In one of the most infamous scandals in international banking, Deutsche Bank helped move an estimated $10 billion out of Russia without anyone inside the institution raising a flag. Between 2011 and 2015, the bank’s Moscow desk executed what came to be called “mirror trades”: Russian clients, including some tied to politically exposed and sanctioned networks, bought securities in Moscow while related counterparties sold the identical securities through the bank’s London office. Each individual trade looked routine. But the aggregate was a covert pipeline that moved billions in funds out of Russia through London and into offshore accounts, exposing the bank to regulatory penalties on three continents.
This case underscores a reality the financial industry is now grappling with. Banks, fintechs, digital asset platforms, and investment firms face risks today that have outgrown the tools built to detect them. The gap between what traditional compliance can protect against, and the evolving tactics and techniques of adversarial nations, is where strategic intelligence becomes essential.
A Growing Target
Governments in Western countries (including the United States, Canada, United Kingdom, Japan, Australia, and throughout Europe) have designated the financial services and banking sectors as critical infrastructure. When a sector is classified as critical infrastructure, it signifies that its assets, systems, and networks are essential to national security, the economy, or public health. Failure or compromise of that sector would cause debilitating effects for society.
Because financial institutions sit at the center of global capital flows, regulatory scrutiny, and geopolitical competition, their systems, people, and partnerships are persistent targets for state-sponsored actors. The PRC’s systemic emphasis on data as a driver of national power ensures that banks and financial services companies will remain high-priority intelligence targets, valued less for their role as financial intermediaries than for their visibility into the broader ecosystems of strategic industries and capital flows. Banks serve clients in defense, energy, advanced technology, and critical infrastructure. They sit at the center of cross-border trade and investment. And they play a pivotal role in enabling corporate strategy, allocating capital, and shaping risk assessments, giving adversaries a window into the decision-making processes of global firms and governments—and the people who lead them.
State-sponsored actors seeking to infiltrate hiring pipelines, exploit third-party relationships, and influence deals are targeting enterprise banks whose innovation units are building AI, quantum, and cybersecurity capabilities. In the fintech and digital asset space, payment platforms, digital wallets, and crypto-processing environments hold high-value data and assets that adversarial governments are actively pursuing for leverage. And investment firms face growing enforcement from regulatory agencies, where even indirect exposure to sanctioned entities can trigger scrutiny and jeopardize funding.
The pressure is showing up across the sector. North Korean operatives have used fabricated identities to secure remote IT roles inside U.S. financial firms, funneling salaries back to the regime while gaining access to sensitive systems. Those schemes have helped the DPRK steal more than $6 billion in cryptocurrency. At Coinbase, overseas support contractorswere bribed by cybercriminals to exfiltrate customer data from inside the company. The result was a $20 million ransom attempt that affected tens of thousands of users. Cases like the Bitzlato CEO arrest and the JPEX exchange scandal tell a different but related story: undisclosed foreign control and executive-level misconduct at crypto platforms can trigger sanctions exposure, money laundering investigations, and lasting reputational damage.
Where the Financial Sector is Most Exposed
Understanding where adversaries are finding their way into organizations starts with understanding how exposure accumulates. It comes through hiring decisions made without full visibility, deal counterparties whose ownership structures aren’t fully traceable, and supply chain dependencies that no one has examined closely enough. For organizations across financial services, markets, and banking, the risk concentrates in three places.
The first is people. Financial institutions need to screen applicants, employees, vendors, and contractors for risky affiliations and falsified resumes, especially in high-trust roles across cybersecurity, fraud, money-movement operations, AI, quantitative research, and cyber R&D. These are the positions state-sponsored actors are working hardest to access, and they are doing so through falsified credentials, hidden affiliations, and ties to foreign programs that conventional background checks were not designed to detect. Rapid hiring cycles and remote-first work have expanded the surface area, making continuous vetting of both candidates and existing personnel essential.
The second is deals and partnerships. Every M&A transaction, IPO, fund onboarding, investment deal, and joint venture pulls new entities into a financial institution’s orbit, and each one can carry hidden ties, foreign control, or sanctions exposure that is rarely visible from the outside. Financial institutions need to be able to identify these risks across counterparties, customers, investors, LPs, board members, and global partners before a deal closes or a relationship deepens. Even indirect exposure, like adversarial capital or a sanctioned co-investor on a cap table, can trigger regulatory reviews and jeopardize investments. The Deutsche Bank mirror trading scandal is a case in point: the clients and counterparties behind the scheme were closely related entities with common owners, but the bank’s KYC (Know Your Customer) processes failed to surface those connections until billions of dollars had already moved.
The third is open source software and supply chain dependencies. Financial institutions increasingly rely on open source tooling in internal platforms and quantitative systems, as well as third-party crypto-processing centers, liquidity partners, and external infrastructure providers. Contributors to these tools and organizational dependencies can carry hidden nation-state ties, and without visibility into who is contributing to the code and infrastructure these institutions depend on, the risk compounds silently.
Case Study: Tracing an IRGC-Linked Network into European Real Estate
In 2025, reporting by Bloomberg and the Financial Times identified more than 400 million euros worth of European properties linked to Ali Ansari, an Iranian national sanctioned by the UK that year for providing economic resources to the Islamic Revolutionary Guard Corps (IRGC). Despite the designation, his holdings, which include London properties, hotels in Germany, and a resort in Spain, largely remain intact. They are held through a web of offshore companies and proxy individuals spread across at least eight jurisdictions. Any financial institution that encountered this network through a deal, a counterparty, or a vendor relationship would have had no way of knowing what sat behind it using standard screening tools.
Strider traced the network from beginning to end. Inside Iran, Ansari built a sprawling empire under the Tat Group name, with holdings in banking, finance, and construction. Tracing Tat Bank’s ownership through Iran’s corporate registry leads through his core construction entity, through multiple U.S.-sanctioned holding companies, and finally to Bonyad Taavon Sepah, the IRGC Cooperative Foundation. From there, the money moved west along a deliberately layered route. Iranian oil revenues, sold to China through sanctioned crude channels, passed through UAE intermediaries, into offshore holding companies in Saint Kitts and Nevis and the Isle of Man, then into Luxembourg and Dutch corporate vehicles, and finally into European real estate. By the time the capital arrived, it looked like legitimate Western investment on paper.
The network also depended on trusted individuals who could operate without drawing attention. Iman Rahimi Aloughareh held senior roles across Ansari’s Iranian businesses while simultaneously serving as founding managing director of the Luxembourg entities and the German operating company that anchored the European structure. Despite sitting at the center of a network with direct ties to the IRGC, Aloughareh has never been sanctioned. His name would not appear in any due diligence screen. This is exactly the kind of hidden ownership, foreign control, and sanctions exposure that financial institutions need visibility into, and exactly the kind that regulators, once they uncover it, treat as the institution’s responsibility.
