North Korea's IT Worker Program: Why Onboarding and Access Security Must Evolve

Cybersecurity has long focused on keeping attackers out. But the latest threat from North Korea shows what happens when the attacker is already inside.
Kris Singh
October 8, 2025
North Korea's IT Worker Program: Why Onboarding and Access Security Must Evolve

Updated August 4, 2026

North Korea's IT worker program is no longer a fringe threat. It is a structured, state-sponsored operation that exploits the weakest link in enterprise security: the hiring process. Okta's analysis uncovered more than 130 identities tied to North Korean IT workers attempting thousands of job interviews with companies worldwide. The program has expanded far beyond big tech, reaching finance, healthcare, government, and outsourcing firms across more than 40 countries. The United Nations estimates these workers generate between $250 million and $600 million annually for the regime.

The threat does not rely on advanced malware. It relies on trust. Specifically, it exploits the gap between who organizations assume they hired and who actually has access to their systems. Closing that gap requires rethinking onboarding and access security from the ground up.

Key takeaways

  • North Korean IT workers use fabricated identities, AI-generated deepfakes, and U.S.-based facilitators to pass standard hiring checks and gain legitimate system access.
  • Traditional background checks and document-based verification cannot detect synthetic or stolen identities at the scale this program operates.
  • The threat does not end at onboarding. Once inside, operatives hold multiple simultaneous jobs, exfiltrate data, and in some cases extort former employers after departure.
  • Identity verification must be embedded at every stage of the hiring funnel: resume submission, interview, pre-Day One onboarding, and ongoing access to sensitive systems.
  • Continuous identity assurance, not point-in-time verification, is the only model that scales with this threat.

How the North Korea IT worker program actually works

The scheme is operationally sophisticated. DPRK operatives do not hack in. They apply in.

Each operative begins by constructing a false identity using stolen or synthetic documents: passports, driver's licenses, Social Security cards. AI tools generate convincing profile photos. Fabricated portfolio websites and fake company references pass basic background checks. Operatives apply for hundreds of remote IT roles simultaneously, often targeting software development, QA testing, database management, and project management positions.

During interviews, they use AI-generated deepfakes to impersonate their fraudulent identity in real time. Some employ U.S.-based facilitators to attend video calls on their behalf. Once hired, the facilitator receives the corporate laptop at a domestic address, installs remote access software (AnyDesk, TeamViewer, RustDesk, TinyPilot), and routes the operative's connection through VPNs to mask their actual location, typically China or Russia.

According to U.S. Department of Justice reports, individual operatives can earn up to $300,000 annually. The North Korean government retains up to 90% of those earnings. CrowdStrike tracks this activity under the designation "FAMOUS CHOLLIMA" and has documented operatives posing as insiders at more than 100 U.S. technology companies.

The tactics have evolved. Google's Threat Intelligence Group (GTIG) documented one individual operating 12 separate personas across the U.S. and Europe. The FBI confirmed in January 2025 that operatives are now exfiltrating proprietary data and code, then holding it hostage for ransom. Some have publicly released stolen code when victims refused to pay.

Why traditional defenses fail against this threat

Traditional security controls were built for external attackers. This threat starts as an approved hire.

Recruiters rely on paper credentials and visual checks. Background check vendors attest to completion without guaranteeing the identity behind the documents is real. Video interviews, once considered a reasonable proxy for in-person verification, are now a vector for deepfake impersonation. VPN logins, inconsistent time zones, and camera-off calls have been normalized by remote work culture, stripping away the behavioral signals that once flagged anomalies.

The failure is structural. Most organizations treat identity as a point-in-time event: verify once at onboarding, then grant indefinite trust. That model does not hold when the person who passed the background check is not the person logging into your systems.

Responsibility is also fragmented. HR owns the hiring process. IT owns access provisioning. Security owns threat monitoring. None of them has a complete view of whether the human behind the screen is who they claim to be. By the time anyone notices something is wrong, access has already been granted, and in many cases, data has already moved.

Building a defensible hiring and access security program

Defending against the North Korea IT worker program requires identity verification at every stage of the hiring funnel, not just at the point of offer.

  • Stage 1: Resume submission. Require government ID verification before a resume reaches a recruiter. This single filter screens out fabricated identities before any human time is invested. It also signals to legitimate candidates that the organization takes authenticity seriously.
  • Stage 2: Interview. Verified identity should confirm that the person on camera is the same person who applied. This means pairing digital identity verification with liveness detection and biometric comparison, not relying on visual judgment from a hiring manager. Hiring managers cannot catch deepfakes. That is not a failure of skill; it is a failure of tooling.
  • Stage 3: Pre-Day One onboarding. A human-in-the-loop check before credentials are issued ensures that no impostor receives system access. This is the last gate before access is granted. It should be treated accordingly.
  • Stage 4: Ongoing access. Apply zero-trust principles to people, not just devices. Re-verify identity before any sensitive action such as: code pushes, fund transfers, administrative changes, or access to sensitive repositories. Continuous behavioral monitoring can detect anomalies that human reviewers miss, including sign-ins from unexpected locations, session durations that exceed human limits, and data movement patterns that fall outside normal job scope.

Organizations should also audit how access is provisioned and de-provisioned. Accounts that remain active after contractors leave are a persistent insider risk. Access decisions should be tied to verified identity, not just job titles or employment status.

Continuous identity for a continuous threat

The DPRK IT worker program is the clearest demonstration that the perimeter is no longer where risk begins or ends. Nation-state actors are applying for jobs. They are passing background checks. They are sitting inside enterprise systems right now, in organizations that believe they hired someone else.

The only defense that scales with this threat is identity assurance that does not stop at onboarding. When every action on a platform is linked to a proven human, impostors lose their advantage. Trust becomes measurable, not assumed.

Future-proofing means building systems that can adapt to deception. The DPRK IT worker campaign is the latest example of how trust can be weaponized. The organizations that close this gap are the ones that treat identity as a continuous signal, verified at submission, at interview, at onboarding, and at every high-risk action that follows.

If your organization hires remote workers or contractors and relies on document-based verification alone, the gap is already open. See how Proof Identify works to close it.

Disclaimer: Proof's products are designed solely for identity verification and fraud prevention. They are not to be used to evaluate a candidate's qualifications, character, or suitability for employment.

graphic of envelop on a square

Subscribe to our newsletter

Related Articles