Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

North Korean Hackers Target Healthcare: What You Need to Know

North Korean cyberattacks reveal how trusted identities and workflows create healthcare cybersecurity risk, and how security teams can test them.

North Korean Hackers Target Healthcare: What You Need to Know

Sometimes, a cyberattack starts with something as routine as a job interview.

In August 2026, WIRED published the results of an investigation into North Korean cyber operations (opens in new tab) based on nearly two years of research by Vangelis Stykas (opens in new tab). The security researcher found evidence connecting the hackers’ infrastructure to 1,640 companies across 57 countries, including healthcare organizations.

Hundreds appeared to have suffered serious intrusions.

The scale of the operation is striking, but the tactics deserve equal attention. Attackers repeatedly exploited ordinary relationships and trusted business processes: recruiters approaching job candidates, contractors accessing client environments, remote workers joining companies, and employees completing seemingly legitimate tasks.

For healthcare security teams, the takeaway goes beyond one North Korean campaign. Attackers are looking for places where trust, identity, and access intersect, and many of those places depend on people making judgment calls under pressure.

What did the North Korean hacker investigation find?

In many cases, the attackers used a technique security experts have tracked for years: posing as recruiters or employers, approaching software developers with convincing job opportunities, and asking candidates to download files presented as coding tests or interview exercises.

Those files, of course, contain malware.

Microsoft tracks this activity as ‘Contagious Interview,’ (opens in new tab) observing the campaign since at least December 2022. What the WIRED investigation adds is a much clearer picture of how far these operations might’ve spread.

Stykas told WIRED that the infrastructure he studied showed evidence of activity involving 1,640 companies in 57 countries. He also encountered compromised contractors who appeared to have access to as many as 30 different companies, demonstrating how a single identity can create exposure across multiple organizations.

North Korean operatives have also sought legitimate remote IT jobs under false identities. The FBI has warned that these workers may use stolen or fabricated identities (opens in new tab), U.S.-based facilitators, remote-access software, front companies, and manipulated hiring processes to obtain positions inside American companies.

These tactics share a common thread. Rather than relying exclusively on technical exploitation, the attackers work their way into processes that organizations already trust.

Why this matters for healthcare cybersecurity

Healthcare organizations depend on an enormous number of trusted interactions every day.

Clinicians need accounts restored quickly. Contractors need access to systems. Vendors troubleshoot software remotely. New employees get onboarded. Executives replace phones. Support teams respond to urgent requests from people they may rarely, if ever, meet in person.

Most of those interactions are legitimate, which is exactly why they can help an attacker. A convincing impersonator doesn’t need to invent a completely foreign process. They can step into an existing one and try to manipulate the person responsible.

Healthcare environments also add urgency to the equation. Security controls have to protect sensitive systems and patient data without unnecessarily delaying clinicians, staff, or critical operations. Social engineers can exploit that tension by manufacturing an emergency, impersonating someone with authority, or presenting just enough personal and organizational information to appear credible.

HHS has specifically warned healthcare organizations about attackers (opens in new tab) calling IT helpdesks, impersonating employees, and using social engineering (opens in new tab) to gain unauthorized access. In one sector alert, the agency described threat actors using local phone numbers and impersonating employees in financial roles to manipulate helpdesk staff.

The helpdesk is a useful place to examine the broader problem.

Healthcare’s helpdesk is an identity control

IT helpdesks are designed to solve problems quickly. They also manage workflows that can directly affect identity and access, including password resets, MFA changes, account recovery, device enrollment, and access restoration.

An attacker who can’t technically bypass MFA may try to persuade someone to reset it. Someone without a password may claim they lost access to an account. An impersonator might say their phone was stolen, their laptop failed, or they urgently need access before a patient procedure or executive meeting.

The attack works when a support process becomes an authentication bypass.

As Doppel has covered in its guide to defending the helpdesk against vishing attacks, helpdesk personnel face a difficult combination of pressures. They’re expected to resolve problems quickly and provide a good employee experience while also detecting people who deliberately use urgency, authority, frustration, familiarity, or personal information to push them around established controls.

Policies and annual training can establish expectations. Testing shows whether those expectations hold up under a realistic attack.

5 healthcare workflows security teams should pressure-test

The North Korean campaign offers a useful prompt for healthcare red teams to look beyond conventional email phishing (opens in new tab). Security teams should identify the trusted workflows an attacker could manipulate and test how the people, processes, and technical controls around them respond.

1. Password, MFA, and account recovery

Healthcare organizations should test whether an unauthorized caller can persuade helpdesk personnel to reset a password, replace an MFA factor, enroll a new device, restore an account, or change identity information.

The useful finding isn’t simply whether an employee passed or failed. Security teams need to understand what caused the control to break. Did the employee skip a callback requirement? Accept information that could be found publicly? Make an exception because the caller claimed to be an executive or clinician?

That distinction determines the fix. Some failures call for training, while others expose a weak workflow or a technical control that should not depend so heavily on individual judgment.

2. Contractor and third-party verification

The WIRED investigation makes contractor risk particularly relevant. Healthcare organizations rely on outside personnel across IT, billing, staffing, consulting, clinical services, software, and other functions, and those workers may follow different access and support processes than full-time employees.

Red teams should test what happens when someone claims to be a contractor, a recently onboarded employee, a remote worker, or a vendor. Can they obtain information about internal processes? Can they persuade someone to restore access? Does the helpdesk have a reliable way to verify an unfamiliar identity?