How Strider Helps Financial Institutions
Strider is the leading provider of strategic intelligence for identifying and mitigating nation-state risk. The platform equips CISOs, insider threat teams, fraud and FinCrime leaders, compliance organizations, and investment teams with visibility into workforce risk, third-party exposure, and malicious communications.
For personnel risk, People Search and Falsified Resume Screening verify identities and surface risky affiliations before and after hire. Insights surfaces targeted technologies and associated employees most at risk from state-sponsored actors and provides tailored briefings to reduce recruitment risk across AI, quantum, and cyber R&D programs.
For deals, partnerships, and supply chain risk, Organizations Search maps multi-tier ownership and personnel ties for deal counterparties, investors, LPs, board members, joint-venture partners, and crypto-processing vendors. It supports M&A, investment banking, and strategic transactions by identifying foreign ownership, sanctions exposure, and hidden affiliations, and helps organizations better align with compliance requirements.
For open source software risk, OSS Search detects state-linked contributors across open source repos and assesses contributors and dependencies in tooling used in internal platforms or quantitative systems, helping prevent supply chain compromise. Shield feeds curated selectors into SIEM and DLP tools to identify, flag, and monitor geopolitical threats, including malicious emails, domains, and multilingual terms tied to state-sponsored cyber or recruitment activity targeting employees. Strider also provides expert analysis within its Intelligence Center on threats facing the financial sector—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
Looking Ahead
The financial services sector is operating in a rapidly changing risk environment—where the threats are geopolitical, the exposure is structural, and the cost of finding out too late keeps rising. Strider gives financial institutions the strategic intelligence to see what’s coming and act before it arrives.
From the systems that power electrical grids to the communications networks that connect the world, critical infrastructure is the foundation of economic growth and resiliency, national security, public safety, and life as we know it. It is a sprawling web of interdependent systems operating at extraordinary scale—divided by sector, but united by shared technologies, intertwined supply chains, and, increasingly, collective vulnerabilities.
While governments around the world maintain their own definitions of “critical infrastructure,” they largely converge around the same core systems that underpin modern society. Terminology may differ, but critical infrastructure sectors broadly include communications, information technology, and digital infrastructure systems; major energy sources (including electricity, renewables, oil, and gas); financial services and banking; government services and facilities; transportation systems (including air, rail, and maritime); water and wastewater; and defense. These are the sectors that societies rely on—making them uniquely attractive targets.
Adversarial nation-states like the People’s Republic of China (PRC), Russia, and Iran have spent the past decade mapping vulnerabilities in critical infrastructure—learning about them, figuring out how best to exploit them, and infiltrating them. The threat these countries now pose is more coordinated, more persistent, and more strategically targeted than at any prior point in history.
Critical infrastructure systems have become the new terrain through which power is projected and pressure is applied.
The Threat Landscape Has Changed
For organizations in critical infrastructure sectors, reliability has always been a top priority: keeping the power flowing, networks connected, goods moving, and daily life running. That hasn’t changed. But the threat landscape these organizations are operating in has. Today, resilience against adversarial nation-states has become as important as the reliability these systems have always prioritized.
That resilience is already being tested worldwide. Foreign-manufactured components with opaque capabilities have been discovered in Western power grids. Major telecommunications carriers have identified state-linked actors operating within their core networks. Energy and industrial companies in North America and Europe have taken systems offline following attacks that moved through third-party partners and global supply chains. The methods of intrusion are varied, but the scale and coordination point to something more deliberate than opportunistic attacks.
What distinguishes this new landscape is the strategy behind it. Intelligence and law enforcement agencies have assessed with high confidence that recent activity by groups like Volt Typhoon, a PRC state-sponsored hacking group known to target critical infrastructure, is inconsistent with traditional cyber espionage. Meanwhile, Russian-backed groups have targeted power grids, government networks, and financial institutions in Europe, aiming to destabilize and erode public trust. And Iran has gone after critical sectors in both the U.S. and Europe—including healthcare, transportation, and oil and gas—to test vulnerabilities.
These actors are not just trying to steal data. They are pre-positioning themselves deep inside critical systems with the goal of being able to cause disruption on demand. The objective is leverage, and critical infrastructure is how they intend to get it.
Policymakers have taken notice and are taking action. Japan’s Economic Security Promotion Act, enacted in 2022, designated approximately 200 entities across 15 sectors as critical infrastructure operators. The government is enabled to vet equipment suppliers or maintainers to ensure that vulnerabilities aren’t introduced related to foreign entities of concern.
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) confirmed that PRC state-sponsored actors had compromised networks across communications, energy, transportation, and water system sectors. Previously, the U.S. banned PRC technology provider Huawei from its 5G and telecommunications networks due to espionage risks.
In its National Security Strategy 2025, the UK government stated that “Hostile activity on British soil from countries like Russia and Iran is increasing, threatening our people, critical national infrastructure and prosperity.” The UK government also pledged to “roll out a series of new measures to…enhance the resilience of our critical national infrastructure.
The European Union, meanwhile, recently moved to restrict PRC suppliers from critical infrastructure, such as telecommunication networks, across member states entirely.
These actions make clear that critical infrastructure is a prime target for adversaries. For those responsible for keeping these systems safe and secure, understanding where and how deeply they have already been reached—and the strategies being employed by adversarial nation-states—has become essential for safeguarding economies and societies.
Where Critical Infrastructure Is Most Exposed
Understanding where adversaries are finding their way in starts with understanding how exposure accumulates—and it rarely happens the way most organizations expect. It comes through procurement decisions made without full visibility, hires that passed every background check, and partnerships that looked clean on paper. For organizations across critical infrastructure sectors, the risk concentrates in three places.
The first is the supply chain. The global supply chain for critical infrastructure components is vast, layered, and can often be difficult to trace. While that complexity is a byproduct of operating at global scale and within intertwined economies, it is also one of the most consequential vulnerabilities that organizations face. Adversaries have spent years learning to exploit it. The result has been solar inverters with undisclosed communication capabilities; telecommunications hardware sourced from entities with government ties; and transformers, fiber optic cables, and industrial control components whose origins cannot be verified.
