- The CrowdStrike report: the numbers that redefine the threat
- Anatomy of infiltration: how North Korean groups operate
- Why Italian SMEs are not immune
- Strategic reading: beyond the technical perimeter
- Practical implications: what to actually do
- The work in progress: what's missing in the Italian debate
- 2027-2028 Outlook: the threat evolves
A new report from CrowdStrike reveals an alarming fact. North Korean hackers are responsible for nearly half of all cyberattacks recorded in the tech sector over the past twelve months. Therefore, the threat doesn't just concern large American corporations.
Indeed, infiltration campaigns are spreading across Europe and Asia. There are two main vectors: remote IT workers posing as legitimate freelancers, and fake recruiters contacting employees of target companies. Consequently, even Italian SMEs in the tech and advanced manufacturing sectors are exposed to real risks. In particular, those managing distributed teams or hiring staff through international digital platforms are particularly vulnerable.
At SHM Studio, we monitor these dynamics to help Italian businesses build a secure and structured digital presence. However, cybersecurity isn't just an IT issue: it involves hiring processes, digital identity management, and company culture. In summary, this article analyzes the numbers behind the phenomenon, the strategic implications for SMEs, and the operational countermeasures to adopt immediately.
The CrowdStrike report: the numbers that redefine the threat
In June 2026, TechCrunch reported CrowdStrike's findings on one of the most underestimated phenomena in global cybersecurity. North Korean actors are responsible for about 50% of cyberattacks recorded in the tech sector in the last twelve months. Therefore, this is an extraordinary share, far exceeding that attributed to other state-sponsored groups.
Moreover, the geographical perimeter of the threat has expanded. Campaigns no longer only target US companies. In fact, Europe and Asia are explicitly among the priority targets. Consequently, the issue directly enters the agenda of Italian SMEs operating in tech, advanced manufacturing, and digital services.
The documented attack vectors are mainly two. The first concerns remote IT workers who infiltrate organizations by posing as legitimate freelancers or contractors. The second involves fake recruiters who contact employees of target companies to steal credentials or install malware. Therefore, the threat is not just technical: it is social and organizational.
Anatomy of infiltration: how North Korean groups operate
To understand the scope of the risk, it is useful to examine documented operational techniques. North Korean groups — often classified under the umbrella Lazarus Group and affiliated clusters — combine advanced social engineering with high technical skills. In particular, they exploit global remote work platforms to insert themselves as employees or collaborators.
According to the analyses of Mandiant (Google Cloud) , these operators use false identities built over time, with credible portfolios and verifiable references. Thus, they bypass the standard checks of many companies. Once inside, they exfiltrate data, install backdoors, or sabotage critical systems.
Also relevant is the fake recruiter tactic. Through LinkedIn and other professional platforms, they contact engineers and developers with tempting job offers. Subsequently, they send infected files disguised as technical tests or contract documents. Despite this, many organizations have not yet updated their onboarding and selection protocols to include adequate security checks.
Why Italian SMEs are not immune
There is a widespread perception in Italian small and medium-sized enterprises: 'we are too small to be a target.' This belief is, in fact, dangerous. Indeed, North Korean groups do not necessarily seek large immediate financial spoils. They often aim to build persistent access positions, to monetize or to use as a bridgehead towards larger supply chains.
Therefore, an Italian tech SME collaborating with European or American multinationals automatically becomes a potentially weak link. Similarly, companies hiring developers through international platforms — Upwork, Toptal, LinkedIn — are exposed to the infiltration risk documented by CrowdStrike.
Among other things, the Italian context presents aggravating specificities. The culture of verifying digital identities is still poorly structured. Remote onboarding processes rarely include in-depth checks. Furthermore, training for non-technical staff on social engineering topics remains insufficient in most SMEs.
For this reason, we at SHM Studio we believe that cybersecurity must be integrated into the overall digital strategy of companies, not treated as a separate issue delegated exclusively to IT.
Strategic reading: beyond the technical perimeter
The phenomenon described by CrowdStrike requires reflection that goes beyond firewalls and antivirus software. According to the Gartner Cybersecurity Framework , the most exposed organizations are those that have not aligned HR and operational processes with cybersecurity policies. Therefore, the problem is systemic.
In particular, three areas are critical for Italian SMEs:
- Digital identity management: who enters the organization, with what credentials, and with what level of access.
- Remote hiring processes: physical identity verification, structured video onboarding, reference checks on independent channels.
- Security culture: continuous training for all employees, not just technical teams.
Furthermore, the importance of digital reputation is often overlooked. A company compromised by a state-sponsored actor suffers damages that go far beyond data loss: credibility with customers, partners, and investors is eroded in a way that is difficult to reverse.
Practical implications: what to actually do
Translating risk awareness into concrete actions is the most difficult step for many SMEs. However, there are accessible measures even without an enterprise budget.
First and foremost, identity verification processes for remote collaborators need to be reviewed. This includes mandatory video calls with ID verification, reference checks through direct channels, and the use of certified background check tools.
Subsequently, the principle of least privilege : each collaborator accesses only the resources strictly necessary for their role. Consequently, any compromise remains contained and does not spread to the entire infrastructure.
Furthermore, training on phishing and social engineering must become periodic and mandatory. Attack simulations — phishing simulations — are effective and relatively inexpensive tools. Finally, the adoption of solutions for Multi-Factor Authentication (MFA) on all critical systems remains the measure with the best cost-benefit ratio available today.
On the digital presence front, integrated AI solutions that SHM Studio develops for SMEs also include monitoring and anomaly detection components applicable to digital workflows. Similarly, a secure and updated web architecture reduces the exposed attack surface.
The work in progress: what's missing in the Italian debate
In the Italian public debate on cybersecurity, a fundamental element is still missing: the explicit connection between IT security and digital competitiveness. Often, the two conversations happen in separate silos. However, a company that suffers a significant breach doesn't just lose data: it loses competitive positioning, contracts, and trust.
Therefore, cybersecurity should enter into conversations about Digital marketing , on the SEO and on overall digital transformation. It is not a separate issue. It is an enabling condition for any sustainable digital growth strategy.
Among other things, the platforms on which SMEs build their visibility — from Linkedin to the systems of Google Ads — are also documented attack vectors. Therefore, those who manage these platforms must be aware of the associated risks.
Finally, the strategic copywriting and institutional communication can play an active role in building a security culture: clear messages, understandable policies, effective internal communication. These tools are part of a healthy digital ecosystem.
2027-2028 Outlook: the threat evolves
The projections for the next two years are not reassuring. In fact, North Korean groups are integrating generative artificial intelligence tools to make fake identities even more credible. Deepfake videos, synthetic profiles, and automated conversations will further lower detection barriers.
According to the analyses of MIT Technology Review , the “infiltrated IT worker” model is set to scale significantly. Consequently, SMEs that do not structure their verification processes today will find themselves in an increasingly difficult position in the 2027-2028 biennium.
For this reason, investing now in secure processes, training, and architectures is not a cost: it is a form of protection for the digital capital built over time. Those who wish to delve deeper into these topics or assess their exposure can contact the SHM Studio team for a consultative comparison. Further resources and insights are available in the SHM Studio blog .
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.