By Marçal Santos, vCISO and founder of SecureLeap. CISM and CDPSE (ISACA). Previously security roles at Aircall, Citibank and Talkdesk. +20 years in cybersecurity.
North Korean IT workers are stopped at four points in a hiring process, not one. Screen the application phone number for VoIP. Hold the candidate's ID to the camera on a live call. Gate the first login on geolocation matching their declared country. Alert on remote administration tools installed within two weeks of the laptop shipping. No single one of those catches an operative on its own, because every individual identity check in a normal hiring funnel has already been engineered around. Twelve controls across the four stages is what works, and this article lists all twelve with the team that owns each one.
The programme they fund is not small. The United Nations estimates the scheme generates USD 250 million to 600 million a year, while the US Treasury attributed close to USD 800 million to 2024 alone. The joint alert issued on 31 July 2026 by the US State Department, the FBI and ten partner governments states that these workers "pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information."
Here is what that looks like from your side of the table. Your attacker filled in the application form. They passed the take-home, answered the system design round well, accepted a slightly below market offer, and asked you to ship the laptop to a different address than the one on their ID. Everything after that was authorised, logged and completely legitimate, because you issued the credentials yourself.
There is no exploit to detect and no perimeter to breach. The hiring funnel is the perimeter, and in most companies not one person in security owns a single step of it.
Definition. A DPRK IT worker is a North Korean national, usually working from North Korea, China, Russia, Southeast Asia or Africa, who obtains remote employment or contract work under a stolen or fabricated identity belonging to a citizen of another country, and remits the salary to the North Korean state. The engineering work is genuine. The identity is not.
Key takeaways
- 12 controls, four stages. Application, interview, offer to first login, and runtime. Each control has one owning team and one trigger.
- Three cheap ones carry most of the value: VoIP screening on the application, a geolocation gate on first login, and an alert on remote administration tools installed within fourteen days of laptop dispatch.
- Single checks fail by design. Background checks screen the borrowed identity, which is real. Document review meets AI-generated documents. Video interviews meet proxies who sit the call.
- Europe is in scope. Google Threat Intelligence Group found DPRK personas seeking work in Germany and Portugal, and facilitators operating in the UK.
- Terminating first is the expensive mistake. Contain, preserve evidence, and freeze payment before you separate. Expect the operative to reapply under a new name.
Why this lands on your desk and not HR's
The 31 July 2026 joint alert was signed by the US State Department and FBI together with agencies from Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom. Eleven governments, one message.
The scale is documented in primary sources rather than vendor estimates. The May 2022 guidance issued jointly by the US Departments of State and Treasury and the FBI recorded that DPRK IT workers "can individually earn more than USD 300,000 a year in some cases, and teams of IT workers can collectively earn more than USD 3 million annually." The same document notes that roughly 30,000 students study information and communications technology subjects at three North Korean universities alone. This is a pipeline, not a handful of operators.
Revenue estimates vary by source and period, and it is worth being precise about that: the United Nations estimate reported by Federal News Network puts the annual figure at USD 250 million to 600 million, while Holland & Knight reported in August 2026 an estimated USD 800 million a year alongside threat intelligence reporting of a 220% increase over twelve months in the number of companies infiltrated. US law enforcement action found operatives inside more than 300 US companies between 2020 and 2024.
The public sector is not exempt. At a Digital Government Institute conference in Washington on 28 July 2026, Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, told a panel:
"Without getting into ongoing investigations, we identified just this past week a [Democratic People's Republic of Korea] remote IT worker that was working for the federal government. Still kind of unpacking that recent case. It's actually a little bit baffling to me, not understanding this particular agency's process."
An earlier case shows the contractor pathway clearly: a Maryland man was sentenced to 15 months in prison for allowing a North Korean national in China to work on software development contracts for the Federal Aviation Administration. According to the Justice Department, he had fraudulently gained work with at least 13 US companies.
Two more reasons this is a security problem rather than an HR one:
- Sanctions liability is strict. Paying a person linked to the DPRK can breach sanctions law whether or not you knew. UN Security Council Resolution 2397 also obliges every UN member state, EU states included, to repatriate DPRK nationals earning income in its jurisdiction. The Financial Action Task Force keeps North Korea on its blacklist.
