North Korea operates a state-sponsored programme that places IT workers into remote jobs at foreign companies using stolen or fabricated identities, to earn foreign currency and, increasingly, to obtain insider access. The worker is real and skilled. The identity they were hired under is not.

For a security team this is an unusual threat, because nothing is breached. Someone is onboarded, provisioned, and paid through the normal process. The failure happened at hiring.

The scale

The US Justice Department has described coordinated actions against these schemes including searches of 29 known or suspected “laptop farms” across 16 states, with US-based facilitators providing a domestic internet connection through company laptops, setting up remote desktop access to them, and reshipping company hardware overseas.

That infrastructure exists to solve the scheme’s one hard problem. The worker is not in the United States, and the job requires them to appear to be. A laptop farm makes a connection from Pyongyang look like a connection from Ohio.

How the scheme runs

A borrowed or fabricated identity. The FBI notes these schemes typically involve “the use of stolen identities, alias emails, social media, online cross-border payment platforms, and online job site accounts, as well as false websites, proxy computers, and witting and unwitting third parties located in the U.S. and elsewhere” (FBI IC3, alert I-012325-PSA, January 2025).

An interview that may not feature the person who does the job. The FBI’s July 2025 guidance is explicit: “Sometimes an individual is employed to pass the initial interview, but the on-the-job work is completed by a different individual” (FBI IC3, alert I-072325-4-PSA, July 2025).

Company hardware routed through a domestic address. The laptop ships to a US address, is connected there, and is accessed remotely from overseas.

Normal-looking work. These are competent developers. The role is performed, deliverables arrive, and there is no obvious reason to look again.

And then, sometimes, extortion. The FBI reports DPRK IT workers “leveraging unlawful access to company networks to exfiltrate proprietary and sensitive data,” and that after being discovered, they “have extorted victims by holding stolen proprietary data and code hostage until companies meet ransom demands” (FBI IC3, alert I-012325-PSA, January 2025).

That changes the risk calculation. Beyond the sanctions and payroll exposure, a discovered fake employee can become an extortion event, which means quietly terminating someone is not a complete response.

What the FBI tells employers to check

The 2025 guidance is worth quoting directly, because it is specific and much of it is actionable this week.

On identity consistency: “Check for misspellings and cross-reference photographs and contact information (e.g. phone numbers, addresses, emails, etc.) with social media profiles.”

On history: “Verify prior employment and higher education history directly with businesses and educational institutions.”

On payments: “Compare payment accounts of all employees, flagging those using similar documentation to establish accounts or with matching banking information. Monitor employees who change their bank accounts often.”

On the interview itself: “Ask the individual to wave their hand in front of their face as it may prompt a malfunction in AI generated video.”

(All FBI IC3, alert I-072325-4-PSA, July 2025.)

The January 2025 alert adds two patterns visible after hire: reuse of “phone numbers (particularly voice-over-IP numbers) and email addresses, on multiple resumes,” and “multiple logins into one account in a short period of time from various IP addresses, often associated with different countries” (FBI IC3, alert I-012325-PSA).

The payment-account indicator is the strongest of these for most organizations, because it looks across the whole workforce rather than at one candidate. Several employees whose bank accounts were opened with similar documentation is a pattern no single interview would reveal.

The interview tip, and its shelf life

The hand-wave suggestion is genuinely useful right now. Occluding a face is one of the harder cases for real-time face-swapping, and a synthetic feed may glitch when a hand crosses it.

It is also a detection technique, which means it has an expiry date nobody can predict. Every published tell becomes a training objective, and occlusion handling has improved in each generation of these models. The honest position is to use it, and to avoid building a hiring control on it.

The wider evidence on human detection is not encouraging. In a 2025 iProov study of 2,000 US and UK consumers, only 0.1% correctly identified every real and fake sample, and high-quality deepfake video was caught 24.5% of the time even when participants were told to look for fakes (iProov, 2025). A hiring manager on their fourth interview of the day is not better positioned than a primed study participant.

Why the durable control is identity, not detection

Every detection technique asks the same question: does this look real? Generative models are built to make things look real, so the question gets harder every year and the defender’s position gets worse.

A different question holds up: does an authority outside this process confirm this person exists and is who they say?

That is the difference between examining an artifact and querying a record. A government-issued ID can be examined, and increasingly can be fabricated convincingly. The same ID can instead be checked against the authority that issued it — in the United States, state DMV records over the AAMVA network — where a fabricated document has no matching record and the quality of the fabrication becomes irrelevant.

