Related
North Korean IT Worker Schemes: Why 11 Governments Are Warning Employers Again
10 minute read
In the broadest international warning to date on fraudulent North Korean IT worker schemes, agencies from 11 countries jointly called on employers, online employment platforms, contracting marketplaces, and governments to strengthen defenses against these operations.
For years, governments and cybersecurity agencies have warned that North Korean IT workers use stolen and fabricated identities to obtain remote employment, generate revenue for the regime, and, in some cases, gain access to corporate networks. What makes this advisory different is not the tactics it describes, but the scale of the international response.
Issued jointly by agencies from Australia, Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, the Republic of Korea, the United Kingdom, and the United States, the advisory reflects a growing international consensus that these operations remain active, continue to evolve, and continue to succeed.
The advisory also comes amid a broader escalation in enforcement. Over the past year, U.S. authorities have announced coordinated investigations, arrests, seizures of laptop farms, and criminal prosecutions tied to North Korean IT worker operations. In April, the U.S. Department of Justice announced the sentencing of two U.S. facilitators involved in a scheme that infiltrated more than 100 companies using the stolen identities of at least 80 Americans and generated more than $5 million for the North Korean regime.
At GetReal Security, we’ve previously explored how AI-powered identity deception is making it increasingly difficult for recruiters and hiring managers to distinguish legitimate candidates from sophisticated imposters during live interviews.
The latest advisory reflects a growing recognition that remote hiring is no longer solely a recruiting challenge but it is increasingly being treated as an enterprise security problem.
From Hiring Fraud to Enterprise Security
Previous public reporting has largely framed North Korean IT worker operations as hiring fraud or sanctions evasion. While those remain central components of the campaign, this alert places greater emphasis on the enterprise security implications.
Organizations that unknowingly hire fraudulent remote workers are not simply facing a human resources problem. They risk granting trusted insiders access to sensitive systems, proprietary data, source code, customer information, and critical business operations.
Our Threat Intelligence team has been tracking this evolution through what we call The Hiring Kill Chain — a framework that maps how threat actors systematically exploit every stage of the hiring lifecycle. Rather than viewing recruitment as a single point of failure, the framework shows how adversaries move from reconnaissance and identity creation to interviews, onboarding, privileged access, and ultimately persistence within an organization.
“Folks in the HR business, they were never meant to be security folks. Their job is to hire people. Their job is not to look out for threats,” Tom Cross, head of threat research at GetReal, said in a recent webinar. “And they're certainly not used to dealing with nation state threat actors. It's really important right now that CISOs and cybersecurity professionals develop relationships with HR teams and figure out how to help them build processes they can follow that will identify these suspicious actors.”
The advisory reinforces this progression. The objective is not simply to deceive a recruiter but to establish trusted access inside an enterprise. Every stage of the hiring process presents an opportunity for adversaries to advance their operation or for organizations to detect and stop it.
Viewed through that lens, this alert is about far more than fraudulent resumés or fake identities. It is recognition that the hiring process itself has become an attack vector. The initial compromise is no longer achieved solely through exploiting a software vulnerability or phishing an employee, it can and is beginning with a job application.
AI Is Lowering the Cost of Identity Deception
While the advisory focuses on indicators organizations should watch for during remote hiring, our Threat Intelligence team has observed a broader trend: AI is reducing the cost and complexity of identity deception.
Threat actors can now fabricate resumés, employment histories, professional profiles, identity documents, and supporting digital assets at unprecedented speed. During live interviews, AI-assisted video and audio manipulation can reinforce those fabricated identities, making deception significantly more convincing than traditional identity fraud alone.
As a result, organizations can no longer assume that a candidate appearing on a video call is the same individual whose resumé, government identification, or background check they reviewed.
Security Should Start Before a Candidate Becomes an Employee
Most identity and cybersecurity technologies are designed to protect employees, contractors, and enterprise accounts after someone has been trusted and granted access.
Remote hiring presents a different challenge. Before an applicant receives a corporate account, a laptop, or access to internal systems, organizations have already made a series of trust decisions. They’ve reviewed a resumé, interviewed the candidate, and an identity is verified only through the onboarding process.
As our research shows, identity deception can occur at multiple stages of the hiring process, not only during the initial interview, but throughout onboarding and then employment.
Traditional identity verification was not designed to continuously validate the human participating in live digital interactions.
The latest advisory, along with what we’ve seen inside the enterprise and what we are hearing from recruiters is that this approach is no longer sufficient nor safe. Threat actors are increasingly targeting what has historically received the least security attention: the front door to each organization.
“Organizations need confidence in who they’re engaging with before enterprise security controls ever come into play,” explains Matthew Moynahan, CEO of GetReal Security. “We need to move beyond the traditional background check and start thinking about a pre-ground check, establishing confidence in who you’re engaging with before access is granted.”
The coordinated response from 11 of the world’s most-influential governments suggests growing recognition that remote hiring has become an increasingly attractive pathway for threat actors seeking trusted access to enterprise systems.
As organizations continue to expand distributed workforces and AI continues to lower the barriers to identity deception, protecting the hiring process will require more than document verification and background checks.
See How GetReal Stops AI Impersonation