Strider’s “In Broad Daylight” report captured exactly what that exploitation looks like in practice. In November 2024, PRC-linked company Deye remotely disabled inverters across the United States, United Kingdom, and Puerto Rico following a commercial dispute. The capability had been embedded in the hardware before it ever reached the grid. The leverage was already in place. The dispute simply revealed it. Strider research also shed light on the sustained PRC effort to identify vulnerabilities and develop methods to disrupt Western power grids—uncovering 2,723 publications on the subject authored by researchers affiliated with PRC defense institutions, including the People’s Liberation Army and national defense universities.
The second is the workforce. Privileged access to critical infrastructure systems is among the most valuable things an adversary can acquire—and state-sponsored actors are pursuing it methodically through recruitment, cultivation, and talent pipelines that look entirely legitimate from the outside. In 2023, that reality came into sharp focus when a telecom contractor in Florida was charged with acting as an agent of China’s Ministry of State Security while maintaining active system access at a major U.S. carrier. For every case like this that surfaces, the harder question is how many have not. Any organization that relies solely on conventional vetting methods is likely carrying risk that has not yet been illuminated.
The third is the extended partner ecosystem. Every joint venture, contractor relationship, and operational partnership is a potential entry point for adversaries to exploit. Partners bring their own supply chains, personnel, and geopolitical entanglements into shared operational environments, and there is rarely visibility into the full ecosystem. In the oil and gas sectors, where global operations and joint ventures are common, adversaries actively seek out partnerships as digital access points to disrupt operations and gain strategic advantage. Intellectual property from exploration breakthroughs, refining processes, and material-science research are frequent targets—compromised through the same trusted partnerships that companies depend on to operate. When any part of that ecosystem is compromised, the entire organization is compromised with it.
A Strider Use Case: A Major Energy Provider Prevented Exposure
A prominent U.S. power and energy company servicing some of the largest metropolitan areas in the country wanted to ensure its critical systems were safeguarded from nation-state threats. Company leaders wanted full visibility into the entities within its ecosystem as third-party partners or technology providers.
The company used Strider’s strategic intelligence platform to identify all entities with technology embedded in its infrastructure, then screened every third-party partner involved in day-to-day operations for connections to foreign entities of concern. What they found was alarming. A substantial portion of their critical infrastructure was being managed by a third-party company with direct connections to the PRC government, military, and defense organizations. The relationship posed a serious risk: this energy company could potentially lose operational control of their critical systems to a PRC government entity or actors working on its behalf. Company leaders severed ties with the management company.
For organizations involved in critical infrastructure sectors, this case illustrates something important: the exposure existed before anyone went looking for it. It only became visible when they had the right tools to see it.
How Strider Helps Critical Infrastructure Organizations
The organizations that manage risk posed by adversarial nation-states best are the ones that can see it clearly across their supply chains, their workforce, and their extended partner ecosystem. Most organizations have invested heavily in tools designed to detect threats after they’ve entered their critical systems. Strider’s strategic intelligence enables organizations to get ahead of these threats.
For supply chain and partner risk, Organizations Search maps the full ownership and affiliation picture behind every vendor, supplier, component, joint venture partner, and major contractor embedded in an operational environment—uncovering multi-tier relationships, hidden parent companies, and state-linked intermediaries.
For workforce risk, People Search screens employees, contractors, and candidates for nation-state ties, falsified credentials, and risky affiliations—revealing hidden connections that conventional background checks were never built to detect.
Across all three, Insights tracks the specific technologies and subject-matter experts most likely to be targeted by state actors and generates reporting for leadership on emerging geopolitical and partner risks.
And Shield flags and blocks malicious domains, emails, and communications tied to known adversary campaigns—feeding high-risk indicators into existing security systems to monitor risky inbound and outbound activity before it reaches operational environments.
Strider also provides expert analysis within its Intelligence Center on critical infrastructure security—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
The systems that make up critical infrastructure are only as resilient as the technologies, supply chains, and people that support them. Strider gives organizations the visibility to understand that full picture and to act on it before someone else does.
Conclusion
Critical infrastructure is the foundation that modern society cannot function without. And precisely because of that, it has become a primary target for those seeking leverage in this new geopolitical era. Keeping it secure, reliable, and free from foreign interference requires a level of vigilance that many organizations have not yet applied—but must.
Those who act now will find the exposure. Those who wait will feel it.
For more than a decade, the Thousand Talents Program (TTP) was one of the People’s Republic of China’s (PRC) largest and most successful mechanisms for attracting overseas scientific and technical expertise. It targeted the world’s top researchers, scientists, and experts, incentivizing them to work in the PRC through competitive compensation, funding, and institutional support. Public reporting estimates that more than 7,000 individuals participated in the program from 2008 to 2018, providing a significant boost to Beijing’s science and technology sectors.
Then, after years of prominence, the program appeared to vanish.

As major Western news outlets began to highlight the risks of intellectual property theft linked to talent recruitment by the PRC, references to the TTP disappeared from official PRC government websites and public-facing recruitment materials. PRC officials told foreign governments and institutions that the program had been discontinued. Even the words “Thousand Talents Program” were discouraged from being used in written correspondence by the PRC. To outsiders—and competing nations—it looked as though the program had run its course.
As references to the TTP declined, Strider analysts observed a corresponding increase in the activity of other talent programs operating under different names. In many cases, the eligibility requirements and incentives for these programs were similar to those offered under the TTP. They targeted the same types of researchers, scientists, and experts from abroad and continued to channel that talent into the PRC’s scientific and technological pipelines.
Eventually, the evidence pointed to a different conclusion: the Thousand Talents Program—perhaps the PRC’s most effective state-sponsored talent recruitment program to date—was never eliminated. It was rebranded, reorganized, and better positioned to influence the next phase of the PRC’s global talent strategy.
The Rise and Fall of the Thousand Talents Program
The Thousand Talents Program (also known as the Thousand Talents Plan) was one of hundreds of talent plans designed to systematically draw advanced scientific and technical expertise to the PRC at scale. It operated as a centralized framework through which universities, research organizations, state laboratories, and companies could recruit foreign talent and align it with PRC priorities.
From its inception, the program was embedded within the Chinese Communist Party’s (CCP) broader political and organizational architecture. According to the plan’s now-defunct website, the United Front Work Department (UFWD) was one of the authorities responsible for implementing the TTP. The UFWD is a decades-old agency responsible for managing the CCP’s influence operations and advancing its interests inside and outside the PRC. President Xi Jinping has described it as “an important magic weapon for the party to defeat the enemy.”
The United States government has framed the program in similarly strategic terms. In 2020, the U.S. Department of Justice described the TTP as “one of the most prominent Chinese talent recruitment plans that [is] designed to attract, recruit, and cultivate high-level scientific talent in furtherance of China’s scientific development, economic prosperity, and national security.”
