint protection for remote work to prevent external control. - AI and Behavioral Analytics: Monitor employee behavior for anomalies such as unusual working hours, repeated access to restricted data, or large data downloads. 3. Employee Training and Incident Response - Cybersecurity Awareness: Regularly train employees on recognizing phishing, social engineering, and fraud attempts, using simulations to enhance awareness of emerging threats like deepfakes. - Incident Management and Reporting: Develop a clear plan to handle cybersecurity or fraud incidents, including internal investigations and containment protocols. - Cross-Functional Drills and Communication: Conduct company-wide simulations to test response plans and promote a culture of security through leadership-driven initiatives. #Cybersecurity #HumanResources #Deepfake #Recruiting #InsiderThreats
-
Nation-states don’t exploit weak security. They exploit workplace dynamics. I know, because this is exactly how I recruited insiders. Espionage doesn’t start with secrets. It starts with validation. A compliment at the right moment. A shared frustration. Someone who listens when your company doesn’t. That’s not spycraft. That’s just a Tuesday at work. I never asked for sensitive information up front. I asked what was broken. Who made their job harder than it needed to be. What they would fix if anyone actually listened. They thought they were venting. I was mapping access, influence, and motivation. That’s called elicitation. Companies like to believe insider threats come from “bad actors.” They don’t. They come from good employees in very human moments: burnout, loyalty conflict, money stress, bruised ego, identity cracks, resentment that’s been quietly fermenting. And yes, your highest performers were always my favorite targets. They were trusted. They were visible. They had access. And they cared enough to talk. Remote work didn’t invent this. It removed friction. You trained people to network. We trained people to recruit. Same skills. Different intent. If your organization still treats espionage as a cyber problem or a personality flaw, you’re already behind. Because the easiest way into your organization was never through the firewall. It was through someone who finally felt understood. #InsiderThreat #HumanRisk #Espionage #TrustIsASystem #Cybersecurity #Leadership #HR *Photo of me back in the day, post deployment*
-
A resume just stole your company's passwords in 25 seconds. Not a fake candidate. Not a deepfake interview. The actual resume file. A campaign called FAUX#ELEVATE is targeting corporate HR departments with malware disguised as job applications. The resume looks normal. Professional formatting. Clean PDF name. When your recruiter opens it, a fake error message pops up. "File corrupted. Please try again." They close the window. Move on to the next applicant. Meanwhile the malware is already running. Here's what happens in the next 25 seconds: → Steals every saved password from Chrome and Firefox → Extracts browser cookies and session tokens → Copies files from the recruiter's desktop → Exfiltrates everything through a Russian email server → Installs a cryptocurrency miner on the company laptop → Deletes all evidence of itself Twenty-five seconds. Your recruiter didn't click a suspicious link. Didn't visit a shady website. Didn't ignore a security warning. They opened a resume. The one thing they do hundreds of times a week. Securonix researchers called this a "well-organized, multi-stage attack operation." The attackers used Dropbox to stage payloads. Compromised WordPress sites for command servers. Legitimate email infrastructure for data theft. Every tool was borrowed. Nothing looked malicious. We train employees to spot phishing emails. Nobody trains recruiters to treat resumes as potential weapons. Your ATS inbox is an attack surface. And right now, the next malicious resume is sitting in someone's queue. Waiting to be opened. #Cybersecurity #Recruiting #InfoSec #ThreatIntelligence #HRTech #CyberRecruitment #TechHiring #PhishingAttack
-
𝗦𝘁𝗿𝗲𝗻𝗴𝘁𝗵𝗲𝗻 𝗬𝗼𝘂𝗿 𝗛𝘂𝗺𝗮𝗻 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹: 𝗥𝗲𝗶𝗻𝗳𝗼𝗿𝗰𝗲 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗧𝗵𝗿𝗼𝘂𝗴𝗵 𝗥𝗲𝗰𝗼𝗴𝗻𝗶𝘁𝗶𝗼𝗻, 𝗡𝗼𝘁 𝗥𝗲𝗺𝗶𝗻𝗱𝗲𝗿𝘀 Cybersecurity often feels like a list of “don’ts.” Don’t click. Don’t trust. Don’t forget. But fear-based compliance doesn’t build resilient teams—empowered behaviour does. If you want security habits to stick, celebrate them. When someone reports a phishing email, acknowledge it. When a team handles sensitive data securely during a tight deadline, highlight it. Positive reinforcement turns good security hygiene into everyday behavior, not just policy. An organization launched a simple “Security Spotlight” program, shouting out small wins, like avoiding a phishing scam or flagging a spoofed vendor invoice. It took minutes per week. Engagement skyrocketed. Security went from being “IT’s problem” to a shared team success. Here’s the shift: embed cybersecurity into the employee experience. Tie it into your EX programs, onboarding, and team rituals. Make it personal, relevant, and appreciated. Because when people feel seen and supported, they don’t just follow rules, they own them. Want to turn secure habits into part of your culture, not just your compliance checklist? Let’s talk about reinforcing the right behaviors with the right mindset with Digital Transformation Strategist.