Two further signals belong in the same check and neither depends on judging appearance. SIM swap and port-out detection flags a phone number that changed hands recently, relevant where a contact number is being used to establish an identity. Man-in-the-middle and anti-replay detection confirms the verification session is live and direct rather than relayed to a third party or replayed from an earlier capture, which is exactly the “someone else passes the interview” pattern the FBI describes. Trusona’s implementation is patented (US Pat. 10,601,859).

None of this requires a selfie, a liveness challenge, or a biometric on file. ATO Protect runs no liveness check, because generative AI defeats those methods.

A verification procedure for hiring

1. Verify identity before the offer, not at onboarding. By onboarding, the hiring decision is made and reversing it is expensive and awkward. The check costs the same either way; only the consequence of failing it changes.

2. Verify against the issuing authority, not against the document. Reading a document confirms what the document says. Querying the issuer confirms a record exists that matches it.

3. Re-verify at the point the laptop ships. The scheme depends on hardware reaching an address the worker controls. A verification at shipping confirms the person receiving the equipment is the person who was hired.

4. Run the FBI’s payment-account comparison across the workforce. Similar account-opening documentation or matching banking details across multiple employees is a pattern, and frequent bank account changes are worth a flag.

5. Verify prior employment and education directly, with the institution rather than through contact details the candidate supplied.

6. Treat identical contact details across applications as a signal. Reused VoIP numbers and email addresses across multiple resumes are documented behaviour.

7. Apply it to contractors and staffing agencies too. These roles are frequently filled through intermediaries, and an agency’s verification standard becomes yours by default.

8. Have a response plan that assumes data already left. Given the documented extortion pattern, discovery should trigger an access and exfiltration review, not only a termination.

What makes this hard, stated plainly

Nobody wants a hiring process that treats candidates as suspects, and a verification step that adds a week to every offer will be quietly bypassed for the candidate everyone wants.

That is the argument for a check that takes a minute rather than a background investigation that takes days. A candidate scans a government ID in their phone’s browser, the check runs against the issuing authority, and the result is a pass or fail. That fits inside an existing offer process, and it can be applied to every hire rather than to the ones somebody felt uneasy about. That matters, because a control applied selectively encodes whatever biases drove the selection.

The full research on the programme’s tradecraft, financing, and enforcement history is in The Global Threat of North Korean IT Workers and AI-Generated Fake Documents.

ATO Protect adds identity verification to hiring, onboarding, and access provisioning: a government-issued ID checked against the authority that issued it, in real time, with no pre-registration and no app to install. See ATO Protect for HR and ATO Protect use cases.

Frequently asked questions

What is the North Korean IT worker scheme? A state-sponsored programme in which North Korea places skilled IT workers into remote jobs at foreign companies using stolen or fabricated identities, generating foreign currency for the regime and, in some cases, providing insider access to company networks.

How do North Korean IT workers get hired? Through ordinary hiring channels, using stolen identities, alias emails and job site accounts, supported by US-based facilitators. The FBI has documented that a different individual sometimes passes the interview from the one who performs the work, and that company laptops are shipped to domestic addresses and accessed remotely from overseas.

What is a laptop farm? A US location where company-issued laptops are physically connected so that overseas workers can access them remotely, making the connection appear domestic. The Justice Department has described searches of 29 known or suspected laptop farms across 16 states.

What should employers look for? The FBI recommends cross-referencing photographs and contact details against social media, verifying prior employment and education directly with the institutions, comparing payment accounts across employees for similar documentation or matching banking details, monitoring frequent bank account changes, and asking a candidate to wave a hand in front of their face during a video interview, which may cause AI-generated video to malfunction.

Can you spot a deepfaked job interview? Sometimes, and it is not a control to rely on. The hand-wave test works against some current systems, but every published tell becomes something the next model handles. In a 2025 iProov study, high-quality deepfake video was correctly identified 24.5% of the time even by people primed to look for fakes.

What happens if a fake employee is discovered? Assume data exposure rather than only a personnel issue. The FBI reports DPRK IT workers exfiltrating proprietary data and, after discovery, extorting victims by holding stolen data and code hostage against ransom demands.

How do you verify a remote job candidate? Verify identity before the offer, by checking a government-issued ID against the authority that issued it rather than by examining the document. Repeat the check when equipment ships to confirm the recipient is the person hired, and apply the same standard to contractors and agency-supplied staff.

Does this only affect large companies? No. These workers apply to roles that are remote, technical, and filled quickly, which describes hiring at organizations of every size. Staffing agencies and contractor arrangements widen the exposure, because the verification standard applied is the intermediary’s.

Every other attack starts by getting past your controls. This one starts by being handed a laptop, a login, and a payroll record, through a process that worked exactly as designed.

ATO Protect verifies the new hire before day one.