30,000 Computers Were Infected Through Fake Job Interviews. Your Employee May Not Be the Real Target
Your employee gets a message from a recruiter. The job looks legitimate. The interview is virtual. Near the end, the recruiter sends over a coding exercise, or the video call conveniently glitches and they're asked to run a quick fix. They do. There was never a job. The interview was the attack. Five days ago, the FBI and international partners confirmed that variations of this scheme have infected at least 30,000 computers in more than 100 countries — and your employee's own information may not have been the point.
Most of the social engineering covered in this series follows a familiar shape: an urgent email, a scary invoice, a suspicious link. Employees have been trained, reasonably well by now, to be wary of things that look like trouble. This one doesn't look like trouble. It looks like an opportunity.
The recruiter was the attacker
On September 18, 2026, a joint advisory from the FBI, Japan's National Police Agency, the US Department of Defense's Cyber Crime Center, Australia's cyber security agency, and German intelligence services confirmed a scheme that's been running since 2022 and has been steadily escalating. A state-linked group operating out of North Korea posts fake job listings, often posing as AI, cryptocurrency, or Web3 companies, on ordinary social media and recruiting sites. Applicants who respond get a real-feeling process: a recruiter, a virtual interview, and a technical assignment.
The assignment is the trap. Candidates are asked to complete a coding exercise, or told the video-conferencing software has a glitch that needs a quick fix, and in either case, they're walked into running a file or a command on their own computer. That single action delivers the malware. It steals browser-stored passwords, keystrokes, screenshots, files, and even identity documents like passport scans, some of which are later reused to impersonate the victim elsewhere.
devices infected across more than 100 countries between roughly December 2025 and July 2026
The advisory also documented funds or account credentials taken from more than 7,000 cryptocurrency wallets, with at least $10.71 million in cryptocurrency transferred back to North Korea over that period. This isn't a single incident or a narrow campaign. It's a sustained, years-long operation that has scaled to a genuinely global reach, and it's still active.
The employee may not be the final target
Here's the detail buried in the advisory that matters most for a small business, and it's easy to miss if you only read the crypto-theft headline. The advisory explicitly warns that stolen credentials from a compromised job seeker can be used against that person's employer, clients, or contracting partners — and that a successful infection creates a real opportunity for attackers to move laterally into whatever corporate network that person can reach.
Your employee's personal information wasn't necessarily the attacker's final destination. Their employer may have been standing one credential away.
Think about what that means in practice. An employee who's quietly job hunting, updating a resume, taking a call on their lunch break, running a "quick test" on the same laptop they use for work, isn't doing anything against the rules. Nobody trained them to see that as risky, because until recently, it mostly wasn't. This advisory is evidence that it now is.
Your security awareness training probably never mentioned job interviews
You've likely trained employees not to open suspicious invoices, not to click strange links, not to wire money on a rushed request. Those are good, necessary habits, and this series has spent a year reinforcing them. But it's a safe bet nobody has ever told your team: if you're interviewing somewhere else, don't run a prospective employer's code on a computer that can also reach our systems. Why would they have? Until this advisory, that wasn't a widely recognized attack path. It is now.
Five rules every business should add now
Never run interview or assignment code on company hardware
Policy · FreeIf an employee is completing a technical assignment for a prospective employer, it should happen on a personal device that has no connection to your systems, never on a company laptop.
Don't use company credentials on outside recruiting platforms
Policy · FreeA work email or a reused work password on a personal job-search account is one more thread connecting an outside compromise back to your business.
Treat unfamiliar code and projects as untrusted by default
AwarenessThe advisory's own guidance for anyone who does need to evaluate unfamiliar code: use a sandbox or virtual machine, or a restricted execution mode, rather than running it directly on a primary device.
Make it easy, and normal, to report a suspicious interview
CultureAn employee who suspects something was off about a job process needs to feel safe raising it, without worrying it reveals they were job hunting. Make clear the concern is welcomed either way.
If malicious code was run, assume compromise, not just cleanup
ResponseDeleting the suspicious file isn't the fix. The advisory's own guidance is to treat the device as potentially compromised, assume data may already be out, and respond accordingly, which for a work-connected device means resetting credentials and reviewing account activity, not just running a scan.
The short version
Phishing used to arrive disguised as something you feared: an angry client, an overdue invoice, a locked account. Increasingly, it arrives disguised as something you want. A raise. A better job. A new client. A lucrative contract. Thirty thousand infected devices across a hundred countries is the scale of what happens when an attacker understands that ambition is easier to exploit than fear. Your employee's job search was never against the rules. Making sure it can't reach your business is the rule most companies haven't written yet.
Know what's actually connected to your business, including the devices you'd never think to check.
View the Threat Intelligence feed → Find Out More About ThreatAngel →📚 Credential Security Series → Read the full series

Comments
Post a Comment