---
title: "Exabeam fraudulent remote hire and insider intrusion"
description: "Exabeam’s account of a fraudulent remote hire, attempted data theft and endpoint containment in summer 2025."
incident_type: "Cybersecurity incident"
status: "active"
last_modified: "2026-10-07"
canonical_url: "https://www.ally.security/incidents/exabeam-insider-threat-2025"
markdown_url: "https://www.ally.security/incidents/exabeam-insider-threat-2025.md"
stix_url: "https://www.ally.security/incidents/exabeam-insider-threat-2025/stix.json"
---

# Exabeam fraudulent remote hire and insider intrusion

A fraudulent remote hire obtained corporate access. Exabeam described detecting the activity, isolating the laptop and stopping the intrusion.

Last modified Oct 7, 2026 · 2 sources

## Summary

- **Environment:** Issued corporate account and remote-work laptop
- **Operational impact:** Isolated laptop; attempted exfiltration reported
- **Financial impact:** No quantified financial loss established

## What happened

In summer 2025, a fraudulent remote hire gained access at [Exabeam](https://www.exabeam.com/), according to its leaders’ [TechTarget account](https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam). The exact incident day is not established here. [2](#source-2)

## Impact

- Exabeam’s [incident presentation](https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf) describes malicious software, command-and-control installation and attempted company-data exfiltration. [1](#source-1)
- The retained evidence does not establish successful data theft, an affected-person count or a quantified loss.

## Timeline

### March 30, 2026 — Leadership account reported

[TechTarget published its account](https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam) of the earlier incident; this is a publication date. [2](#source-2)

### October 7, 2026 — Briefing updated

This briefing was last reviewed and updated on October 7, 2026.

## Threat Group & Attack Vector

Exabeam says stolen identity information and forged documents enabled the hire. The actor then signed into an issued corporate account. [1](#source-1) [2](#source-2)

### Actors

- Exabeam characterized the insider as North Korean; this record does not establish a specific group independently. [1](#source-1)

### TTPs

- T1078 — [Valid Accounts](https://attack.mitre.org/techniques/T1078/): abuse of the issued corporate account. [2](#source-2)

## Response

Responders isolated the laptop and disabled it after the user tried deleting files. Exabeam leaders described about five hours of observation and sharing indicators with the [FBI](https://www.fbi.gov/). [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/exabeam-insider-threat-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### From Hired to Fired: Lessons From a Real Insider Threat

research · Exabeam

<https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf>

<a id="source-2"></a>

### How AI caught a malicious North Korean insider at Exabeam

news · TechTarget · Mar 30, 2026

<https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam leadership told TechTarget that responders observed the isolated device for about five hours and sent indicators to the FBI.
2. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam leadership described a fraudulent remote hire gaining corporate access in summer 2025.
3. **Occurred At · 100% confidence · current**  
   TechTarget publishes Exabeam leadership account: 2026-03-30
4. **Affected Organization · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam
5. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam described isolating the laptop and disabling it after the user attempted to delete files.
6. **Used Attack Technique · 90% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: https://attack.mitre.org/techniques/T1078/
7. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam leadership described the actor signing into an issued corporate account on the first working day.
8. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam reported malicious software and command-and-control installation and attempted company-data exfiltration.
9. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam said stolen identity information and forged documents were used to pass hiring checks.
10. **Resulted In · 100% confidence · current**  
   Exabeam fraudulent remote hire and insider intrusion: Exabeam characterized the insider as a North Korean actor; the retained sources do not independently establish a specific group.

</details>
