A company was hacked after it hired a North Korean cyber criminal posing as an IT contractor. The unnamed company fell victim to a new North Korean hacking tactic, according to cybersecurity company Secureworks, which investigated the incident. A North Korean cyber criminal posing as an IT contractor was hired for a fixed-term contract by the firm, which is based either in the UK, US or Australia. Secureworks is keeping the company’s location general in order to protect the company. Within days of starting work, the criminal “accessed and exfiltrated company data”, according to Rafe Pilling, who is the director of threat intelligence at Secureworks. Then, when the employment contract was finished, the criminal used the hacked data “to demand a hefty ransom in return for not publishing” it, said Mr Pilling. This is a new tactic for the North Korean regime, which was already trying to sneak its workers into UK companies. “It is almost certain that UK firms are currently being targeted by [North Korean] IT workers disguised as freelance third-country IT workers …