1,000 Companies in 3 Months: North Korea's Hiring Infiltration


A single North Korean cell applied to more than 1,000 companies in three months. The operatives used AI to write their resumes, AI to generate answers during live interviews, and AI face swapping to appear as someone else on video calls. Some of them were hired.
The Wall Street Journal traced that workforce using leaked data taken from the operatives' own machines, including browser history, emails, calendars, and screen recordings. The FBI has now identified thousands of these applicants across the United States.
How the scheme actually works
The operatives do not enter the country. They apply for remote roles using stolen American identities, which is what allows them to clear background checks. A single worker often runs several aliases at once and holds multiple jobs simultaneously.
Once hired, the corporate laptop ships to a US address and stays there. A domestic facilitator receives the machine, maintains it, and gives the offshore worker remote access. Those same facilitators open bank accounts, cash the paychecks, and in some cases sit in on company meetings while the actual work happens overseas. One Ohio facilitator collected $75,000 a year, split evenly with the workers.
The economics explain the volume. Individual operatives can earn more than $300,000 annually. The regime withholds up to 90 percent of it. Analysts estimate the scheme generated as much as $800 million in a single year.
The costs land on people who had nothing to do with it. One Georgia man discovered his stolen identity had been used to hold jobs across the country. He could no longer open a bank account, secure a loan, or rent a home.
Every control they defeated was a document check
Look at what the hiring process actually evaluated at each stage.
The resume was AI generated. The cover letter was AI generated. The interview answers were read from a chatbot in real time. The face on the video call was synthesized. The identity documents belonged to a real American with a real credit history, which is precisely why the background check cleared.
Each of those controls asks the same question: is this document valid? None of them asks a different and far more important one: is the person on this call the person these documents describe?
That distinction is the entire vulnerability. A stolen identity passes a records check because the identity is real. A face swap passes a video interview because nobody is comparing the face on screen against a government issued credential in real time.
The handoff gap between HR, IT, and security
Hiring fraud is expensive because it does not stop at payroll.
In most organizations, three teams touch employee identity and none of them share a system. HR verifies documents in the applicant tracking system. IT provisions accounts in the identity platform. Security monitors behavior in the SIEM. There is no cryptographic chain connecting the person HR verified to the account IT created to the activity Security watches.
A fraudulent hire clears recruiting on a Tuesday and receives credentials, VPN access, and source code repositories the following Monday. The identity failure happened in the hiring funnel. The breach shows up in engineering. IBM puts the average cost of a data breach at $4.9 million, and that figure does not account for the sanctions exposure that comes with having paid a designated regime.
What verification at the point of hire requires
Closing this gap means verifying the person, not the paperwork:
- NIST IAL2 identity verification. Government ID capture paired with a real-time biometric selfie compared against that credential.
- Liveness detection. AI-powered confirmation that a live human is present, which is what rejects face swaps, deepfakes, and static photos.
- AAMVA integration. Driver license validation against DMV records in real time.
- Trusted Referees. Trained human verification for edge cases and high-risk candidates, as NIST provides for in SP 800-63A.
- A tamper-evident record. Cryptographic evidence of who was verified, when, and by what standard.
A face swap does not survive a biometric comparison. A stolen document does not survive a liveness check performed on the person actually holding it.
Why hiring is the right place to fix employee identity
Hiring is the moment an organization has the strongest claim to know who someone is. Verifying identity once at that moment, then carrying that verified credential forward, changes the economics of everything downstream. Onboarding, account recovery, privileged access re-verification, and offboarding all inherit that assurance instead of re-establishing it weakly each time.
The alternative is the model that produced this story: discover the fraudulent employee after the access was granted, the data moved, and the money left the country.
The FBI has identified thousands of these applicants - we first flagged the pattern back in October of last year. One cell alone reached 1,000 companies in a single quarter. For any team hiring remote workers, the question is no longer whether a fraudulent applicant has entered the pipeline. It is whether the process would catch them, and whether you could prove it afterward.
If you'd like to see how Proof verifies candidate identity before day one, you can book time with our team here.













.jpg)

































































.jpg)
























































