Fake IT Workers: When the Hire Is the Breach
North Korean fake IT workers have infiltrated hundreds of companies. How the hiring-fraud pipeline works — and how to vet remote candidates before day one.

Every security awareness program teaches employees to distrust strangers: unexpected emails, unknown callers, unfamiliar links. Almost none of them prepares the organization for the stranger who arrives through the front door — interviewed, referenced, background-checked, and issued a laptop and credentials on day one.
That is exactly the gap state-sponsored hiring fraud exploits. Over the past three years, North Korea has industrialized the practice of placing its own operatives inside Western companies as remote software developers and IT staff. The scheme funds a sanctioned regime, and for the employer it collapses several risk categories into one person: an insider threat with legitimate access, an APT with a salary, and a compliance violation drawing payroll. The uncomfortable conclusion for security leaders: your hiring pipeline is now an attack surface, and almost nobody owns its defense.
From oddity to industrial scale
When the first cases surfaced, they read like curiosities. The current numbers read like a campaign.
CrowdStrike's 2025 Threat Hunting Report documented more than 320 incidents in a single year of the DPRK-linked group it tracks as FAMOUS CHOLLIMA obtaining remote employment under false identities — a 220% year-over-year increase. Its threat hunters described operatives using generative AI at every stage of the operation: drafting resumes, answering interview questions, masking appearance on video calls, completing coding assignments, and juggling three to four jobs at once.
A year later the picture had escalated further. CrowdStrike's 2026 technology-sector analysis, reported by TechCrunch, attributed 47% of state-backed activity targeting tech companies between April 2025 and May 2026 to the same North Korean program — hands-on-keyboard intrusions conducted by people the victims were paying.
Nor is this only a nation-state story. The tooling that makes the scheme work — AI-written resumes, synthetic profile photos, real-time video filters — is available to any fraudster, and Gartner projects that by 2028 one in four candidate profiles worldwide will be fake. Whoever is on the other end, the defensive problem is the same: can your organization verify that the person you hired is the person doing the work?
Anatomy of the scheme
The operation is a pipeline, and each stage defeats a different corporate control.
It starts with a synthetic identity: stolen or rented personal data of a real person in the target country, combined with an AI-generated or AI-enhanced profile photo and a fabricated work history. That identity applies — at volume — for fully remote developer, DevOps and IT support roles. Interviews are passed with live AI assistance, and in a growing share of cases with real-time deepfake video that wraps the operative's face in the claimed identity's likeness.
Then comes the stage most defenders have never heard of. The new hire cannot receive a corporate laptop in Pyongyang or northeastern China, so the machine is shipped to a domestic address belonging to a paid facilitator — a laptop farm, an apartment where dozens of corporate laptops from different victim companies sit powered on and connected, fitted with remote-access software so the operative abroad can work "from" a plausible IP address in the right time zone.
The scale of that logistics layer became public in July 2025, when the US Department of Justice sentenced Christina Chapman to more than eight years in prison for running a laptop farm out of her Arizona home. Her operation alone serviced overseas workers who defrauded 309 US businesses using the stolen identities of 68 Americans, generating over $17 million in illicit revenue for the DPRK — from a single facilitator.
| Hiring stage | What the fraud looks like | The tell |
|---|---|---|
| Application | AI-polished resume, cloned portfolio, stolen identity that clears a name-based background check | Work history that no former colleague on LinkedIn can vouch for; identical resume text appearing under multiple names |
| Interview | AI-assisted answers; deepfake or filtered video; "camera problems" | Lip-sync lag, refusal to move hands near the face on request, answers that arrive fluent but delayed |
| Onboarding | Laptop shipped to a facilitator's address, not the claimed residence | Last-minute shipping address changes; address tied to other employees or known farms |
| Employment | Work done over remote-access tools; several concurrent jobs | Persistent VPN plus consumer remote-desktop software; mouse-jiggler artifacts; no-show at any in-person event |
Sixteen minutes at KnowBe4
The clearest public case study comes, ironically, from inside the security industry. In July 2024, security awareness vendor KnowBe4 disclosed that it had hired a fake North Korean IT worker as a software engineer. The candidate used a stolen US identity and an AI-enhanced stock photo, and passed four video interviews plus a background check. The moment the corporate Mac reached its shipping address and came online, it began loading infostealer malware. Endpoint detection flagged the activity within minutes, the SOC contained the device, and no data was lost.
Two lessons sit in that story. The first is sobering: a company whose entire business is detecting social engineering was socially engineered by a job application — four humans interviewed the operative and every one was convinced. The second is encouraging: layered controls worked. Hiring fraud does not need to be caught at the interview to be caught; it needs to be caught before harm, and instrumented endpoints, least-privilege onboarding and an alert SOC bought exactly that.
The fake IT worker collapses your threat model: an insider threat with valid credentials, an APT with a salary, and a sanctions violation on payroll — all hired through your own process.
