Stopping IT Worker Scams Requires Revamped HR Process

As North Korean hackers continue to infiltrate companies worldwide through IT worker scams, human-resource managers are being forced to revamp their hiring processes to prevent these malicious operations from succeeding. The threat, which has been dubbed “WaterPlum” or “Contagious Interview,” involves fake IT workers being embedded in companies to provide a steady flow of income for the North Korean regime.

The campaign, which has infected at least 30,000 devices across more than 100 countries and stolen over 7,000 cryptocurrency wallet credentials, relies on the widespread use of remote work arrangements, especially in the tech industry. The hackers’ goal is not to steal sensitive data or disrupt operations but rather to maintain a constant inflow of funds to North Korea.

To combat this threat, companies must improve their hiring processes by training human-resource managers to detect suspicious applicants and escalating efforts to determine whether they pose a risk to the organization. This includes looking for red flags such as a lack of digital footprint, use of voice-over-IP (VoIP) for calls, or inconsistent answers during interviews.

According to Nicholas Kowalczyk, vice president and chief risk, compliance, and privacy officer at Kelly Services, detecting IT worker scams requires stacking multiple pieces within the recruiting process. “It’s not about finding one silver bullet,” he says. “Rather, it’s about creating a hurdle for bad actors that doesn’t unduly burden legitimate candidates.”

One company that has successfully detected and thwarted an IT worker scam is Nisos, a human-risk management firm that applied its own tactics to catch the hackers in the act. By running their own operation on the suspected North Korean operative, Nisos was able to monitor the individual’s activities over several months, including their use of Gmail and Discord to communicate with other operators.

The success of these operations has generated significant concern among security experts, who warn that companies must take proactive steps to prevent these scams from succeeding. “It’s not just about having a good HR process,” says Ryan LaSalle, CEO of Nisos. “It’s about being vigilant and using technology to your advantage.”

In addition to improving hiring processes, companies can also benefit from automated analysis tools that help identify suspicious behavior and patterns. While no single solution can completely prevent these scams, combining human expertise with technological advancements can significantly reduce the risk of infiltration.

For readers who may be concerned about the threat of IT worker scams in their own organizations, there are several practical steps to take. First, make sure your HR team is trained to detect suspicious applicants and has access to resources that can help identify red flags. Second, consider implementing automated analysis tools to monitor employee activity and identify potential security risks. Finally, stay vigilant and continuously review and refine your hiring processes to prevent these scams from succeeding.


Source: Dark Reading — 2026-09-25