Over time, the program expanded into a set of distinct branches designed to target different career stages and use cases. These included long-term tracks for researchers, short-term arrangements that allowed overseas experts to retain foreign affiliations, entrepreneurial tracks linked to commercialization, and the Young Thousand Talents Program, which focused on early- and mid-career researchers trained abroad.
That scale and visibility, however, created exposure.

As international scrutiny intensified and U.S. enforcement actions increasingly cited the Thousand Talents Program by name, the branding that had once amplified the program’s reach became a liability. Some individuals affiliated with the TTP became targets of FBI investigations aimed at curbing the transfer of sensitive technology and intellectual property to the PRC. As a result, the program became closely associated with enforcement and counterintelligence concerns in the United States and across the West.
A Strategic Rebrand and Reorganization
By the early 2020s, the PRC’s national talent recruitment architecture began to shift in visible ways.
Chinese-language recruitment forums and open-source reporting indicate that in 2021, the Thousand Talents Program was rebranded under a new name: the Qiming Program. Overseen by the PRC’s Ministry of Industry and Information Technology, Qiming seeks technological experts in industries of strategic importance, such as semiconductors.
The timing and structure of the change are notable.
The rise of Qiming closely tracked the decline of Thousand Talents references on the open web. Eligibility requirements for participation in Qiming closely mirrored those previously associated with the Thousand Talents Program, indicating continuity in how candidates were targeted and selected. Qiming’s financial incentives—which include lucrative one-time awards from central and local governments—are identical to provisions in the original TTP. The end goal also remained consistent: recruiting overseas talent to advance the PRC’s strategic scientific and technological dominance. Taken together, these signals suggest that Qiming functions as an alias for, if not the direct replacement of, the TTP.
Qiming and other national-level talent introduction programs are only part of the PRC’s sustained, whole-of-nation approach to recruiting foreign talent. Even as individual programs change names or structures, talent recruitment activity remains a top priority for the PRC—and an essential consideration for organizations seeking to safeguard their people, technology, and innovation from economic statecraft.
From Indicators to Actionable Intelligence
Strider helps organizations address this challenge by enabling a more comprehensive view of the PRC’s talent recruitment ecosystem.
Tools like Shield help organizations protect intellectual property by identifying higher-risk indicators—such as specific email addresses, affiliated domains, and keywords in multiple languages—commonly associated with state-linked recruitment and technology transfer activity. Other tools, such as People Search and Insights, help illuminate individuals’ involvement in state-sponsored talent programs. Meanwhile, Organizations Search can uncover organizations involved in state-directed recruitment efforts. Alongside this data-driven approach, Strider provides ongoing analysis within its Intelligence Center of recruitment trends, institutional linkages, and talent movement—offering additional context on how state-sponsored efforts are evolving in real time.
Conclusion
The evolution of the Thousand Talents Program demonstrates how the PRC rebrands and reorganizes major initiatives to sustain talent recruitment under external pressure. Looking ahead, the most consequential developments are unlikely to announce themselves. Instead, they will emerge through updated programs, new structures, and familiar patterns in unfamiliar places. As a result, the advantage will belong to organizations that can leverage cutting-edge intelligence to identify, assess, and act on threats faster.
“Nearly every Fortune 500 company has grappled with how to safeguard their workforce from the threat of infiltration by DPRK actors posing as IT workers.”
This observation from Strider CEO and Co-Founder Greg Levesque captures a sobering reality for companies operating in this new geopolitical era: the global talent market is being exploited by adversarial nation-states looking to gain advantage. Strider’s Inside the Shadow Network report reveals how this new threat has direct consequences for businesses—not as abstract geopolitical risk, but as measurable sources of legal, financial, and reputational exposure.
In the first and second blog posts in this series, we examined how North Korea’s remote IT worker scheme operates and the infrastructure that enables it, including the use of falsified identities, freelancing platforms, and PRC-based intermediaries. With that foundation in place, the remaining question for business leaders is: What does this mean for my company?
Answering that question requires moving beyond awareness to insight—understanding where exposure actually exists and how it shows up inside companies.
Risks to Businesses
As North Korea’s remote IT worker scheme has expanded, so too has the scope and scale of its impact on Western and Japanese companies. This risk surfaces across multiple dimensions of business, often incrementally, and often before companies even recognize they are exposed.
Regulatory and legal risks are often the first to emerge. Companies that unknowingly hire or contract North Korean nationals posing as remote IT workers may find themselves in direct violation of U.S. and international sanctions against the DPRK. Companies that violate these sanctions could face severe penalties, including hefty fines, legal action, and restrictions on their ability to operate internationally.
Reputational damage can follow quickly once exposure becomes public. Any degree of association with North Korean nationals can do irreparable damage to the public image of Western and Japanese companies. It can give the perception of weak oversight or insufficient controls, which would be especially harmful for companies in sensitive industries such as defense, technology, and finance. And worse, it can erode trust among customers, partners, regulators, and investors.
Intellectual property theft presents a more subtle but consequential risk. By embedding themselves in legitimate IT roles, North Korean nationals may gain access to a company’s proprietary software, internal tools, and trade secrets. The result is the quiet removal and relocation of intellectual property back to the DPRK, where it can be used to advance its technological capabilities or transferred to other hostile nation-states and criminal organizations.
Data breaches and espionage add another dimension of exposure. Access to corporate systems can allow embedded workers to interact with sensitive data, including personal information, financial records, and confidential corporate communications. That data may be exfiltrated for intelligence purposes or monetized through illicit channels, leaving companies and employees exposed. In some cases, organizations only uncover the extent of these breaches well after the data has left their control.
Financial losses from cybercrime round out the risk landscape. North Korean IT workers have been linked to ransomware attacks, hacking operations, and other cyber activity targeting Western and Japanese companies. The resulting costs for companies have been substantial—from ransom payments and system recovery to business interruption and increased security spending, totaling hundreds of millions of dollars.
Why Traditional Due Diligence Misses This Threat
What this scheme ultimately exposes is a gap between how companies assess risk and how adversarial nation-states are operating in this new geopolitical era. Traditional hiring practices were not designed to detect actors operating through falsified identities, layered intermediaries, and global platforms.
Mitigation begins with visibility. Companies need a clearer understanding of who they are hiring and contracting with—particularly across remote roles, third-party vendors, and outsourced IT services. That means moving beyond surface-level identity verification to in-depth assessments of potential affiliations, linkages, and exposure to networks that may not be immediately apparent through conventional due diligence.
Enter Strider.
Strider helps companies solve the visibility problem by turning open-source data into strategic, actionable intelligence. That means providing companies a faster way to screen both the individuals applying for work and the organizations behind them.
