X
Story Stream
recent articles

In late July an FBI official disclosed that a North Korean operative had worked as a remote IT contractor inside a U.S. federal agency for months before anyone caught it. Days later the FBI, the State Department, and six allied governments issued a joint alert: North Korean IT workers are using stolen identities and forged documents to land remote jobs at Western companies, then routing their paychecks back to Pyongyang to help fund its weapons programs. The Treasury Department puts the take at nearly $800 million in 2024 alone.

This is being covered as a counterintelligence story, and it is one. But I read it as something else: a duty-of-care case waiting for a plaintiff's lawyer to file it.

Start with the legal mechanism most of the coverage skips. Sanctions liability under the North Korea sanctions regime is strict. Treasury does not need to show a company knew it was paying a Pyongyang-run operation. It needs to show only that the payment happened. A firm that unknowingly puts a North Korean operative on payroll or grants network access to someone working on behalf of a sanctioned regime, is exposed to civil penalties regardless of intent, and the Office of Foreign Assets Control has settled cases for well into seven figures over conduct far less deliberate than this.

Now add Delaware law, since that is where most public companies are chartered and where the derivative suits get filed. Since Caremark in 1996 and sharpened by the Delaware Supreme Court in Marchand v. Barnhill, the listeria case that arose from an ice cream recall, boards have an affirmative duty to implement a reasonable system for monitoring risks that are mission critical to the business. For any company whose value sits in its codebase, its customer data, or its intellectual property, who has remote access to those systems is plainly such a risk. A board that never asked management how remote technical hires are vetted, never received a compliance report on the subject, and learned of the exposure only from a subpoena has exposure under Caremark, not just a public-relations problem.

The fact pattern is no longer hypothetical. A facilitator was recently sentenced to eight years after helping generate more than $17 million for North Korea by placing operatives inside more than 300 organizations, including government agencies. The tradecraft has moved past the obvious tells. Operatives now use generative AI to answer interview questions in real time and deepfake video to pass camera checks, so the standard advice, insisting on a live unscripted call, is no longer sufficient by itself. Eight individuals have been sentenced this year alone for facilitating these schemes.

Consider how the derivative suit reads after the next public incident: a contractor exfiltrates source code, or a ransom demand surfaces, or an audit finds months of vendor payments routed to a blocked entity. The stock absorbs the disclosure. Plaintiff's counsel does not sue the contractor, who has no assets and is likely unreachable. Counsel sues the board, and the complaint will not read like a cybersecurity brief. It will read like a Caremark complaint: public advisories from the FBI and Treasury dating back to 2022, repeated warnings through 2026, and no board minutes showing the topic was ever discussed. That is the utter-failure-to-monitor standard, built entirely from the company's own record of ignoring public warnings.

The defense deserves its strongest argument, because the underlying problem is genuinely harder than it used to be. AI-generated resumes, coached interview responses, and forged documents good enough to pass a standard background check are a real technical challenge, and no compliance program will catch every bad actor. Fiduciary duty has never required perfection. It requires a system: a board or committee that has seen a report on remote-hiring controls, asked questions about identity verification and device custody, and can produce minutes showing it did. Companies that segment network access for new remote hires pending verification, require live and unscripted interviews, and put this on a risk or audit committee's calendar at least annually will survive a Caremark claim even when one bad actor gets through. Companies that treated it as an HR checkbox will not.

None of this requires a board to become a counterintelligence unit. It requires what boards already exist to do: ask management a hard question, get a documented answer, and keep the records. That is considerably cheaper than explaining to a judge why a public FBI advisory sat unread in the general counsel's inbox for four years.



Comment
Show comments Hide Comments