AI unmasked a North Korean spy inside Exabeam's network
A cybersecurity firm's hiring process let in a foreign operative, caught only by behavioral detection afterward
A new hire cleared every stage of a rigorous screening process, including a background check and a government identity form. Within a day, the same employee was being treated as a national security threat.
The candidate had leaned on generative AI tools to get through technical and video interviews before landing an offer at a major cybersecurity vendor. He backed the deception with a doctored driver’s license, forged references and faked employment paperwork that cleared third-party verification.
Security staff had flagged some inconsistencies during the hiring process and were watching the new hire closely.
In the summer of 2025, within 24 hours of his first login, automated behavior analysis flagged a cluster of activity that did not fit the profile of a typical first-day employee.
“He submitted a series of fraudulent documents, including a doctored driver’s license where the image was either a deepfake or heavily altered,” Steve Povolny, vice president of AI strategy and security research at Exabeam, told TechJournal.uk in an interview in London.
“He provided false references and faked his I-9 forms, and was validated through our third-party background check,” Povolny said.
Form I-9 is a federal document required for every new hire in the United States, used to verify an employee's identity and confirm they are legally authorized to work in the country, typically cross-checked against government-issued identification such as a driver's license or passport.
“He installed a number of malicious executables and connected to a command-and-control server. He installed Jump Desktop [remote-access] software and VPN [virtual private network] software, and was trying to get approval to ship his laptop to Austin, Texas,” Povolny said.
He said the laptop was probably headed to a laptop farm to give North Korea a way back in.
“We were able to shut down all the activity, reimage his laptop and avoid any kind of breach within about four to six hours,” he said.
“This is not a traditional insider threat, where you have a disgruntled employee who is already inside,” said Findlay Whitelaw, field chief information security officer at Exabeam. “The intent is there for an external threat actor to get in through a legitimate business process, through the hiring process itself.”
“There were some red flags during the interviewing process, but nothing specific enough to flag him as a threat,” Povolny said. “We hear a resounding affirmation from other companies that this is happening all over the place.”
“They are hiring nation-state actors accidentally and finding out after the fact, sometimes not within hours but within days, weeks or months,” he said.
Povolny and Whitelaw were in London for Infosecurity Europe 2026 to present the case to a room of security professionals.
Exabeam, a California-based cybersecurity company known for its threat-detection software, chose to make the account public, arguing that other organizations are quietly living through the same experience.
Behavior beats background checks
Povolny and Whitelaw spoke to TechJournal.uk’s Jeff Pao at Infosecurity Europe 2026, organized by Reed Exhibitions, in London. They delivered a conference session dissecting the case for an audience of security practitioners.
“When you try to rely on static detection and rules to fire on malicious behaviors, that can get you so far, but in this case it probably would never have detected him,” Povolny said.
“He was doing things that looked normal: installing software, side-loading DLLs [dynamic-link libraries], installing VPN software,” he said. “Those things might be anomalous for a new user, but they weren’t smoking guns.”
“We caught this with a combination of our UEBA [user and entity behavior analytics] detections, which profiled the anomalous behavior and identified that this user was doing things way outside a normal baseline,” he said. “Our AI, Exabeam Nova, stitched all of those events together and prioritized it as an investigation.”
A human analyst then reviewed the flagged investigation, confirmed the detections and isolated and reimaged the laptop within hours. Exabeam has offered behavior-analytics capability for more than 15 years.
“Our tool detected what we said it would detect,” Whitelaw said. “If we did not have that ability, this could have gone low and slow, because the incidents would have stayed in isolation,” she said.
“We’re not asking you to be forensically dissecting everything, but you need to tick all the boxes and back that up with compensating controls,” she said. “That’s where user and entity behavior analytics comes in, because once someone is in and looks legitimate, they’ve got the keys to the kingdom.”
Whitelaw said a new employee would typically be completing mandatory training, setting up email or working through the files needed for the job, but what this actor did was completely different.
“It’s much like having a software-based vulnerability, where you have a backdoor into the network,” Povolny said. “Intellectual property, code bases, internal sensitive documents and credentials become much easier to steal once you are on the inside, and lateral movement into privileged systems becomes possible.”
A widening nation-state problem
“We see a lot of threat groups associated with North Korea. This one was tied to a threat actor group called Famous Chollima,” Povolny said. “They are well-funded and nation-state driven, and this one was being tracked specifically by the FBI and associated with North Korea to the best of our intelligence.”
Similar schemes have also been traced to China, Iran and Russia.
The US Treasury Department estimates thousands of North Korean IT workers hold jobs at American companies, including Fortune 500 firms, funneling salaries back to Pyongyang’s weapons programs. CrowdStrike researchers say Famous Chollima infiltrated more than 320 companies in 2025, a 220% year-over-year increase, driven partly by heavier use of generative AI during hiring.
In June 2025, the US Department of Justice announced coordinated action across 16 states. Officials seized about 200 computers and charged operatives who had gained jobs at more than 100 US companies using stolen identities. The FBI has separately warned that North Korean IT workers have extorted employers by holding stolen data and proprietary code hostage.
“We understand this could damage our reputation, but we are under no illusion that we are immune,” Whitelaw said. “No one is immune, bigger companies or smaller ones. Our ethos is to share this and learn from it, and quite frankly, to drink our own Kool-Aid, because our detection tools picked it up.”
“We gave a version of this talk at RSA Conference this year,” Povolny said. “Shortly afterward, someone in the audience came up to us, pale-faced, and said what we described looked very familiar. Two days later, they called and said they had found a very similar North Korean operative on their own network.”
He said these companies would never have looked at it if they hadn’t seen the talk.
“This is less about reputation and more about the greater good, improving how the technology works,” Whitelaw said. “This is half the problem with insider threats: people keep it to themselves.”
Povolny said some of Exabeam's most exciting recent work is what it calls Agent Behavior Analytics (ABA). The company has built UEBA capability for more than 15 years and is now applying the same approach to AI agents, baselining normal behavior, watching for anomalies and driving detection from that baseline
“The agent-based detection looks for first-time behavior, the first time this agent has behaved in this way,” Whitelaw said. “It looks for that same behavioral drift in human and non-human identities alike.”
Povolny said Exabeam is also expanding its AI agents to run deeper investigations and chat-based, supervised analysis. He said more product releases are planned over the coming quarter to year, applying the same behavioral-monitoring approach used to catch the North Korean operative to the autonomous digital workers now spreading through corporate networks.



