Halil, FBI and DOJ reporting confirms these schemes use stolen identities, U.S.-based facilitators or laptop farms, proxy systems, and unauthorized remote-access software. The identity problem is therefore a fraudulent insider holding valid credentials. Phishing-resistant FIDO2 is necessary, but it cannot establish that the person operating the managed device is the person hired.
New hires—effective immediately: require independent authoritative-document verification plus a supervised live challenge, preferably an in-person identity/location check; reconcile legal name, tax identity, residence, payment beneficiary, phone, and employment history through independent channels. Ship a managed, hardware-attested device only to the verified address, prohibit forwarding, and activate it during a live session. Permit access only from that device using device-bound FIDO2. For the probationary period, deny production, treasury, multisig, deployer, bridge-admin, signing, secrets-export, and CI/CD-administration rights; use task-specific JIT access with two-person approval.
Existing privileged workers—first 12 hours: reconcile HR and payroll records, device-shipping history, IdP/VPN sessions, hardware identifiers, recovery factors, EDR, DNS/proxy, GitHub, cloud and OAuth audit logs. James Okafor and I would treat authoritative identity/payment mismatches, one device or authenticator servicing multiple identities, unauthorized RMM or persistent remote-control infrastructure, and correlated code/data movement as strong evidence for containment—not proof of DPRK attribution. Require two independent telemetry sources. AI-detector scores, image metadata, video artifacts, accent, VoIP use, U.S. IP addresses, résumé inconsistencies, time-zone anomalies, or personal GitHub activity are weak signals alone.
Containment by hour 24: suspend production and financial roles first; revoke IdP sessions, refresh tokens, registered authenticators and recovery methods; quarantine devices and invalidate VPN/device certificates. Then revoke GitHub tokens, SSH keys, OAuth grants, cloud credentials, service principals, CI/CD secrets and code-signing keys. If access to DeFi control keys cannot be excluded, replace deployer, upgrade-admin, bridge and treasury signers from clean devices and recalculate the multisig quorum. Preserve endpoint and audit evidence, review every commit and deployment touched by the worker, and involve sanctions counsel. A password reset—or ordinary push MFA—does not evict this access chain.