Strider’s People Search screens individuals for nation-state ties, falsified resumes, or hidden risks so teams can make better decisions across hiring and access workflows. It also supports resume verification by flagging inconsistencies and suspicious credentials that can be missed in standard checks.
Strider’s Organizations Search helps companies identify state-sponsored threats across third-party relationships by revealing hidden connections across parent companies, subsidiaries, suppliers, customers, and key personnel. By prioritizing high-risk connections with risk-only filtering, it allows companies to identify potential threats quickly and act before exposure spreads.
Strider brings these insights into the decisions that matter most: when companies are evaluating candidates, approving vendors, or expanding access for contractors. In this new threat landscape, increased visibility is necessary.
Conclusion
Today, it is North Korean workers infiltrating companies while posing as remote IT workers. Tomorrow, it may be other state-backed actors using new tools, methods, or operations to target private industry. The bottom line is that this type of threat isn’t going away. As long as innovations and new technologies are happening in this sector, adversaries will keep looking for ways to access and exploit them.
Companies that recognize this shift now—and invest in intelligence-led approaches to secure their workforce—will be the ones better equipped to protect their operations, their reputations, and their long-term resilience.
How falsified identities, front companies, and intermediaries enable DPRK remote worker operations
Over the past several years, thousands of North Korean nationals—often posing as remote IT workers—have infiltrated Western and Japanese companies and generated billions of dollars for the DPRK regime.
As Strider’s Inside the Shadow Network report details, North Korea has developed an operational model that actively exploits the structure of the global talent market. Understanding how this model works—and why it continues to succeed—is a critical step for Western and Japanese companies seeking to protect their revenue, innovation, and reputation, while also avoiding U.S. and UN sanctions violations.
Tactics, Techniques, and Procedures (TTPs) in Practice
One of the primary tactics underpinning these schemes is the use of disguised identities and front companies. North Korean IT workers routinely operate under aliases, supported by forged documents and fabricated credentials, to secure employment with foreign firms. In many cases, they establish front companies that appear to be legitimate IT services firms that allow these individuals to interact with global clients without raising suspicion.
Freelancing platforms are also an entry point for North Korean nationals targeting Western and Japanese companies. Sites like Upwork, Freelancer, and Fiverr are popular platforms where companies can connect with skilled freelancers looking for remote technical work. These platforms typically require some form of identity verification based on information provided by freelancers, but they make clear that they cannot guarantee a user is who they claim to be. This creates opportunities for North Korean nationals—often using stolen identities—to infiltrate the talent pool of global companies under the guise of remote IT work.
But that initial access is just the beginning. Once a national is embedded in a company, their access to critical systems often expands. Additional permissions are granted. Credentials are issued. Over time, what began as limited work on one or two projects can evolve into broad visibility across a company’s core systems.
In some cases, that access is leveraged directly for cybercrime activities. This can include the deployment of ransomware, phishing campaigns, and hacking operations coordinated with North Korean state-sponsored groups such as the Lazarus Group. The proceeds from these cybercrimes are funneled back to the DPRK regime, helping fund its nuclear and missile programs.
Other nationals focus on application and software development, creating apps and programs marketed to global audiences, often under the banner of foreign companies. At first glance, these apps and programs can appear legitimate and innocuous. They can cover many different fields, including business, health and fitness, social networking, sports, entertainment, and lifestyle. But these apps and programs can also serve as a Trojan horse for malicious code that allows North Korean nationals to conduct surveillance, steal data from users, and generate illicit revenue.
The DPRK has also shown a growing interest in cryptocurrency markets as a mechanism to evade international sanctions. A recent report from the blockchain watchdog company Chainalysis found that North Korea stole more than $2 billion in cryptocurrency last year. That amounts to over half of all crypto stolen globally in 2025 and brings the DPRK’s total identified haul since 2016 to nearly $7 billion. These markets are prime targets for North Korean IT workers, who create and deploy malware to mine cryptocurrencies, hack exchanges, and participate in initial coin offerings.
The Broader Threat Ecosystem
This operational model goes beyond the tactics, techniques, and procedures of individual actors. It depends on a broader ecosystem that allows North Korean nationals to work outside the DPRK and remain connected to global platforms and markets.
Strider is shedding light on how this ecosystem operates. Powered by a dataset spanning nearly 20 billion global open-source documents, Strider is using advanced AI technology and proprietary methodologies to uncover and map complex threat networks and identify potential intermediaries. That research shows that intermediaries based in the People’s Republic of China (PRC) play a particularly important role in this ecosystem. In practical terms, these intermediaries help solve the logistical challenges of operating overseas for North Korean workers.
One example is the Liaoning China Trade Industry Co., Ltd., which was sanctioned by the United States last year after it was discovered that the company had shipped equipment—including computers, graphics cards, HDMI cables, and more—to Department 53, an entity subordinate to the DPRK Ministry of National Defense. It is this type of support that allows North Korean nationals to remain fully equipped and functioning without raising any alarms or jeopardizing their identities.
Strider’s data allows even deeper analysis of PRC operational support. Using Organizations Search, its proprietary third-party due diligence platform, Strider identified 35 additional organizations linked to Liaoning China Trade that could also be supporting Department 53. In many cases, these organizations appear to operate in normal commercial sectors and present themselves as legitimate businesses. But beneath the surface, they pose a significant risk to Western and Japanese companies, which may engage with these organizations and unknowingly expose themselves to potential sanctions violations and serious reputational harm.
While the PRC plays a central role in this scheme due to its proximity and vast digital economy, Strider’s research shows that North Korean IT workers also operate from Russia, Southeast Asia, parts of Africa, and the Middle East. These regions differ in regulatory and political context, but they offer similar advantages: access to the global internet, uneven oversight, and distance from the DPRK.
Conclusion
Government entities are working to uncover and eliminate the DPRK remote worker threat, but the scope and scale of this operation are already far greater than most companies recognize. Addressing this network requires coordinated vigilance across both public and private sectors. To help combat threats like this, Strider developed a tool—Falsified Resume Screening—to help organizational leaders detect fabricated or inconsistent credentials in job applicants.
Moving forward, business leaders must take a proactive approach to safeguarding their organization from unwittingly hiring a remote worker from the DPRK—because the integrity of their workforce, sanctions compliance, and reputation are at stake.
Insider threats remain one of the most complex and consequential risks organizations face today. Unlike external cyberattacks or obvious physical intrusions, insider threats often arise from trusted individuals—employees, contractors, or research partners—who exploit their access to sensitive data, intellectual property, or systems. While not every insider threat is malicious, the potential damage is significant: intellectual property theft, reputational harm, regulatory violations, and compromised national security.