The FBI recommends stronger identity verification throughout hiring and employment and has warned businesses about risks involving contracted IT workers hired through third parties. Technical safeguards remain essential, but organizations also need evidence that the workflows surrounding those identities can withstand impersonation.

3. Sensitive-information elicitation

A social engineering attack doesn’t have to produce an immediate account takeover to succeed. An attacker may spend an early interaction gathering information that makes the next one more convincing.

A seemingly harmless conversation could reveal employee identifiers, authentication procedures, naming conventions, support processes, internal technology, organizational relationships, or other operational details. Each detail gives an attacker more material for building a believable pretext.

Human-layer testing should therefore measure information disclosure as well as obvious security events. A helpdesk agent who refuses a password reset but explains the exact verification process may still give an attacker something useful for the next attempt.

4. Multi-channel attack chains

Real attackers can move across channels as they build credibility. A campaign might begin with a recruiter message, continue through a video interview, involve a file download, and later move to email, messaging platforms, SMS, or voice.

The same approach can be used against healthcare organizations. An attacker could research an employee, send a spoofed message, follow up through another channel, and eventually call the helpdesk with enough context to make the request sound legitimate.

Testing these steps together gives defenders a better picture of the attack path than an isolated phishing exercise. Doppel’s human risk management platform (opens in new tab) supports simulations across voice, email, SMS, collaboration platforms, and messaging channels, allowing red teams to see how employees respond as a scenario develops across multiple interactions.

5. Verification and escalation procedures

Security teams should also test whether employees consistently follow the processes designed to stop these attacks. That includes callback requirements, identity verification, ticket creation, secondary approval, reporting, and escalation.

The most valuable exercises introduce the same kinds of pressure an attacker would use. Does the process still work when the caller sounds frustrated? What happens when they claim to be a senior executive? Will an employee make an exception when the person appears to know internal information?

These results can help distinguish a people problem from a process problem. If multiple employees break the same control in the same place, the organization may need to redesign the workflow rather than simply assign more training.

Move from periodic testing to continuous human-layer red teaming

Healthcare security teams already test infrastructure, applications, identities, and technical controls for weaknesses. Human-facing processes deserve comparable scrutiny because attackers are actively looking for gaps between written policy and real-world behavior.

A strong human-layer red team exercise (opens in new tab) starts with a specific attack path. Can a caller manipulate an MFA reset? Can someone posing as a contractor obtain sensitive operational information? Will an employee escalate a suspicious request? Does a recently changed process actually prevent the attack it was designed to stop?

The resulting findings should feed directly into remediation. Teams can update workflows, strengthen technical controls, coach higher-risk populations, or introduce additional verification requirements based on what the exercise uncovers.

Then they should retest the attack.

That creates a repeatable cycle of discovery, remediation, retesting, and measuring improvement. Doppel’s red teaming and insider risk management capabilities (opens in new tab) help security teams run those exercises across larger populations and multiple channels, rather than relying entirely on manually conducted tests.

Measure the attack paths that matter

Traditional phishing metrics (opens in new tab) can still provide useful signals, but they answer a narrow set of questions. A click rate (opens in new tab) doesn’t tell a healthcare CISO whether an attacker can socially engineer an MFA reset, extract sensitive information from a support team, or impersonate a contractor with access to critical systems.

Human-risk programs can add metrics tied more directly to those attack paths, including:

  • Adherence to identity-verification procedures
  • Sensitive information disclosed during simulations
  • Reporting and escalation behavior
  • Exceptions made to established policies
  • Susceptibility by role, workflow, or attack technique
  • Repeat behavior after remediation
  • Improvement between initial testing and retesting

These measurements give security teams a clearer picture of where human-driven risk actually exists and whether the controls surrounding it are improving.

Third-party access deserves particular attention. Verizon’s 2025 Data Breach Investigations Report found that the share of breaches involving third parties doubled (opens in new tab) year over year, reinforcing the need to treat vendors, contractors, and other external identities as part of the organization’s attack surface.

Healthcare organizations can’t eliminate contractors, remote workers, support requests, or identity exceptions. They can make those workflows harder to exploit and collect evidence that the controls work.

Test trust before attackers do

The North Korean campaign documented by WIRED demonstrates how much damage attackers can cause when they gain a foothold inside trusted relationships and routine business processes. Recruiting, contractor access, remote employment, and ordinary employee interactions can all become entry points.

Healthcare organizations have their own versions of those high-trust workflows. Helpdesks handle identity recovery. Vendors and contractors connect to internal systems. Clinicians and employees make urgent requests. Support personnel routinely have to decide whether the person asking for access is really who they claim to be.

Those decisions are part of the security perimeter.

Human-layer red teaming gives healthcare organizations a way to find weaknesses before an adversary does. By testing realistic attack paths across people, processes, and technology, security teams can identify where controls break, fix the underlying problem, and verify that the same technique will not work the next time.

Doppel helps healthcare security teams defend against social engineering (opens in new tab) across employees and operations through threat-informed human risk management (opens in new tab), realistic multi-channel simulation (opens in new tab), and scalable red teaming.

The goal is to understand which attack paths are open, close them, and measure whether the organization is becoming harder to manipulate. Get started with Doppel (opens in new tab) by scheduling a demo.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.