Skip to main content
← Back to blog

Remote IT Hiring Needs Identity Verification, Not Just Interviews

FBI-backed steps for reducing the risk of fraudulent remote IT workers and unauthorized remote access.

By Alex Castrillo3 min readFact-checked August 28, 2026
Remote IT Hiring Needs Identity Verification, Not Just Interviews

Remote technical hiring can create privileged access before an employer has established that the worker, device, and physical location are genuine. This is a documented business risk, not a hypothetical scenario.

What the evidence supports

The FBI warns that North Korean IT workers have used false or stolen identities, U.S.-based facilitators, company devices, and unauthorized remote-access software to obtain work and reach company networks. The advisory recommends stronger identity verification, device controls, and monitoring for unusual access patterns.

Why it matters to a Connecticut operator

A systems administrator, developer, or outsourced support worker may reach email, cloud administration, POS integrations, or sensitive vendor data. Hiring and access decisions therefore belong in the security program, not only in HR.

Operator checklist

  • Verify identity with live, repeatable checks and compare employment, payment, tax, and shipping details for inconsistencies.
  • Ship managed devices only to verified individuals and investigate unexplained device-forwarding arrangements.
  • Prohibit unapproved remote-access tools and alert on their installation.
  • Grant the minimum access required and review privileged activity during onboarding.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.