At Strider, we recognize that the insider threat challenge is no longer limited to disgruntled employees or lone actors. Increasingly, these risks are linked to state-sponsored efforts that target organizations through talent recruitment, supply chain infiltration, and research partnerships. Our products are designed to give organizations the visibility and intelligence they need to identify these risks early, mitigate vulnerabilities, and protect what matters most.
In this blog post, we’ll explore how Strider’s suite of products empowers organizations to protect against insider threats by uncovering hidden affiliations, mapping risky connections, and delivering actionable intelligence.
Understanding the Modern Insider Threat
Traditional security models focused on access control and monitoring system anomalies. While these remain important, they fall short when insiders are recruited or influenced by foreign adversaries. For example, researchers may be courted by state-backed talent recruitment programs that encourage them to transfer cutting-edge innovations abroad. Or an employee may conceal ties to a foreign military entity during the hiring process.
These risks are especially acute in sectors like defense, high tech, energy, and academia—where sensitive intellectual property is both highly valuable and highly targeted. The challenge is that many of these threats do not leave digital fingerprints in the early stages.
Instead, they are rooted in affiliations, backgrounds, and institutional relationships that require deep analysis of open-source intelligence and proprietary data.
This is where Strider’s products deliver unmatched value.
People Search: Uncovering Hidden Affiliations
When hiring, vetting researchers, or evaluating collaborators, organizations often rely on self-disclosed resumes and standard background checks. Unfortunately, these methods are often insufficient when individuals deliberately conceal foreign ties.
Strider’s People Search addresses this gap by aggregating and analyzing open-source intelligence to uncover connections to high-risk entities, such as foreign intelligence services, governments, and militaries. With this capability, organizations can:
- Detect undisclosed affiliations: Identify if an applicant or employee is linked to state-sponsored talent programs or research institutions affiliated with adversarial nations.
- Verify credentials: Through Falsified Resume Screening, ensure that the applicant is who they are purporting to be and haven’t applied with a fraudulent persona. This is especially relevant for organizations concerned about unwittingly hiring remote workers from the DPRK.
- Ensure transparency: Build confidence that no hidden affiliations threaten sensitive projects.
By enabling proactive screening, People Search helps organizations ensure trust in their workforce and avoid inadvertently granting access to individuals who may pose an insider threat.
Organizations Search: Securing the Supply Chain and Partnerships
Insider threats don’t always come from direct employees. Contractors, research partners, and suppliers can serve as entry points for state-sponsored influence. Often, affiliations are hidden in complex ownership structures or through partnerships with universities and institutes that serve as fronts for foreign militaries.
Strider’s Organizations Search empowers leaders to understand these hidden relationships within their organizations. Specifically, the Organizations Search tool reveals:
- Risk profiles of organizations.
- Ownership and subsidiary structures that link vendors or partners to adversarial governments, shown in a network view.
- Board memberships and leadership ties to sanctioned or restricted entities.
- Connections to banned talent programs or institutes like Confucius Institutes.
For example, before entering into an academic collaboration, a university can use Organizations Search to determine whether a foreign partner has ties to a hostile nation. By making these risks visible, Organizations Search prevents insider threats from entering through seemingly trusted third parties.
Open Source Software Search: Protecting the Software Supply Chain
Insider risks also extend to the software ecosystem. With open source software now serving as the foundation of many mission-critical systems, organizations face growing exposure if contributors to their code base have risky affiliations.
Strider’s Open Source Software Search (OSS Search) screens contributors across an organization’s software supply chain. By analyzing repositories and contributor backgrounds, OSS Search uncovers:
- Hidden links between open-source contributors and adversarial nation-state entities.
- Dependency risks that could create vulnerabilities in critical systems.
- Potential insertion of malicious code or data exfiltration mechanisms.
In an era where a single compromised software library can ripple across industries, OSS Search adds a critical layer of defense against insider threats buried in code.
Insights: Strategic Intelligence for At-Risk Teams
While detection and screening are essential, insider threat mitigation also requires a proactive approach to awareness and resilience. That’s where Strider’s Insights—our advanced intelligence—comes in.
Insights provides organizations with tailored strategic intelligence about which research areas, technologies, or people are most likely to be targeted by foreign adversaries. This intelligence enables organizations to:
- Protect researchers and innovators: Identify which faculty or employees may be under surveillance or recruitment efforts.
- Deliver targeted training: Equip at-risk staff with knowledge of espionage tactics and best practices to safeguard data.
- Enhance travel security: Brief personnel before international travel on surveillance risks and protective measures.
By shifting the conversation from reactive to proactive, Insights ensures organizations can anticipate and blunt insider threat recruitment before it succeeds.
Shield: Real-Time Detection in Digital Systems
Insider threats often communicate with foreign sponsors through digital channels, blending into the noise of everyday email and network traffic. To help organizations spot these signals, Strider developed Shield.
Shield delivers a curated, expert-verified dataset of high-risk email addresses, domains, and multilingual keywords associated with state-sponsored actors. Integrated via API into an organization’s SIEM or DLP system, Shield enables:
- Real-time detection: Existing systems, layered with Strider’s dataset, can spot and block suspicious communications and activities linked to known adversaries.
- Reduced false positives: Data is curated to minimize noise so analysts can focus on what matters.
- Continuous updates: Monthly refreshes ensure organizations stay ahead of evolving threats.
By integrating Shield into existing systems, organizations gain a powerful capability to detect when insiders are engaging with adversarial entities.
Building a Comprehensive Insider Threat Defense
The insider threat problem is multi-faceted: it spans people, partnerships, software, and communications. Strider’s holistic approach ensures that organizations can address these risks from every angle:
- People Search builds trust in the workforce.
- Organizations Search secures partnerships and supply chains.
- OSS Search protects the software ecosystem.
- Insights equips people and institutions with proactive defenses.
- Shield enables real-time detection in digital systems.
Together, these tools give organizations the visibility and intelligence to detect risks early, respond decisively, and stay compliant with regulations. More importantly, they empower leaders to safeguard their people, technology, and intellectual property from insider threats driven by state-sponsored actors.
Spark, Strider’s proprietary AI engine, is layered onto each existing product. With Spark, organizations have the ability to security integrate internal DLP data with Strider’s AI risk intelligence for deeper, data-driven risk insights. It also features an intuitive chat interface with real-time analysis and query, suggested searches, multilingual data input, and sourcing for original intelligence sources.
