Kraken Uncovers North Korean Hacker Posing As Job Applicant
Kraken, a prominent crypto exchange platform, has reportedly uncovered a North Korean hacker who attempted to secure a job at the firm under a false identity. The individual, posing as "Steven Smith," was suspected of trying to infiltrate the company to steal money and sensitive information. Nick Percoco, the chief security officer at Kraken, revealed that the person was on a "Do Not Hire" list and was believed to be working for North Korea's Kim Jong Un. Instead of immediately dismissing the application, Percoco chose to engage with the individual to gather more information.
Ask Aime: "Could this North Korean hacker's attempted job at Kraken have been a distraction for them while pulling off a major crypto heist?"
Percoco explained that the hacker's objective was to gain employment, steal intellectual property, and siphon funds from the company. During an interview with Kraken, the individual was asked to present his identification. After a brief delay, he provided a screenshot of a driver’s license bearing the name "Stephen Smith" with an address 300 miles away from Houston, where he claimed to reside. This raised further suspicions about his true identity.
According to a recent report, "Steven Smith" claimed to have a bachelor’s degree in computer science from New York University and over a decade of experience working as a software engineer at prominent US firms such as cisco and Kindly Human. This elaborate backstory was likely crafted to enhance his credibility and increase the chances of being hired. The United Nations has estimated that North Korea generates between $250 million and $600 million annually through such deceptive tactics, hiring spies to infiltrate foreign companies and steal valuable information.
Kraken's decision to confront the hacker rather than dismissing his application outright highlights the company's proactive approach to security. By engaging with the individual, Kraken was able to gather more information about the hacker's methods and intentions, which can be used to strengthen the company's defenses against future attacks. This incident underscores the ongoing threat posed by state-sponsored hackers and the importance of vigilance in the crypto industry. Companies must remain vigilant and implement robust security measures to protect against such sophisticated attempts at infiltration.