- The exit is worse than the entry. Since late 2024, Google Threat Intelligence Group has documented (GTIG) terminated workers extorting former employers, threatening to release source code and internal data or hand it to a competitor.
How the scheme actually works
DPRK IT worker hire from stolen identity and facilitator network, through the company's hiring process, to salary remittance, source code theft, extortion and sanctions exposure
The joint alert describes an operation with a clear division of labour. A proxy in a third country supplies the identity, often real ID images belonging to a genuine person, and may register the account, sit the interview, and in some cases meet someone in person to build trust. The DPRK worker does the actual engineering, and the work is often good: web, mobile, blockchain and increasingly AI and machine learning roles.
The money moves through a third party's bank account, or a money transfer service, or cryptocurrency, with the account holder forwarding funds on for a cut. In Europe, GTIG investigators saw payment through cryptocurrency, TransferWise and Payoneer, with recruitment through Upwork, Telegram and Freelancer.
The physical trick is the laptop farm. Your company ships a managed device to what looks like a residential address in your country. A facilitator, paid monthly to host many machines in one room, plugs it into an IP-based KVM switch and keeps it powered on. The operator connects in from abroad over a VPN. Your endpoint telemetry sees a device in the right country doing normal work.
That is what makes this different from a phishing campaign. The identity is fraudulent, but every credential is real, every access request goes through your approval workflow, and every log line is clean.
Why your current hiring checks do not catch it
Four defences that most companies believe in, and what each one actually stops:
Generative AI is the reason each of these degraded at once. Hemmen, describing what the FBI now sees, put the scope of it in one sentence: "We're seeing AI use across that entire spectrum of the DPRK remote worker, from application to employment." He noted AI in resume and identity document creation, in video interviews, and in remote meetings to generate deepfakes.
There is a bitter detail in the primary record here. The 2022 joint advisory lists the categories of work DPRK IT teams take on, and among them are "facial and biometric recognition software" and "artificial intelligence-related applications." The skills being sold on the open market are the same skills used to defeat the identity checks.
The pattern is that every single-point identity check has been engineered around. What has not been engineered around is correlation: the same detail appearing in two places it should not, or two details that cannot both be true. That is what the twelve controls below are built on.
The 12 controls, by hiring stage
Grid mapping twelve named controls to four hiring stages, each row showing the owning team and the trigger that fires the control
Stage 1: Application.
Owner: recruiting.
Trigger: every CV for a remote technical role.
1. Screen the phone number for VoIP. Run a carrier lookup on every remote technical applicant. VoIP numbers on applications are a documented tactic, called out by name in Mandiant's incident response findings. This is a cheap API call, it runs before a human reads the CV, and it costs a legitimate candidate nothing. For sensitive roles, require a number tied to a real carrier before the first interview is scheduled.
2. Source reference contact details independently. Never call a number or email the candidate supplied. Find the referee through the company's own switchboard or a professional network, and confirm the referee's employment separately. GTIG documented one operative who ran at least twelve personas and used personas under their own control to vouch for the others.
3. Deduplicate against every past applicant. Build a match index across shipping address, bank details or IBAN, phone, headshot hash, portfolio URL, repository handle and distinctive CV phrasing. Mandiant found the same CV reused across many personas, and background-check universities that contradicted the CV's own education history. A recurring pattern is a US or local address paired with a degree from an institution in Singapore, Japan or Hong Kong, where verification is hard and acceptance rates make the claim implausible.
Also watch for an offer to work materially below market rate, which the joint alert lists as a hiring-stage indicator.
Stage 2: Interview.
Owner: hiring manager.
Trigger: the live call.
4. Camera on, ID held to the lens, on the first call. Not a scan emailed afterwards. The interviewer checks that the face matches the document and the online profile in real time. Where you can, add liveness or biometric verification against the document. Treat this as one control, not proof: the 2026 alert warns that proxies sit interviews and even make in-person contact.
