How to catch a North Korean IT worker before you hire one

The scheme runs on stolen identities and AI-assisted interviews.

6 Min Read

North Korean IT worker fraud is a state-directed employment scheme in which operatives use stolen identities and AI-assisted interviews to get hired into remote IT roles at U.S. and European companies, then route the wages back to Pyongyang. Most of the signals that expose it, however, live not in security monitoring tools but in HR files, shipping records, and payment logs.

A campaign our Risk Operations Center just tracked

Resilience’s Risk Operations Center — the ROC — identified an active Democratic People’s Republic of Korea (DPRK) hiring campaign this month running across a number of client and prospective-client accounts. The ROC contacted every affected company directly to ensure each was aware and able to act. Most reported that the candidate hadn’t advanced past early screening to an offer. Results vary by account, but the campaign still reached well into real hiring pipelines, and AI-assisted interviews help explain why.

The program is controlled by North Korea’s Reconnaissance General Bureau, and it exists mainly to generate hard currency for the regime. The FBI, the State Department, and the Treasury Department warned in their May 2022 guidance on North Korean IT worker threats that individual operatives had earned up to $300,000 a year under the scheme as of 2022, with the broader program generating hundreds of millions annually for entities including North Korea’s Ministry of Defense and its weapons programs.

Job stacking (a single operative holding several full-time remote positions at once) multiplies the effect even further. And some operatives go beyond wage extraction entirely, exfiltrating proprietary data or extorting employers after they’re let go.

How operatives get past your hiring process

Getting hired is the hard part, and the tactics are built specifically to survive it. Operatives use purchased or stolen U.S. and European identities, and AI voice and video tools now stand in for parts of the interview itself, passing background checks and video calls that used to be a reliable filter. Local facilitators in the target country run what the FBI calls “laptop farms,” hosting company laptops at a U.S. residence or storefront so that an overseas worker can log in from a domestic IP address and bypass geolocation controls. Operatives route wages to third-party accounts, money-transfer platforms, or cryptocurrency wallets rather than to the name on the employment paperwork.

Federal investigators have treated the laptop farm as central to the fraud for years. In a June 2025 release announcing coordinated nationwide actions against the scheme, the Justice Department detailed a search of 29 known or suspected laptop farms across 16 states, the seizure of 21 fraudulent websites and 29 financial accounts used to launder the money, and confirmation that operatives had used the scheme to land positions at more than 100 U.S. companies.

Hiring a North Korean national, knowingly or not, creates direct exposure to U.S. and UN sanctions for the company that signed the offer letter, regardless of whether HR or the hiring manager had any reason to suspect fraud at the time. The Justice Department has continued to escalate its response since then. The November 2025 announcement of nationwide actions against the scheme’s revenue generation is part of a joint National Security Division and FBI effort called the DPRK RevGen: Domestic Enabler Initiative, specifically designed to prosecute the domestic facilitators who host these laptops and launder wages. That’s the detail that should get legal into the conversation the moment a real red flag surfaces, not after it’s confirmed.

Where the signals show up across the hiring lifecycle

While your threat team is usually tasked with monitoring for any type of intrusion, the FBI’s public alert on North Korean IT worker threats to U.S. businesses (2025), along with guidance from the Cybersecurity and Infrastructure Security Agency (CISA), the State Department, and allied agencies, lays out red-flag indicators spanning the entire hiring and employment lifecycle. And from the first interview to the first paycheck, most of them are visible to people who aren’t in security. Instead, it’s HR and logistics who need to be on the lookout for the following signals.

Interviews and onboarding

Watch for camera avoidance or video artifacts, such as blurred backgrounds, motion that doesn’t track naturally, or audio that lags the mouth, any of which can point to an AI voice or video tool standing in for the real interviewee. Proxy interviewing shows up, too, where the person on camera can’t answer basic questions about their own resume or impromptu questions about the supposed locale, and identity documents sometimes don’t match the name on file elsewhere in the application.

