New Delhi, Aug. 12 -- WASHINGTON - The person who got inside was not a hacker. There was no zero-day exploit, no phishing chain, no spoofed credential that penetrated a layer of government security from the outside. The employee applied for a remote IT position at a US federal agency, passed whatever vetting the agency used, received system access, and went to work. The salary they earned went to Pyongyang.

The FBI confirmed this month that it is investigating the case of a North Korean national who was hired for a remote IT job at an unnamed US federal government agency, a disclosure made by a senior Bureau official at a conference in Washington on July 28 and first reported by TechCrunch. The agency involved has not been identified pub...