30,000 Computers Were Infected Through Fake Job Interviews. Your Employee May Not Be the Real Target


FBI-Led Advisory
Human Risk
September 2026  ·  7 min read

Your employee gets a message from a recruiter. The job looks legitimate. The interview is virtual. Near the end, the recruiter sends over a coding exercise, or the video call conveniently glitches and they're asked to run a quick fix. They do. There was never a job. The interview was the attack. Five days ago, the FBI and international partners confirmed that variations of this scheme have infected at least 30,000 computers in more than 100 countries — and your employee's own information may not have been the point.


Most of the social engineering covered in this series follows a familiar shape: an urgent email, a scary invoice, a suspicious link. Employees have been trained, reasonably well by now, to be wary of things that look like trouble. This one doesn't look like trouble. It looks like an opportunity.

The recruiter was the attacker

On September 18, 2026, a joint advisory from the FBI, Japan's National Police Agency, the US Department of Defense's Cyber Crime Center, Australia's cyber security agency, and German intelligence services confirmed a scheme that's been running since 2022 and has been steadily escalating. A state-linked group operating out of North Korea posts fake job listings, often posing as AI, cryptocurrency, or Web3 companies, on ordinary social media and recruiting sites. Applicants who respond get a real-feeling process: a recruiter, a virtual interview, and a technical assignment.

The assignment is the trap. Candidates are asked to complete a coding exercise, or told the video-conferencing software has a glitch that needs a quick fix, and in either case, they're walked into running a file or a command on their own computer. That single action delivers the malware. It steals browser-stored passwords, keystrokes, screenshots, files, and even identity documents like passport scans, some of which are later reused to impersonate the victim elsewhere.

30,000

devices infected across more than 100 countries between roughly December 2025 and July 2026

The advisory also documented funds or account credentials taken from more than 7,000 cryptocurrency wallets, with at least $10.71 million in cryptocurrency transferred back to North Korea over that period. This isn't a single incident or a narrow campaign. It's a sustained, years-long operation that has scaled to a genuinely global reach, and it's still active.

The employee may not be the final target

Here's the detail buried in the advisory that matters most for a small business, and it's easy to miss if you only read the crypto-theft headline. The advisory explicitly warns that stolen credentials from a compromised job seeker can be used against that person's employer, clients, or contracting partners — and that a successful infection creates a real opportunity for attackers to move laterally into whatever corporate network that person can reach.

Your employee's personal information wasn't necessarily the attacker's final destination. Their employer may have been standing one credential away.

Think about what that means in practice. An employee who's quietly job hunting, updating a resume, taking a call on their lunch break, running a "quick test" on the same laptop they use for work, isn't doing anything against the rules. Nobody trained them to see that as risky, because until recently, it mostly wasn't. This advisory is evidence that it now is.

How one job interview reaches your business
1
A convincing fake job listing targets developers, IT staff, and technical freelancers specifically — the employees most likely to have real, valuable access to your systems.
2
A real-feeling interview process builds trust over days or weeks, ending in a technical assignment or a fabricated technical problem.
3
The candidate runs the file on whatever computer they happen to be using — which, for a huge share of small business employees, is also the computer they use for work.
4
The malware harvests what's on that machine — saved passwords, active sessions, files, screenshots — regardless of whose accounts they belong to.
5
Whatever that machine can reach becomes reachable by the attacker, including your business's systems, if the boundary between "personal job search" and "work laptop" was never really enforced.

Your security awareness training probably never mentioned job interviews

You've likely trained employees not to open suspicious invoices, not to click strange links, not to wire money on a rushed request. Those are good, necessary habits, and this series has spent a year reinforcing them. But it's a safe bet nobody has ever told your team: if you're interviewing somewhere else, don't run a prospective employer's code on a computer that can also reach our systems. Why would they have? Until this advisory, that wasn't a widely recognized attack path. It is now.

This connects directly to the single most-read post in this entire series, about the risk that sits on your payroll rather than outside your firewall. That post was about ordinary human error and everyday habits. This is the same lesson wearing a new disguise: the attack surface of your business now includes what an employee does while looking for their next job, on whatever device they happen to be using to do it.

Five rules every business should add now

1

Never run interview or assignment code on company hardware

Policy · Free

If an employee is completing a technical assignment for a prospective employer, it should happen on a personal device that has no connection to your systems, never on a company laptop.

2

Don't use company credentials on outside recruiting platforms

Policy · Free

A work email or a reused work password on a personal job-search account is one more thread connecting an outside compromise back to your business.

3

Treat unfamiliar code and projects as untrusted by default

Awareness

The advisory's own guidance for anyone who does need to evaluate unfamiliar code: use a sandbox or virtual machine, or a restricted execution mode, rather than running it directly on a primary device.

4

Make it easy, and normal, to report a suspicious interview

Culture

An employee who suspects something was off about a job process needs to feel safe raising it, without worrying it reveals they were job hunting. Make clear the concern is welcomed either way.

5

If malicious code was run, assume compromise, not just cleanup

Response

Deleting the suspicious file isn't the fix. The advisory's own guidance is to treat the device as potentially compromised, assume data may already be out, and respond accordingly, which for a work-connected device means resetting credentials and reviewing account activity, not just running a scan.

This is precisely the kind of exposure the ThreatAngel CyberScore's Security Posture assessment is meant to surface, alongside the human-risk factors this series keeps returning to. Knowing which devices can reach your systems, and whether the boundary between personal and work activity is actually enforced, is the practical version of the lesson this advisory teaches at global scale.

The short version

Phishing used to arrive disguised as something you feared: an angry client, an overdue invoice, a locked account. Increasingly, it arrives disguised as something you want. A raise. A better job. A new client. A lucrative contract. Thirty thousand infected devices across a hundred countries is the scale of what happens when an attacker understands that ambition is easier to exploit than fear. Your employee's job search was never against the rules. Making sure it can't reach your business is the rule most companies haven't written yet.

Know what's actually connected to your business, including the devices you'd never think to check.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.