Network and account access

Once someone has system access, the pattern appears in the logs. Remote desktop tools such as AnyDesk or TeamViewer, or a commercial VPN, can mask an overseas IP address behind a domestic-looking login. Concurrent sessions from locations that are geographically impossible, or an account that stays active for improbably long stretches, are both worth a closer look. So are logins that trace back to IP addresses your identity provider or security monitoring system (SIEM) has already flagged as known proxies.

Hardware and shipping

This is one of the hardest signals to fake, because it requires a real address. A company laptop shipped to a residential address or a commercial drop box that doesn’t match the employee’s stated location is one of the clearest indicators of a laptop farm. Insistence on using a personal device instead, or any attempt to route corporate equipment overseas after the fact, are two more great indicators.

Payment and behavior

Salary directed to a money-transfer platform or a cryptocurrency wallet, rather than via direct deposit under the employee’s legal name, is a financial red flag on its own. The same goes for a resume, GitHub repository, or set of banking details that appears identically across multiple contractor profiles on the same hiring platform. And watch for anger or pressure when advance pay or unusual compensation terms get denied, since legitimate contractors rarely push that hard.

What to do when you spot one

A name match by itself doesn’t confirm anything. Corroborate it against the applicant’s stated start date, job title, and the site where the position was posted before drawing any conclusion, whether or not that match appears in an HR file or an applicant tracking system.

If the person is already hired, treat it as a potential active insider threat rather than a routine personnel issue. Don’t confront the employee directly. Loop in security and legal without tipping them off, preserve the onboarding records (identity documents, laptop shipping address, and payroll and banking details), and review what systems and data the account touched. Report it to the FBI (or the international equivalent) either through a local field office or via IC3.gov, the FBI’s Internet Crime Complaint Center.

If the person wasn’t hired, preserve all application records, block further contact, and report the incident to federal authorities, as this information might assist law enforcement in tracking this campaign.

Building this into how you hire

Enforcement against this scheme has expanded every year since the first federal advisory in 2022, and the fraud keeps adapting, particularly on the AI side of the interview process. The practical response is a standing check built into remote hiring, IT provisioning, and payroll setup, much like how identity verification became routine after the last wave of hiring fraud.

Common questions about North Korean IT worker fraud

What is North Korean IT worker fraud?

North Korean IT worker fraud is a state-directed scheme in which North Korean operatives use stolen or fabricated identities to get hired into remote IT jobs at foreign companies, then send the wages back to fund the regime, including its weapons programs.

Can a company be held liable for unknowingly hiring a North Korean IT worker?

Yes, you may be held liable for unknowingly hiring a North Korean IT worker. Sanctions exposure attaches to the hire itself, not to whether the company knew who it was hiring, which is why legal counsel needs to be involved as soon as a credible red flag appears.

Why is a mismatched laptop shipping address hard to fake?

A company laptop shipped to an address that doesn’t match where the employee says they live requires a real, physical location, something a scripted interview or a stolen identity document can’t produce.

Are AI tools making this harder to detect during video interviews?

Yes, AI tools are making it harder to detect North Korean hiring scams during video interviews. Voice and video tools now stand in for real interviewees in some cases, defeating a step that used to filter out fraudulent applicants. That’s shifting more of the detection burden onto network, hardware, and payment signals after someone’s hired.

What should a company do if it thinks it’s already hired someone tied to this scheme?

If you think you’ve already hired someone tied to this scheme, treat it as a potential active insider threat. Don’t confront the employee. Bring in security and legal, preserve the onboarding and access records, and report it to the FBI (or international equivalent) through a local field office or IC3.gov.

Which industries are being targeted?

Public reporting from threat-intelligence vendors, including Cyble (“Threat Actor Profile: WageMole”) and BrandDefense (“Inside WageMole: North Korea’s Fusion of Cybercrime and Espionage,” 2025), shows North Korean hiring scams affecting companies across sectors and sizes, rather than concentrating in one industry, though some industries and characteristics are likely more appealing than others, e.g., technology and financial services (especially cryptocurrency-adjacent services), with weaker verification processes and a remote-first workforce.

Nothing here should be taken as legal, financial, or security advice for your specific situation — see the full disclaimer at cyberresilience.com/disclaimer.