Investigations found suspected North Korean operatives getting hired into real companies by impersonating other people, including roles outside IT such as healthcare and sales/marketing. The workflow relies on fake or stolen identity documents, remote-access tooling, and deception during interviews and onboarding, creating an insider-risk pathway that can bypass traditional “hacking” defenses.
How the scheme operates
Investigators have found suspected North Korean operatives obtaining real jobs by impersonating other people, using stolen or forged identity documents and VPN or proxy services to hide their true location. This is not limited to IT roles anymore. Cases now include healthcare and sales and marketing positions, showing the fraud model is being applied more broadly across industries such as healthcare, financial services, software and technology, staffing and consulting, and government.
The workflow spans the entire employment lifecycle. It starts with fabricated or synthetic personas used to apply for jobs, continues through interviews where AI tools may be used to generate answers in real time, and persists after hiring through remote-access tooling and requests to bypass normal device and payroll policies.
Why it succeeds
This approach works because it targets human and process gaps rather than technical defenses. Traditional security controls are built around detecting intrusions, not around verifying that a new hire is who they claim to be. Interviewers are not typically trained to detect AI-assisted answers or synthetic personas, and onboarding teams may not scrutinize proof-of-residence documents or identity paperwork closely enough to catch small anomalies. Once someone is hired, they gain legitimate access, credentials, and trust, effectively bypassing the defenses organizations build against outside attackers.
What to watch for
- Proof-of-residence documents with unusual wording or formatting anomalies
- Identity documents that look duplicated or unusually similar across different candidates or hires
- Repeated use of VPNs or proxies during onboarding and early employment
- Interview answers that sound copied verbatim or unnaturally generic
- Requests to use personal devices or personal bank accounts for work-related tasks
- Unusual coordination through external chat tools alongside frequent changes to payroll or profile details
Building resistance
Organizations can treat hiring and onboarding as a security control rather than purely an HR function. This means training interviewers and HR staff to spot AI-assisted interviewing and fabricated personas, performing rigorous identity and background verification before onboarding, and applying extra scrutiny when remote candidates present inconsistent signals. It also means enforcing standard processes for any changes to payroll details or work devices, since deviations from policy are a recurring pattern in these cases. Because this activity is described as an ongoing and scalable operation, continuous awareness and monitoring across HR, IT, and finance teams is more effective than a one-time check.
Key findings
- DPRK-linked actors are expanding fraudulent employment beyond IT into sales/marketing and the medical profession.
- The scheme involves impersonating real people using stolen/forged identity documents and masking location with VPNs/proxies during onboarding and employment.
- In one healthcare case, multiple red flags surfaced during onboarding, including repeated VPN/proxy use, suspicious identity docs, and anomalies in bills used as proof of residence.
- In a financial services case, investigators found PiKVM and a USB capture card used in a way consistent with laptop-farm remote control and webcam/video feed manipulation for conferencing apps.
- Recorded Future observed operators using AI tools during interviews (real-time transcription/chatbot answers) and using synthetically generated personas and illicit ID-generation services.
Who’s being targeted
- Commonly targeted roles: HR, Recruiting/Talent Acquisition, Hiring managers, Interview panels, IT support / Service Desk, Security/IT, Finance/Payroll, Legal/Compliance.
- Affected industries: Healthcare, Financial services, Software and technology, Staffing and consulting, Healthcare and biotechnology, Government.
- Attack channels: email, website, teams, zoom, slack, telegram.
- Impersonated: Job candidate/new employee (impersonating another individual), Experienced remote candidate using a fabricated persona, New remote employee (operating under a synthetic identity).
Red flags to watch for
- Proof-of-residence documents contain obvious wording anomalies
- Identity documents appear duplicated or unusually similar across different hires
- Repeated use of VPNs/proxies during onboarding and early employment
- Interview answers sound copied verbatim or unnaturally generic
- Candidate behavior suggests live coaching/transcription tooling
- Profile photo/persona details appear synthetic or inconsistent online
- Pressure to use personal devices or personal banking despite policy
- Unusual coordination channels and external tooling
- Frequent changes/updates to profile or payroll details
Frequently asked questions
What industries are affected by this fraudulent hiring scheme?
Beyond IT, the scheme has expanded into healthcare, financial services, software and technology, staffing and consulting, and government sectors.
How do the fraudulent hires pass identity verification during onboarding?
They rely on stolen or forged identity documents and use VPNs and proxy services to mask their true identity and location during onboarding and employment.
How are AI tools used in these job interviews?
Operators use screen recording software alongside AI transcription and chatbot tools to generate real-time answers during interviews, sometimes repeating chatbot responses verbatim.
What should happen after a suspicious hire is already employed?
Organizations should be cautious of requests to use personal devices or personal bank accounts for work and should enforce standard verification for any payroll or profile changes.
Read the video transcript
Imagine three “new hires” in healthcare… all real people on Zoom, all fake identities controlled from overseas. DPRK-linked workers are now getting hired into sales, marketing, even medical roles by impersonating other people with forged IDs, VPNs like Astrill, and proxies like IPRoyal, slipping past normal IT security as “remote staff.” Here’s the twist: during interviews they use AI, screen recording, live transcription, chatbot answers, to read out ChatGPT-style responses verbatim, backed by synthetically generated profile photos and polished fake resumes. If you spot duplicated IDs, weird bill wording, or interview answers that sound copy‑pasted, hit pause on hiring and escalate to Security, treat remote onboarding like a security incident, not just paperwork.