The September 18 multinational advisory assesses WaterPlum and some DPRK IT workers under the 313 General Bureau. It reports some actor overlap and shared IPs used for laptop-farm access and other services. It does not establish that every recruiter lure and fraudulent hire is one operation.
The operational problem is mundane: HR validates the named worker, IT ships a laptop, engineering grants repo access, and finance approves payment. Four normal tickets; no single view of the engagement. A high-access contractor with an independent identity, device, session, or payee inconsistency merits a joint review before privilege expands. That is a threshold for verification, not a nationality or VPN-IP test. Give the person a fair way to resolve discrepancies.
The article lays out the escalation and ownership model.