Insider threats will never be fully eliminated—but they can be managed. The key is understanding that these risks are not random but often deliberate, coordinated efforts by nation-state actors. By shining light on hidden affiliations, risky partnerships, and subtle recruitment efforts, Strider helps organizations take back control.
With Strider’s products, insider threat protection becomes less about suspicion and more about clarity. Organizations gain the confidence to collaborate, innovate, and grow—knowing they are protected by intelligence built for the modern era of geopolitical competition.
We’re excited to announce a major milestone in Strider’s growth: the evolution of our Strategic Intelligence Platform along with refreshed product names that reflect this transformation.

As nation-state threats become increasingly complex and consequential, organizations need more than isolated tools to safeguard their critical assets. They need a unified platform that delivers strategic context and actionable insights with speed. Our Strategic Intelligence Platform is designed to do exactly that. It brings together world-class data, cutting-edge products, and patented AI tools to help industry, government, and academia identify and mitigate state-sponsored threats, protect innovation, and navigate a fast-changing geopolitical landscape.
One Platform. Clearer Names. Deeper Insight.
With this platform launch, we’ve taken an important step in aligning our product names with the holistic intelligence they deliver:
- Insights (formerly Ranger): Consolidates analyst-curated intelligence on personnel, technologies, and organizational connections targeted by nation-state actors. Designed to accelerate proactive decision-making and drive strategic action.
- People Search (formerly Sentry): Identifies individual connections to state-sponsored threats, helping organizations efficiently vet internal teams and external partners .
- Organizations Search (formerly Checkpoint): Illuminates third-party risk across supply chains, partners, and subsidiaries—uncovering nation-state hidden ties to help organizations make better decisions and secure with confidence.
These new names doesn’t just improve clarity, it reflects a deeper theme: these aren’t individual tools. Together, they form a strategic whole that is connected by shared data, a risk methodology built for state-sponsored threat detection, and a singular mission to protect critical assets in the global competition for knowledge, talent, and innovation.
Why Strategic Intelligence Matters Today
In a world where nation-state actors are targeting critical assets—from intellectual property to research partnerships—strategic intelligence is no longer optional. It’s essential.
Strider’s intelligence goes beyond raw data. It gives users the foresight to identify state-sponsored threats early, the clarity to act decisively, and the confidence to protect long-term priorities. Whether you’re a private company safeguarding innovation, a government agency monitoring foreign influence, or a university preserving research integrity, Strider delivers the intelligence you need to turn uncertainty into action.
And this is just the beginning. These product updates mark the next step in our commitment to provide faster insights, deeper visibility, and greater strategic value. As the threat landscape evolves, so will our platform, ensuring you stay ahead of today’s most complex and consequential risks.
Ready to Dive Deeper?
If you’re a current Strider client, we’ve created a change management guide to help your team navigate the new product names and fully leverage the power of Strider’s Strategic Intelligence Platform. Reach out to your Client Success Manager (CSM) to get the guide and walk through the updates together.
If you’re exploring Strider for the first time, now is the perfect moment to see how our platform can help you identify risks, secure innovation, and stay ahead of state-sponsored threats.
Get a demo of the Strategic Intelligence Platform and see how your organization can benefit.
Russia launched its full-scale invasion of Ukraine on February 24, 2022, initiating one of the largest conflicts in Europe since World War II. This war, which has lasted far longer than many experts anticipated, has led to widespread international condemnation and a significant humanitarian crisis.
Over the past three years, Russia’s technology sector has fallen behind, and the Kremlin is now resorting to increasingly nefarious tactics to close the gap and achieve “technological sovereignty”—its ability to develop, control, and maintain its own critical technologies and technological infrastructure without relying on foreign countries or multinational corporations.
This concept has gained increasing importance for Russia, especially in the context of geopolitical tensions, economic sanctions, and its efforts to insulate its economy and national security from external influence.
In this article, we’ll talk about the drivers behind Russia’s technological stagnation, four areas where they’re adapting their tactics, and the steps your organization can take to protect your own technology.
For a deeper dive, though, download “Navigating the New Geopolitical Reality”—a comprehensive white paper written by Strider’s Global Intelligence Unit about Russia’s evolving strategy.
Russia adapts economic espionage tactics in Europe
Its ongoing war with Ukraine has been devastating to Russia’s technology sector, which continues to lag further behind the West.
- Because of sanctions, export controls, and visa restrictions imposed by the United States and its allies, Russia has struggled to acquire critical technologies—such as quantum computing, additive manufacturing, and augmented reality.
- The expulsion of more than 700 Russian officials from countries throughout Europe has also significantly reduced the number of personnel able to engage in espionage throughout the continent.
- Since the invasion, around one million Russians—most of them young and well-educated, who would have contributed to Russia’s advanced industries—have fled the country. Additionally, it’s estimated that Russia has lost around 50,000 scientists to emigration since 2019.
As a result, Russia is adapting its strategies to navigate economic isolation and sustain its technological edge. This includes a growing reliance on individuals operating under non-official cover—such as oil and gas workers, professors, and other professionals—who may utilize social media platforms like LinkedIn to connect with targets in Europe and the United States.
This means that private companies are now being subjected to greater risk from Russia and other adversarial nations.
The Kremlin ramps up reverse-engineering efforts
After Russia invaded Ukraine, many firms chose to close up shop in Russia and move elsewhere. Likely as a form of retribution against those firms, Russian president Vladimir Putin directed the government to use funds from the “exit tax” imposed on foreign companies leaving Russia to finance reverse-engineering initiatives.
As a result, since 2022, the Russian government has funneled at least $110 million USD into projects focused on imitating Western-made products. This push toward imitation technology has raised concerns that foreign companies may face increased competition from Russian knockoffs in markets favorable to Russia, such as India.
The Russian government is seeking to reverse engineer hundreds of products manufactured by leading American and European companies, including integrated circuits, chemical compounds, automotive parts, and engines, and weapons systems.
Russia leverages relationships for “gray zone” operations
“Gray zone” activities—such as arson, attempted bombings, vandalism, cyberattacks, propaganda and misinformation, territorial encroachment, and other disruptive actions—generally fall between traditional states of peace and war. These actions, in which Russia has been heavily involved, are often ambiguous, covert, or non-traditional, designed to achieve strategic objectives without crossing thresholds that would typically provoke a formal military response or war.
The Russian government has reportedly been analyzing online profiles of individuals in Europe to identify those who may be susceptible to manipulation by the Kremlin—and then using them to target infrastructure and organizations (especially those providing support to Ukraine) as part of a broader campaign intended to create chaos and undermine NATO and EU cohesion.
