Fake worker scams trick companies into giving access
Criminals are getting into company networks not by cracking passwords, but by fooling the humans who hand out access. That includes fake job applicants who get hired as employees, and callers who trick help desks into resetting someone else's password.
- Report priority
- Medium
- Targets
- Specops Software+1 more
How it works
Attackers target the moments when a company decides to trust someone, like hiring a new employee or resetting a locked account, using stolen or fake documents and convincing phone calls instead of hacking a login directly.
What to do
Most individual readers are not personally at risk, but organizations should review whether their hiring process verifies identity documents and whether their help desk can be talked into a password reset with only a name and a phone call.
The fix is process, such as requiring stronger identity verification at hiring and account recovery, and using tools like Specops Password Policy to block compromised passwords and add verification steps to Active Directory resets.
Technical details
Affected software: Specops Software, Active Directory
A North Korean operative uses a stolen or purchased identity document, including photos supplied by someone in another country, to apply for and land a remote IT job at a tech company. Once hired, that operative does the actual work while appearing to be a legitimate employee with normal system access. Separately, a caller impersonating a real employee phones a company's help desk, convinces the staff to reset that employee's password, and uses the reset to get into the account.
The described risk is not a single CVE but a pattern: attackers target identity establishment and recovery workflows rather than authentication itself. Two documented cases anchor it: a July 2026 joint US-Japan-Canada-UK government alert on North Korean IT workers using falsified identity documents to gain remote employment at technology firms, and the 2025 Scattered Spider led ransomware attack on Marks & Spencer, where help-desk social engineering enabled a password reset that gave attackers account access, contributing to an estimated 400 million dollar hit to the retailer's operating profit.