Nisos A.I CyberSecurity Scoring
Nisos
Company Information
Website:https://www.nisos.com
Employees number:105
Number of followers:7,979
NAICS:
Industry Type:Data Security Software Products
Homepage:nisos.com
Nisos Risk Score (AI oriented)
Between 700 and 749
NisosData Security Software Products
Updated:
30/04/2026
30/04/2026
721/1000
Moderate
Ba
Nisos Global Score (TPRM)
xxxx
NisosData Security Software Products
Score locked

NisosModerate
Current Score
721Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
724
JULY 2026
724
JUNE 2026
723
MAY 2026
740
Cyber Attack
30 Apr 2026 • Nisos
Nisos: Security Breach: Rayn Lasalle
North Korean Hackers Leverage AI in Sophisticated Scam Targeting Industries
721
CRITICAL-19
NIS1777581234
North Korean Hackers Leverage AI in Sophisticated Scam Targeting Industries
In a rare firsthand account, Ryan LaSalle, CEO of human risk management firm Nisos, revealed details of an AI-driven cyberattack orchestrated by North Korean threat actors. The incident underscores the growing sophistication of state-backed hackers leveraging artificial intelligence to breach critical systems, particularly in the manufacturing sector.
LaSalle’s team uncovered the scam, which exploited AI tools to enhance social engineering tactics, financial fraud, and intellectual property theft. The attack highlights the escalating risks posed by foreign adversaries using advanced technologies to infiltrate high-value industries, with potential consequences ranging from financial losses to compromised proprietary data.
The disruption of this operation by Nisos provides a case study in how AI-powered threats are evolving and why organizations must treat such intelligence with heightened urgency. The full investigation report offers deeper insights into the methods and impact of these emerging cyber risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
740
MARCH 2026
740
FEBRUARY 2026
739
JANUARY 2026
739
DECEMBER 2025
739
NOVEMBER 2025
738
OCTOBER 2025
738
SEPTEMBER 2025
737
JUNE 2025
754
Cyber Attack
01 Jun 2025 • Nisos
Nisos: North Korean IT Worker Used Stolen Identity, AI-Generated Resume in Job Scam
North Korean Operative Attempts AI-Assisted Fraud to Infiltrate U.S. Cybersecurity Firm
735
CRITICAL-19
NIS1774881212
North Korean Operative Attempts AI-Assisted Fraud to Infiltrate U.S. Cybersecurity Firm
A suspected North Korean IT worker attempted to secure a senior remote role at U.S.-based threat intelligence firm Nisos in June 2025, using a stolen identity, AI-generated materials, and sophisticated remote access tools. The incident underscores the evolving tactics of DPRK-linked employment fraud, blending traditional identity theft with AI and VPN-based anonymization.
The operative applied for a Lead AI Architect position under the guise of a Florida-based full stack developer and AI specialist, using stolen personally identifiable information (PII), a fabricated email, and a VoIP phone number. Network analysis tied the applicant to Astrill VPN, a service previously linked to North Korean remote IT worker activity.
The AI-generated resume closely mirrored Nisos’ job description, listing skills and technologies verbatim from the posting including programming languages, cloud platforms, and OSINT tools while the summary section reused phrasing about "researching emerging agentic AI technologies." During a virtual interview, the candidate exhibited telltale signs of AI assistance, frequently looking away from the camera, pausing with the phrase "How can I say?", and failing to recognize a fake "Hurricane George" question designed to test authenticity.
Pre-employment OSINT revealed three inconsistent resume profiles under the same name, all referencing the real address of a Florida resident confirming identity theft. When Nisos shipped a corporate laptop to the provided address (different from the resume’s), tracking revealed a "laptop farm" inside a closet, containing ~20 devices managed via Raspberry Pi-based PiKVM hardware. This setup allowed remote operators to control multiple machines undetected, using Tailscale’s mesh VPN for encrypted command execution and data exfiltration.
The investigation identified ~40 devices on the network, with many tied to different employee identities across multiple companies. Security researchers warn this model enables DPRK operatives to earn foreign currency and access sensitive corporate data while evading detection. The case highlights the need for enhanced remote hiring controls, including deeper identity verification and technical interviews to expose AI-assisted deception.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Nisos ??
What was Nisos's A.I Rankiteo Cyber Score in July 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in June 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in May 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in April 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in March 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in February 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in January 2026 ??
What was Nisos's A.I Rankiteo Cyber Score in December 2025 ??
What was Nisos's A.I Rankiteo Cyber Score in November 2025 ??
What was Nisos's A.I Rankiteo Cyber Score in October 2025 ??
What was Nisos's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Nisos's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Nisos ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Nisos's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?