A slight delay in the new IT employee’s onboarding indicated to Amazon’s cybersecurity experts that he was not who he claimed to be.
Keystroke data from a laptop belonging to an employee who was supposed to be in the United States should have reached Amazon’s headquarters in Seattle in tens of milliseconds. Instead, the data flow from that computer was more than 110 milliseconds, Amazon’s chief security officer, Stephen Schmidt, told Bloomberg.
This delay indicated that the worker was actually half a world away from the company’s office. He had been hired by an Amazon contractor, unaware that he was one of the North Korean hackers who steal money and data from Western companies by posing as remote IT workers.
Amazon employees have detected and prevented more than 1,800 attempts by North Koreans since April 2024, Schmidt said. The number of such attempts has increased by an average of 27% quarter-on-quarter this year, according to the company.
«If we hadn’t been looking for workers from the DPRK, we wouldn’t have found them,» Schmidt noted.
This year, Amazon security staff began keeping a close eye on a systems administrator hired by an outside firm after monitoring systems on the employee’s Amazon laptop alerted them to unusual behavior. Amazon discovered that the computer had been remotely controlled and traced the traffic all the way to China. Schmidt noted that the laptop did not have access to sensitive data, so security staff had been watching the hacker for some time.
«It appears that this individual used the same script as other North Koreans we’ve seen to get this job,» recalled Stephen Schmidt.
An Amazon representative said that the fraudster was helped by a woman from Arizona who was sentenced to several years in prison in July for participating in schemes with fake IT workers.
Schmidt noted that while sometimes scammers steal real identities, they tend to follow a pattern: going to the same schools and working for the same companies, often foreign consulting firms that are difficult to verify from the U.S. Other telltale signs include hesitant use of American idioms and English articles such as «a,» «an,» or «the.»
Schmidt said the North Korean fraudster was removed from Amazon’s systems within days. He stressed the need to thoroughly vet potential employees’ resumes, not just LinkedIn scans, and to have «good security software» that can detect subtle signs, such as small delays in data transmission from fingers on a keyboard.
Recall that in November of this year, Project Manager Anastasia Kyrnychna spoke about a strange communication with a developer who had a Ukrainian name and location in Lviv, but stated that he only uses English for work. Ukrainian IT experts suggest that programmers from North Korea or scammers from other countries were behind this account.
The manager told about correspondence with an allegedly Ukrainian developer who refused to switch from English to Ukrainian. The AIT team suggests that it was a programmer from the DPRK
«What do you think of Kim Jong-un?» An IT recruiter suggests that North Korean IT professionals are applying for jobs in Europe under the guise of suspicious candidates from Asia. She uses a special screening question for such people
Amazon запускає шоу з записами «розумних» дзвінків Ring. Це той самий українский стартап, який продала Кіра Рудик і в якого були проблеми з витоком персональних даних
Розповідаємо про зв’язок американського техгіганта та української компанії.
«Чи є у мене талант, якщо комп’ютер може імітувати мене?». Штучний інтелект пише книги авторам Amazon Kindle. The Verge поспілкувався з авторами та виявив багато цікавого
Письменники-романісти використовують штучний інтелект для створення своїх творів. Видання про технології The Verge поспілкувалося з письменницею Дженніфер Лепп, яка випускає нову книгу кожні дев’ять тижнів, й дізналося про те, як працює штучний інтелект для написання романів. Наводимо адаптований переклад статті.
Google, Amazon, Lyft і DoorDash компенсуватимуть працівникам витрати на аборт. Проте така пільга доступна не всім: що відбувається?
Технологічні компанії покриватимуть працівникам витрати на поїздки, пов’язані з абортами, пише Wired. Проте така компенсація буде доступна не для всіх працівників.
Зокрема, зазначається, що Google, Amazon та інші компанії допомагатимуть штатному персоналу шукати медичну допомогу за межами штату. Розповідаємо, що про це відомо.