CRISISTABLETOP
Modern technology workplace used by remote software teams
← Exercise library

THREAT-INFORMED EXERCISE · WORKFORCE & INSIDER RISK

DPRK Remote IT Worker Infiltration

Hiring pressure and convincing credentials allow a fraudulent remote developer to enter the company through a U.S.-based laptop farm. Months later, identity, telemetry, and payroll anomalies converge with an FBI warning. The team must contain persistent access, preserve evidence, investigate stolen code and customer data, stop potentially prohibited payments, respond to extortion, communicate under uncertainty, and find a second suspect supplied by a staffing firm.

3 HRSuggested duration15Participant roles14Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Examine the organization's ability to prevent, detect, investigate, contain, and recover from a fraudulent remote-worker infiltration while coordinating cybersecurity, employment, privacy, sanctions, export, contractual, law-enforcement, insurance, communications, and governance decisions.

A fraudulent remote IT employee uses a stolen identity, a U.S.-based laptop farm, remote-access tooling, and deceptive payment channels to obtain trusted access, copy sensitive information, generate revenue for the DPRK, and extort the employer after discovery.

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

Which evidence-based hiring anomalies justify enhanced verification or a pause?

02

How should the company balance immediate containment with a law-enforcement request to preserve operational secrecy?

03

Can every session, token, repository, cloud key, customer environment, device, and payment path be identified and controlled?

04

How will sanctions obligations be reconciled with final-pay, benefit, tax, and employment requirements?

05

What can the company tell affected customers, workers, regulators, investors, the board, and media while attribution and scope remain uncertain?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Six months earlier
    Module 1 · Recruitment and access

    A difficult engineering role remains open

    A fast-growing U.S. technology company has struggled for months to hire a senior remote developer. A candidate using the name Jordan Lee applies with an excellent technical portfolio, a U.S. address, and recent contract work for recognizable companies. The resume lists a foreign university that the recruiter has not previously encountered.

  2. Interview week
    Module 1 · Recruitment and access

    Video and coding-test inconsistencies

    Jordan joins the video interview from a blurred background. Audio and lip movement briefly fall out of sync. During the coding exercise, Jordan pauses for long periods, gives polished answers after looking off screen, and declines a request to attend a final in-person identity check because of an urgent family issue.

  3. Offer accepted
    Module 1 · Recruitment and access

    Laptop destination changes

    After accepting the offer, Jordan asks IT to ship the company laptop to a temporary address in another state. The address is also used by a commercial mail-receiving business. Jordan says a relative will sign for the package during a move.

  4. Month 3
    Module 1 · Recruitment and access

    A productive employee seeks broader privileges

    Jordan receives strong reviews, closes difficult tickets, and regularly works outside the team's normal hours. Jordan asks for direct production access, cloud-administrator rights, and permission to export a customer database to accelerate troubleshooting.

  5. Month 6 · Monday
    Module 1 · Recruitment and access

    Endpoint telemetry shows remote control

    Security monitoring detects persistent remote-desktop sessions into Jordan's company laptop. The sessions originate from the local broadband connection associated with the shipping address. Endpoint logs also show clipboard transfers and development activity at nearly all hours.

  6. Month 6 · Tuesday
    Module 1 · Recruitment and access

    Identity and payroll records diverge

    A targeted review finds that Jordan's portfolio photo differs from an image captured during the interview. A former employer cannot confirm the claimed engagement. Payroll reports two recent bank-account changes, and another remote contractor uses the same account-routing information.

  7. Month 6 · Wednesday, 08:30
    Module 2 · Discovery and response

    The FBI calls about a suspected laptop farm

    An FBI private-sector coordinator tells the General Counsel that Jordan's identity appears to have been stolen. Agents are investigating a suspected laptop farm at the shipping address and believe overseas operators may be accessing multiple U.S. company devices. The FBI requests that the company preserve evidence and avoid alerting the operator until agents advise otherwise.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadGeneral CounselHuman Resources LeadTalent Acquisition LeadPrivacy OfficerFinance and Payroll LeadThird-Party Risk and Procurement LeadProduct and Export Compliance LeadEngineering ManagerCommunications LeadLaw Enforcement LiaisonCyber Insurance LiaisonExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • A documented remote-worker identity and equipment-shipping control model
  • A cross-functional fraudulent-worker escalation and containment playbook
  • A lawful sanctions and employment-payment decision path
  • Tested evidence, customer, notification, extortion, and communications workstreams
  • Staffing-firm controls and an enterprise-wide threat-hunting plan
Start with this exerciseRead the facilitator guide