In April 2026, the U.S. Department of Justice announced sentences for two men who ran laptop farms to assist North Korean operatives for three years. Their operation used the stolen identities of more than 80 Americans to land remote jobs at over 100 U.S. companies, several of them Fortune 500. One operative burrowed far enough into a defense contractor to reach export-controlled data. Before it was shut down, the scheme generated more than $5 million for the North Korean government and cost the victim companies millions more to unwind.
This case is one operation among many. DPRK IT-worker programs generate more than $600 million a year by placing operatives as remote employees.
Abnormal is releasing Infiltration Prevention to provide security teams with a way to detect impostors and threat actors attempting to infiltrate organizations, just like the programs above. This new security solution analyzes new identities entering your applicant tracking system (ATS), correlating behavioral, identity, and threat intelligence signals to surface potentially fraudulent patterns and activity commonly linked to nation-state actors for your security team’s review. Incident responders are provided with a timeline and detailed evidence of attempted infiltration to investigate.
Infiltration Prevention is another new security product expanding Abnormal's behavioral AI beyond email this year. It's built to extend the security perimeter to detect fraudulent identities before access is ever granted, long before background checks and post-hire insider risk tools.
Note: Infiltration Prevention is officially EA as of July 15, 2026 and will become GA at Black Hat USA 2026 on August 3, 2026. This blog serves as a preview of those GA capabilities.
Inside Infiltration Prevention
Infiltration Prevention applies Abnormal's threat intelligence to new identities entering your ATS, correlating behavioral, identity, and additional threat-intel signals to help catch synthetic and nation-state-linked identities before access would ever be granted. A background check confirms who someone was. Infiltration Prevention is built to see through who they're pretending to be. This is not a tool meant to recommend hiring decisions. It does not replace your existing HR and screening processes. Infiltration Prevention is built to stop bad actors.
The threat intelligence that powers Infiltration Prevention means a new identity gets evaluated against patterns surfaced elsewhere. No single application has to look suspicious on its own, but correlated against multiple appearances of similar personas, re-used resume templates, and known facilitator networks, a coordinated campaign gets flagged in ways a single company’s data alone typically wouldn’t surface.
Detection at the Application Stage
Most existing controls at the hiring stage are built for compliance, not security. A background check verifies a synthetic background just fine, but it isn't built to catch application- or behavioral-level anomalous patterns.
Infiltration Prevention adds a security layer, checking new identities entering your ATS and using the behavioral approach that Abnormal already applies to secure your internal email and identities, plus additional signals often associated with nation-state actors, like VoIP burner numbers and VPN-masked locations.
Example Use Case: An organization is hiring a Senior Software Engineer. Of all the personas now entering its ATS, Infiltration Prevention flags one. On paper, it's a legitimate identity: real name, real references. But the phone number tied to this persona is a VoIP number also linked to two other personas that appeared the same week, all claiming similar locations. That anomaly gets correlated against known threat intelligence to build an evidence brief for response.
Evidence Briefs for Human Review
Infiltration Prevention doesn’t hand a security team an unexplained alert. Instead, it builds an enriched evidence brief and timeline for every flagged identity. The solution is designed to give incident responders what they need to act decisively before that actor is ever provisioned and not take automated action against any persona.
Example Use Case: Infiltration Prevention flags a fabricated persona. An incident responder opens the evidence brief and sees the first signal: the domain in the individual's contact email was registered recently. Minutes later, the timeline updates: the name on the application doesn't match the name on the resume. As more evidence surfaces, the brief keeps updating, until a cluster of similar identities emerges, revealing a coordinated network rather than a single bad actor.
Abnormal Threat Intelligence Sees the Full Campaign
Nation-state-led infiltration attempts are surging, and organizations struggle to see past the identities in their own ATS. Abnormal's threat intelligence is built to connect known campaign fingerprints wherever they resurface, shared IP ranges, resume content, and phone prefixes, so a pattern invisible to any one organization becomes obvious against Abnormal's threat research.
Example Use Case: Three identities apply to three different companies in the same week, each under a different name but sharing the same VoIP prefix and near-identical resume language. On its own, each looks unremarkable. Checked against Abnormal's threat intelligence, the pattern matches a facilitator network already flagged elsewhere, confirming a coordinated campaign instead of three unrelated identities.
Keep Malicious Actors from Becoming Insider Threats
The best time to catch an infiltrator is before they're ever provisioned. Security teams have had no easy way to act on that, until now.
Attackers keep improving their ability to fabricate identities. Abnormal's behavioral AI keeps improving its ability to catch them.
Security leaders can feel confident that identities entering their organization, previously outside of security's purview, are now visible. Security practitioners can consult evidence briefs to respond with confidence, without interrupting HR and recruiting's hiring practices.
Infiltration Prevention extends Abnormal into the realm of insider risk, where one of the most effective defenses is knowing what normal behavior looks like and catching deviations fast.
Infiltration Prevention is available today to existing Abnormal customers already running Greenhouse or Workday.
To learn how Infiltration Prevention can help your organization keep fabricated personas from becoming real insiders, connect with your Abnormal team or request inside access.
The above is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Abnormal AI’s products remains at the sole discretion of Abnormal AI and is subject to change.

