Organizations are facing a growing risk from insider threats, as cybercriminals increasingly exploit both the hiring process and employee online behavior to gain unauthorized access to sensitive data. Attackers are now impersonating cybersecurity and IT professionals, using fabricated resumes, deepfake technology, and stolen identities to secure legitimate positions within companies. Once inside, these "fake workers" can access confidential databases and systems, often leveraging remote work vulnerabilities and sophisticated obfuscation techniques such as VPNs and proxy servers to mask their true origins.
At the same time, employees' tendency to overshare on professional and social platforms like LinkedIn, GitHub, and X provides threat actors with valuable intelligence. Publicly available information about job roles, internal relationships, technical stacks, and even travel plans can be weaponized for spearphishing, business email compromise, and other targeted attacks. The combination of lax vetting in remote hiring and excessive online disclosure significantly increases the attack surface, making it easier for adversaries to infiltrate organizations and execute sophisticated social engineering campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Security reporting highlighted a growing insider-threat trend in which remote work and weak in-person verification make it easier for impostors posing as cybersecurity or IT staff to pass hiring processes. Managed service providers were identified as especially exposed because of their access to multiple client environments.
Researchers warned that employee posts on platforms such as LinkedIn, GitHub, Instagram, and X can provide OSINT that threat actors use for spearphishing, credential theft, malware delivery, and BEC. They also noted that groups such as SEABORGIUM and TA453 routinely use this reconnaissance approach.
Organizations reported cases in which malicious actors, including groups linked to North Korea, used stolen or fabricated identities, AI-generated resumes, fake credentials, and deepfake interviews to obtain remote cybersecurity and IT roles. The goal was to gain privileged access for data theft, financial fraud, or espionage.
Children's Healthcare of Atlanta was hit by a business email compromise attack that resulted in a $3.6 million loss, illustrating how attackers can weaponize publicly available employee and organizational information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.