{
  "type": "bundle",
  "id": "bundle--56d19aed-198e-5d0e-8744-8345d5b8ce94",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--a2f1bd3c-cfa6-5e8e-8642-fc9e30b55e1d",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "org:e0dc0d25-a16f-47f7-a6ca-b429068623c4",
      "name": "Exabeam",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--1003ba5f-fd83-5e5b-844b-26270389b4bd",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "inc:117d4997-d808-4048-a32e-b05ae95e4737",
      "name": "Exabeam fraudulent remote hire and insider intrusion"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--d2e8c8ac-8672-5b40-8f44-06e5bf38927e",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "brh:d09fd8b8-15ef-493b-804d-cc0b240e3813",
      "name": "Exabeam fraudulent remote hire and insider intrusion"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--dcafb85d-daa3-51f8-8bb2-fb1ef0630418",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:593e23ae-4346-4c18-855e-5372d72c80bc",
      "relationship_type": "affected-organization",
      "source_ref": "incident--1003ba5f-fd83-5e5b-844b-26270389b4bd",
      "target_ref": "identity--a2f1bd3c-cfa6-5e8e-8642-fc9e30b55e1d",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Exabeam",
          "url": "https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf",
          "external_id": "cit:8f153b31-8eda-4f66-ae71-b12928abd7e5",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:dd7748b6b0d9ff3fc44766d6e72d0ce37e4efba0672ad0174547dcaf1f4e3ad6"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--17529eb7-86ac-51cf-8a2a-d1faef2ade33",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:ba7d5b03-2bce-4070-b216-2429469ffb29",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "TechTarget",
          "url": "https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam",
          "external_id": "cit:aa622e1b-6e1b-41e5-be1e-86c9c17f4138",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:27d4922f13e7d75317c7cfeebccceba65860f99be2ecc757a0bd29bfeb0630de"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam leadership described the actor signing into an issued corporate account on the first working day."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--36a0d018-1e6e-5639-8807-2328ead8bf7b",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:e2724da3-506d-4ace-9ee8-12245f625ab9",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Exabeam",
          "url": "https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf",
          "external_id": "cit:870806bc-1dba-49c5-9fbf-464b173c84ce",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:dd7748b6b0d9ff3fc44766d6e72d0ce37e4efba0672ad0174547dcaf1f4e3ad6"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam characterized the insider as a North Korean actor; the retained sources do not independently establish a specific group."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--803a4e69-b77f-56f9-870f-b22af36b42d4",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:7ed53864-6393-4096-9ffc-034948a99702",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Exabeam",
          "url": "https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf",
          "external_id": "cit:87f3f20e-5749-408b-b63b-45254d855e25",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:dd7748b6b0d9ff3fc44766d6e72d0ce37e4efba0672ad0174547dcaf1f4e3ad6"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam described isolating the laptop and disabling it after the user attempted to delete files."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--aaa4c4b9-e6dc-52b5-8ab3-5723fc5400ba",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:bf88350e-a938-4e19-a66f-a7dd9adc8588",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Exabeam",
          "url": "https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf",
          "external_id": "cit:cc43ccd4-923b-4821-bb14-ae5b6e12f738",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:dd7748b6b0d9ff3fc44766d6e72d0ce37e4efba0672ad0174547dcaf1f4e3ad6"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam said stolen identity information and forged documents were used to pass hiring checks."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--aee125b8-4c09-5b05-8012-d849e9c43e5a",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:3828d63d-e398-496c-944d-e1b1f130dcfe",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "TechTarget",
          "url": "https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam",
          "external_id": "cit:d7f7883b-36c8-4162-b90b-e798666f5c3e",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:27d4922f13e7d75317c7cfeebccceba65860f99be2ecc757a0bd29bfeb0630de"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2026-03-30"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--b11ce419-20c5-5979-84aa-5b38a0793716",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:9cf2ff78-43ab-44ad-af53-cd1744bb28ed",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1078/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--c93a05a5-106e-504e-84e3-be6d9d32da8c",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:0e67aab5-c5ed-4eb6-9f5b-30784ea1ff69",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "TechTarget",
          "url": "https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam",
          "external_id": "cit:628e03f1-af4d-4399-b3fe-163fa77489af",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:27d4922f13e7d75317c7cfeebccceba65860f99be2ecc757a0bd29bfeb0630de"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam leadership told TechTarget that responders observed the isolated device for about five hours and sent indicators to the FBI."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--cc8e8b62-1438-5e41-8e0e-f33c26a4e79c",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:1ac145fa-0061-442f-bd5c-e429e4f50815",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "TechTarget",
          "url": "https://www.techtarget.com/cybersecurity/feature/How-AI-caught-a-malicious-North-Korean-insider-at-Exabeam",
          "external_id": "cit:f3a82f98-4f0f-475e-b642-0b58c2004555",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:27d4922f13e7d75317c7cfeebccceba65860f99be2ecc757a0bd29bfeb0630de"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam leadership described a fraudulent remote hire gaining corporate access in summer 2025."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--e28c3f0e-d49d-5de1-807d-7c7f4c3d629c",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "clm:bf57df0d-2133-423c-8b97-cc58bd5b44b5",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Exabeam",
          "url": "https://www.exabeam.com/wp-content/uploads/SLIDEDECK-From-Hired-to-Fired-Lessons-From-a-Real-Insider-Threat.pdf",
          "external_id": "cit:b4d072b6-5e7b-47eb-847f-e15d5d543014",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:dd7748b6b0d9ff3fc44766d6e72d0ce37e4efba0672ad0174547dcaf1f4e3ad6"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Exabeam reported malicious software and command-and-control installation and attempted company-data exfiltration."
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--6f92ba30-8141-5b31-879f-8717c50392ac",
      "created": "2026-10-07T15:30:00Z",
      "modified": "2026-10-07T15:30:00Z",
      "x_ally_original_id": "evt:d6f46156-bf12-4483-9004-e0b1cb06b6cd",
      "name": "TechTarget publishes Exabeam leadership account"
    }
  ]
}