The European Union has increased export prohibitions in an attempt to punish Russia for evading sanctions
Starting in January 2025, new prohibitions on exports to Russia will raise compliance burdens and risks for businesses based in the European Union (EU).
Since the war started in 2022, the EU and its allies have implemented hundreds of sanctions aimed at limiting Moscow’s access to foreign technology necessary to sustain the war. These sanctions, however, are notoriously difficult to uphold, and third-party countries continue to play a key role in helping Russia evade them. According to Ukraine’s military intelligence agency, there has been no significant change in the flow of foreign components to Russia.
Read more about how companies with ties to Russia—including some within Ukraine—pose a risk to Western organizations.
What can you do to mitigate risk for your organization?
This complex environment requires more than traditional due diligence or surface-level risk assessments. Organizations must have a comprehensive understanding of how state actors—like Russia—manipulate supply chains, leverage global networks, and exploit access to sensitive technology.
Strider’s Organizations Search provides unparalleled visibility into complex supply chains, uncovering hidden connections to state-sponsored actors and high-risk entities. This is especially critical in the context of Russia’s evolving tactics to acquire foreign technology despite extensive sanctions.
Competing Governments and Global Economic Risks
Today, many governments are using their international economic relationships to achieve their own strategic goals. Sometimes, this comes at the expense of their global partners. Countries like the PRC, Russia, and Iran often put this strategy to use to further their own technological interests, making it harder for businesses and academic institutions worldwide to protect themselves from these risks.
That’s why Strider created Organizations Search, our third-party due diligence tool for security, compliance, and reputational insights.
Huge Organizations Search Data Expansion
This month, we’re excited to announce some major improvements to Organizations Search. These new milestones significantly contribute to our vision of Organizations Search being a comprehensive risk screening solution for strategic state-sponsored intervention in the global economy.
Most notably, Organizations Search now includes government registration records for 200 million legal entities located in the United States, Canada, Europe, and Japan. Integration of this data into Organizations Search reflects the rapid maturation of Strider’s ability to illuminate risky economic connections around the world, not just within regions of special concern.
In the coming year, we’ll be adding even more data sources related to cross-border trade, ownership, and other economic relationships. With these updates, our clients will gain an even deeper understanding of which organizations might pose a risk due to their economic connections. After all, state-sponsored actors don’t limit themselves to their home countries—they own, trade with, and collaborate with millions of organizations around the world. Our clients know this and are looking for scalable solutions to manage these risks.
New Data from Russia and Iran
We’re also excited to announce two new data additions specifically focused on Russia and Iran.
First, we’ve added over 5 million supplier relationships from Russian government procurement records. This data shows which commercial firms in Russia have contracts with military, defense, and government end users. Understanding these connections can help our users identify companies with economic incentives to align with Russian government priorities.
Second, we’ve added 2 million legal entities from Iran’s business registration system. This will help our users gain more insights into businesses operating in that often opaque region.
Looking Ahead
In today’s unpredictable globalized business environment, this type of comprehensive due diligence is more critical than ever before.
These updates are just the beginning. We have many more exciting data expansions and features planned for Organizations Search in the coming months. These enhancements will further empower our users to screen broadly and deeply for state-sponsored risks within their global economic footprints.
Learn more about Organizations Search here.
Request a demo to see what insights Organizations Search can unlock for your organization.
In academia and innovation, the integrity and security of research not only propel the boundaries of knowledge but also safeguard the interests of national security. Strider, through its meticulous gathering of open-source data and strategic intelligence, stands at the forefront of ensuring that research institutes thrive in a complex landscape with security at the core of their efforts.
Research Security as National Security
The interconnectedness of global research initiatives has undeniably spurred innovation at an unprecedented scale. However, this openness has also introduced vulnerabilities that foreign entities, governments, or individuals exploit, casting a shadow over the integrity of research endeavors. The U.S. government’s growing apprehension towards such influences underscores a crucial equilibrium—one where research security and international collaboration must coexist without compromising the other.
Instances of these concerns range widely, from the inadvertent sharing of proprietary information and intellectual property to the non-disclosure of substantial foreign support. These are not mere administrative oversights but potential breaches of national security. Thus, ensuring research integrity is more critical now than ever, demanding a vigilant and proactive stance against such influences.
Many Faces of Research Security Breaches
The National Science Foundation (NSF) regularly provides examples of the various types of research security breaches to highlight the myriad ways they occur and bolster efforts to identify and mitigate these threats. Below are two case studies NSF recently shared:
Case Study 1
A striking example involves an NSF-funded principal investigator who, unbeknownst to their U.S. organization, participated in a foreign talent program while holding a faculty position abroad. This case escalated when the investigator failed to disclose foreign affiliations and funding, a requirement by NSF’s standards. The repercussions were severe—suspension of awards, resignation, and eventual government-wide debarment. This case underscores the critical need for transparency and adherence to funding guidelines.
Case Study 2
Another case saw a professor exploiting federal grants for research already conducted overseas. The breach involved not just the misallocation of funds but also an active effort to obstruct investigations by submitting falsified documentation. The subsequent criminal conviction of the professor highlights the rigorous measures taken to uphold research integrity and security.
Using Data to Protect Data
At Strider, our approach to safeguarding research and fostering secure international collaborations is rooted in strategic intelligence. This intelligence is sourced from a comprehensive collection of critical open-source data, which is then augmented by proprietary data processing methodologies. Our suite of products and services is tailored to preemptively identify and mitigate risks, ensuring the integrity of your research endeavors.
Insights stands as our flagship offering, empowering organizations to discern and protect against pursuits by foreign governments. It identifies which of your technologies and research topics are at risk of being targeted by foreign governments. It also illuminates any connections to sanctioned, restricted, or state-owned entities your employees—including researchers—may have. With Insights, you can ensure individuals working on specific research have disclosed appropriate information and connections beforehand.
People Search facilitates instantaneous due diligence, screening for potential state-sponsored risks among researchers and visitors. Its sophisticated identification process illuminates connections that might pose security risks in areas including restricted government and military entities, as well as industry and education associations.
Organizations Search enables third-party due diligence for security risks before collaboration and partnership. It reveals connections that third-party partners may have with restricted or high-risk entities, including foreign government, defense, research, or military institutions.
Shield is an email security tool that offers protection against covert attempts by state-sponsored actors to solicit your researchers and employees. By providing an ever-growing list of verified email addresses, domain names, and key words directly linked to such actors, you can be alerted when anyone in your organization is approached.
Conclusion
In an era when the geopolitics of research security are continually evolving, Strider helps research institutes be better equipped to safely navigate state-sponsored risk with critical strategic intelligence. Reach out to a Strider representative today to see how you can better enhance security in your organization.