What happens after day one
While undiscovered, the operative's first product is payroll — salaries wired, in aggregate, to a sanctioned weapons program. But the FBI warned in January 2025 that the program has turned more aggressive: operatives copy company source code to personal cloud accounts, harvest credentials and internal data, and — once caught and fired — extort their former employer with the stolen material. Some have held code hostage; others have leaked it. The 2025 activity CrowdStrike tracked included credential theft and ransom demands, and North Korean operations in total stole roughly $2 billion in cryptocurrency in 2025 alone.
That changes the response playbook. A suspected fake worker is not an HR problem to be handled with a termination letter — it is a live intrusion. Security should quietly assess the account's access and recent data movement before HR acts, so that revocation, evidence preservation and laptop recovery happen in one coordinated step rather than tipping off the operative mid-exfiltration. Much of that discipline already exists in a good offboarding process; this scenario simply demands it executed at incident-response speed.
Hardening the hiring pipeline
The defense is not one control but friction at every stage the scheme must pass.
1. Verify identity, not just history. A name-based background check validates that an identity exists — not that the candidate owns it. Add document-based identity verification with a liveness check for remote hires in sensitive roles, and repeat it at onboarding: the person who shows up on day one should be the person who interviewed.
2. Make cameras non-negotiable and add light friction. Require video interviews on camera. Simple, polite requests — turn your head, raise a hand in front of your face, hold up ID — defeat most current real-time face-swap tooling, which still struggles with occlusion. Persistent camera refusal across multiple rounds is itself a finding.
3. Interrogate the logistics. Ship equipment only to the verified home address, flag last-minute changes, and reconcile the address against payroll, tax and I-9 records. Check first-login geolocation and network fingerprints against the claimed location, and alert on consumer remote-access tools appearing on a brand-new hire's machine.
4. Onboard with least privilege. New hires do not need broad repository, production or customer-data access in week one. Staged access limits the blast radius of a bad hire — the reason KnowBe4's incident ended at sixteen minutes rather than sixteen weeks was restricted initial access plus endpoint monitoring.
5. Train the people who hire. Recruiters, hiring managers and IT onboarding staff are targets of social engineering just as surely as finance teams facing deepfake voice fraud — but almost no awareness program includes them. Brief them on the scheme, give them a reporting path for "something felt off," and treat a suspicious candidate report like a phishing report: fast feedback, no blame. Role-specific coverage like this is exactly what a human risk management program means by measuring and training the roles that face the risk, not the average employee.
6. Rehearse the discovery scenario. Add "we think employee X is not who they claim" to your tabletop rotation, with HR, legal and security at the same table. The FBI's guidance and your own extortion playbook should be tested before you need them.
Hiring is now an attack surface
Security teams spent a decade teaching the workforce that identity is the perimeter. Hiring fraud is the logical next move: if stolen credentials are getting harder to use, apply for real ones. The organizations that handle this well will be the ones that treat recruiting, onboarding and IT provisioning as part of the security program — measured, trained and rehearsed like any other high-risk workflow, and reflected in how they quantify human risk across roles. The ones that handle it badly will keep discovering, months late, that their most productive remote developer never existed.
Frequently asked questions
How do fake IT worker schemes actually work?
Operatives build synthetic candidate identities from stolen personal data, AI-generated photos and fabricated work histories, then apply for fully remote engineering and IT roles. Interviews are passed with AI assistance and sometimes real-time deepfake video. Once hired, the company laptop is shipped to a domestic address that is actually a laptop farm — a facilitator's home running dozens of corporate machines — while the worker operates from abroad over remote-access tools, drawing a real salary and holding real credentials.
How common is fake IT worker fraud?
It has moved from anecdote to industrial scale. CrowdStrike's 2025 Threat Hunting Report documented more than 320 incidents of North Korean operatives obtaining remote jobs in a single year — a 220% year-over-year increase — and its 2026 technology-sector analysis attributed 47% of state-backed activity against tech companies to the same program. Gartner projects that by 2028 one in four candidate profiles globally will be fake.
What are the red flags during hiring?
The strongest signals cluster around identity friction: reluctance to appear on camera or subtle lip-sync lag when they do, a shipping address that does not match the claimed residence or repeated last-minute address changes, VoIP-only phone numbers, inconsistencies between resume, LinkedIn history and background check, and candidates who excel in asynchronous coding tests but stumble when asked to reason live about their own claimed experience.
What should we do if we think we already hired a fake IT worker?
Treat it as an active intrusion, not an HR matter. Involve security before HR acts: quietly review the account's access and data movement, preserve evidence, then disable access and recover the laptop in one coordinated step. Expect extortion — the FBI warned in January 2025 that discovered operatives increasingly exfiltrate code and internal data and demand ransom after termination. In the US, report the case to the FBI's Internet Crime Complaint Center.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo