Skip to main content
SocureLinkedIn

Socure discusses workforce fraud, citing a North Korean campaign and a $17M scheme.

Source

LinkedInAug 12, 2026
likes
18
comments
1

Post

Your newest security threat might already have a badge, a login, and a paycheck. A year-long North Korean IT worker campaign used a fabricated identity to land a remote job inside a U.S. federal agency. Nobody caught it until federal investigators did. In one scheme, fraudsters used at least 80 stolen American identities to get hired at more than 100 U.S. companies, including Fortune 500 organizations, and generated more than $17 million before getting caught. At Socure, we receive hundreds of resumes a month from candidates we believe are fake. If we're seeing that volume, every company hiring remotely is too. In this special edition of World War Fraud Weekly, Mike Cook breaks down Workforce Fraud: -Why the warnings about this threat went unheeded, and what changed -The $17 million "laptop farm" scheme that reached 309 companies -Why Form I-9, E-Verify, and Zero Trust weren't built to catch this Read the full edition below.

linkedin.com/posts/socure_your-newest-security-threat-might-already-a...Read the full source

Extracted by Autobound

From the Signal API record
Signal
LinkedIn

What this signalsCompany posts often show what the team is pushing right now.

The full record

From the Signal API record

Topics and mentions

Tags

  • Security
  • Compliance
  • Hiring Plans
  • Fraud Protection

Initiatives

  • discussing workforce fraud tactics and impact
  • highlighting Socure's fraud detection capabilities

Pain points

  • workforce fraud from fake identities
  • fake candidates in hiring pipeline
  • limitations of I-9, E-Verify, Zero Trust in detecting fraud

Technologies named

  • Zero Trust
  • E-Verify
  • Form I-9

Extraction

Detected
Aug 13, 2026
signal_type
linkedin-post-company
signal_subtype
linkedinPost

Use this data

Get every LinkedIn signal for Socure and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Socure this week?”

  2. Send it to your own tools

    The Signal API returns LinkedIn signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full linkedin-post-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/18be8eb6-1715-49de-8cee-c6f044fb4e48 returns this record as JSON. POST /v1/companies/enrich returns every signal for socure.com.

{
  "signal_id": "18be8eb6-1715-49de-8cee-c6f044fb4e48",
  "signal_type": "linkedin-post-company",
  "signal_subtype": "linkedinPost",
  "detected_at": "2026-08-13T07:54:12.447+00:00",
  "company": {
    "name": "Socure",
    "domain": "socure.com"
  },
  "data": {
    "tags": [
      "Security",
      "Compliance",
      "Hiring Plans",
      "Fraud Protection"
    ],
    "summary": "Socure discusses workforce fraud, citing a North Korean campaign and a $17M scheme.",
    "post_url": "https://www.linkedin.com/posts/socure_your-newest-security-threat-might-already-activity-7493388150766006272-mI3Z",
    "num_likes": 18,
    "post_text": "Your newest security threat might already have a badge, a login, and a paycheck.\n\nA year-long North Korean IT worker campaign used a fabricated identity to land a remote job inside a U.S. federal agency. Nobody caught it until federal investigators did.\n\nIn one scheme, fraudsters used at least 80 stolen American identities to get hired at more than 100 U.S. companies, including Fortune 500 organizations, and generated more than $17 million before getting caught.\n\nAt Socure, we receive hundreds of resumes a month from candidates we believe are fake. If we're seeing that volume, every company hiring remotely is too.\n\nIn this special edition of World War Fraud Weekly, Mike Cook breaks down Workforce Fraud:\n-Why the warnings about this threat went unheeded, and what changed\n-The $17 million \"laptop farm\" scheme that reached 309 companies\n-Why Form I-9, E-Verify, and Zero Trust weren't built to catch this\n\nRead the full edition below.",
    "initiatives": [
      {
        "topic": "discussing workforce fraud tactics and impact",
        "urgency": 0.7
      },
      {
        "topic": "highlighting Socure's fraud detection capabilities",
        "urgency": 0.6
      }
    ],
    "pain_points": [
      {
        "topic": "workforce fraud from fake identities",
        "intensity": 0.8
      },
      {
        "topic": "fake candidates in hiring pipeline",
        "intensity": 0.7
      },
      {
        "topic": "limitations of I-9, E-Verify, Zero Trust in detecting fraud",
        "intensity": 0.6
      }
    ],
    "posted_date": "2026-08-12T19:29:15.562Z",
    "num_comments": 1,
    "technologies_mentioned": [
      {
        "name": "Zero Trust",
        "status": "evaluating"
      },
      {
        "name": "E-Verify",
        "status": "evaluating"
      },
      {
        "name": "Form I-9",
        "status": "evaluating"
      }
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.