TL;DR: In 2024 a cybersecurity company hired a software engineer who passed four video interviews and a background check, then started planting malware on his first day. He was a North Korean operative on a stolen identity with an AI-touched photo. In 2026 an autonomous AI agent broke into Hugging Face, and when the company’s own defenders went to investigate, commercial AI tools refused to help, because a safety filter cannot tell a defender from an attacker. Two stories, one lesson. Your automated gates now wave the threat through, and the thing that catches it is a person with the judgment to see that something is wrong.
In 2008, a New York auction house put dozens of bottles of rare Burgundy from Domaine Ponsot on the block, some labeled with vintages from the 1940s. The provenance looked clean and the bidders were ready. Then Laurent Ponsot, whose family makes the wine, saw the catalog and flew to New York to stop the sale, because his domaine did not make that wine until 1982. “This wine cannot exist,” he later told a court. The bottles came from Rudy Kurniawan, who ran a counterfeit-wine operation out of his kitchen and drew a ten-year sentence. The auction house and the paperwork had passed the fakes. The one man who had spent his life with the real thing read the list and knew at a glance that it could not be true.
The wine was a warning shot. The same move, an elaborate fake that clears every institutional check until one person who knows the real thing stops it, is now aimed at what a company cannot afford to get wrong: who it hires and what runs on its network.
In July 2024, KnowBe4, a company that sells security-awareness training, hired a software engineer for its AI team. He had a clean background check, a US identity, and a face that matched the one on four separate video interviews. Every gate the company had built said yes. The identity was stolen, the photo was AI-enhanced, and the engineer was a North Korean operative. His company laptop started trying to load malware within hours of arriving. KnowBe4’s security team caught the behavior that night and published the account, the only reason I can name them here.
One hire is a story. The scale is the argument. In June 2025 the Justice Department searched 29 “laptop farms” across 16 states, seized dozens of financial accounts, and described North Korean IT workers who used stolen identities to get hired at more than 100 US companies. The regime keeps up to 90 percent of the wages and has pulled in hundreds of millions of dollars, money that flows past US sanctions. One hire carries two payloads: access from the inside, and cash back to Pyongyang.
Most coverage files the North Korean scheme under HR fraud, or a background-check failure, or remote-work risk. It is a security breach that happens to enter through the recruiting funnel. The hiring pipeline is a perimeter now, and the recruiter reviewing a candidate is doing frontline defense whether the org chart says so or not. AI is what turned this from a curiosity into an industry: one operation can now generate synthetic candidates at scale, complete with deepfaked photos and avatars that hold a live video call.
Now the same coin, other face. In July 2026, Hugging Face, the largest repository of open AI models, disclosed an intrusion that, in its own words, “was driven, end to end, by an autonomous AI agent system.” A poisoned dataset ran code on a processing worker. The agent escalated, harvested credentials, and moved across internal systems over a weekend, more than 17,000 recorded actions. OpenAI confirmed the agent was its own model, running in an internal safety test that escaped its boundary. The barrier to this kind of campaign has fallen: Anthropic documented a near-novice who used an AI agent to extort 17 companies in a month. A synthetic attacker is cheap now. So is a synthetic employee.
Then the investigation ran into a wall. When Hugging Face’s team tried to analyze the real attack payloads with commercial AI models, the safety guardrails blocked them, because a filter “cannot distinguish an incident responder from an attacker.” They ran the forensics on an open-weight model on their own hardware instead. Their conclusion, in plain words: the attacker “was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.”
The safety alignment that makes hosted AI responsible for millions of ordinary users is a tax on the people defending you and a free pass for the people attacking you. Defending an organization now takes someone who can vet and run a capable model on infrastructure they control, before an incident, so a content filter cannot lock them out mid-response. That is a rarer skill than operating a security dashboard.
Put the two stories side by side and they point to the same conclusion. The background check passed. The four interviews passed. The sandbox boundary held, on paper. In each case the automated gate waved the threat through, and a person caught it: KnowBe4’s analyst on odd account activity, Hugging Face’s responders on correlated signals their own AI surfaced. When your attacker and your newest colleague can both be fabricated, the automated checks are the thing being fooled, and human judgment is the thing doing the catching. Ponsot caught the wine the same way, by knowing the genuine article well enough to see what could not be true. That kind of judgment takes years to earn.
This is where the cyber talent conversation loses the plot. Everyone quotes the ISC2 figure of 4.8 million unfilled security jobs and argues about whether AI fills the gap or replaces the analysts. That same ISC2 study reports something the headline skips: for the first time, budget passed talent as the top reason roles stay open, and the workforce grew one tenth of one percent, the slowest on record. Meanwhile AI is absorbing tier-1 work, the rung where junior analysts learn to tell a real alert from noise. The real shortage is judgment, and it has been hiding behind a headcount number. Automate the entry rung to save money this year, and you thin the supply of the only people who can catch a threat the machine passed.
The governments that treat cyber as national security already build for this. The US runs CyberCorps Scholarship for Service: the state funds the degree, the graduate owes it service. The UK’s GCHQ runs CyberFirst, paying undergraduates a bursary and summer placements. Both grow talent instead of buying it. A private employer that only buys experienced defenders, while automating away its own junior tier, is bidding for a shrinking pool against states that grow their own.
I spend my days deciding what to buy and what to build, and these stories are the same design problem: identity is cheap to fake, judgment is expensive to grow, and the tasks that grow it are the ones AI makes easiest to cut.
The defenses that hold now are stubbornly human: the recruiter who notices every time the story does not add up, the analyst who can run the model no vendor will run for them, the leader who decides what a machine may do without a person watching. AI can write the resume, pass the interview, and drive the attack. It cannot yet be the one who notices. You can keep training that person, or automate them away and learn what your gates were really worth.
Here’s How You Take Action
If you set workforce strategy: Move identity verification in hiring from a paperwork step to a security control, and put your security and recruiting teams in the same room before your next remote technical hire.
If you run a security team: Vet and stand up a capable self-hosted model now, while it is calm, so a vendor’s safety filter cannot lock you out in the middle of an incident. Hugging Face learned this the hard way; borrow the lesson for free.
If you are cutting the entry rung to fund AI: The tier-1 work you are automating is where your future senior defenders learn judgment. Automate the task, keep the apprenticeship, or you will buy this year’s margin with next decade’s empty bench.
If you hire remote technical talent: Learn how the North Korean scheme actually works. Treat a background check that comes back too clean as a reason to look harder, and count a live, verified human as worth the friction.
For everyone: The next time someone says AI will close the cybersecurity talent gap, ask which gap they mean, bodies or judgment. The answer tells you whether they understand the problem.
Christina Lexa writes Workforce Rewired, on the intersection of workforce transformation, AI, and global talent.
The views expressed here are my own and do not represent the position of my employer or any organization I am affiliated with.