5. Ask questions that cannot be scripted. Local knowledge about the city they claim to live in, specific follow-ups on a project from three roles ago, an unannounced deep dive into a line of their own CV. What you are testing is not the answer, it is whether the answer arrives without a lag, a glance off-screen, or a switch to chat. A common pattern is a "technical difficulty" that moves substantive discussion to a side channel.
6. Record anomalies as structured data, not as a feeling. One uniform checklist for every candidate in the role, scored and stored in the ATS. This matters for two reasons. It lets you see three weak signals stacking into one strong one across separate interviewers, and it is the documentation that keeps your process defensible. More on that below.
Stage 3: Offer to first login.
Owner: IT and HR jointly.
Trigger: the signed offer.
This is the highest-yield stage. It is also the one most companies skip, because the hire feels finished once the offer is signed.
7. Re-verify identity at provisioning, not only at offer. Vetting at offer is not vetting at access. Run the identity check again against the person who actually shows up to collect credentials, and hold all system access until it clears. A gap of two weeks between vetting and provisioning is a gap someone can walk through.
8. Verify the device serial number on camera at IT onboarding. Ask the new hire to read the serial off the machine while on a call. Anyone holding their own laptop can do this in ten seconds. A farm operator hosting thirty devices in a room cannot do it convincingly for the right one. Ship only to the address you verified, and treat a change of shipping address after the offer as an escalation, not an admin task. Mandiant found the mismatch between claimed residence and requested shipping address to be one of the most consistent characteristics across its engagements.
9. Gate the first login on geolocation. The country of first login must match the declared country of residence before access opens. Alert on impossible travel from day one. Where a corporate laptop was shipped, confirm the device geolocates where the person said they live, and keep confirming: investigators repeatedly found devices that never once geolocated to the stated address. In one GTIG case a corporate laptop intended for New York was found operational in London.
Stage 4: Runtime.
Owner: security.
Trigger: from day one onward.
10. Alert on remote administration tools installed shortly after shipment. The recurring pattern in incident response is multiple remote management tools installed on a corporate laptop immediately after it arrives at the farm. Mandiant's engagements named six specifically: GoToRemote and LogMeIn, GoToMeeting, Chrome Remote Desktop, AnyDesk, TeamViewer and RustDesk. Build a detection for any of them appearing within fourteen days of device dispatch, and a second, higher-severity rule for two or more on one host at any time. Restrict installation of remote desktop software by policy and disable local administrator accounts so the install requires a request you can see.
11. Enrich corporate egress IPs against VPN and proxy datasets. Mandiant found that connections to those remote management tools originated primarily from IP addresses associated with Astrill VPN, likely from China or North Korea. Correlate, do not block: services like this have large legitimate user bases, so a hit is an investigative pivot and never a verdict on its own. Pair it with impossible travel and with a residential-proxy check.
12. Hunt for mouse jigglers and IP-KVM devices. Mandiant observed operatives using the Caffeine keep-awake utility to stay active across several laptops and profiles at once, which is what holding multiple jobs simultaneously requires. An IP-based KVM presents as a USB HID device on a machine that should have a human at the keyboard. Both are cheap detections on a managed endpoint and both are very hard to explain away.
Is this a European problem too?
Yes. DPRK IT workers are actively targeting European employers, and Portugal is named in the primary research. In April 2025, Google Threat Intelligence Group reported that investigations "uncovered other IT worker personas seeking employment in Germany and Portugal, alongside login credentials for user accounts of European job websites and human capital management platforms."
The wider European picture from the same GTIG reporting:
- One operative ran at least twelve personas across Europe and the US in late 2024, targeting organisations in the defence industrial base and government sectors, providing fabricated references and using other personas under their control to vouch for credibility.
- Facilitators, the people who defeat identity verification and receive funds, were found operating in the United Kingdom as well as the US.
- Recovered facilitator infrastructure contained fabricated personas with degrees from Belgrade University and claimed residences in Slovakia, instructions for navigating European job sites, guidance on using a Serbian time zone in communications, and contact details for a broker in false passports.
- Claimed nationalities across these personas included Italian, Japanese, Malaysian, Singaporean, Ukrainian, American and Vietnamese.
GTIG attributes the shift to pressure in the US market: increased public awareness, Department of Justice indictments and right-to-work verification challenges pushed operations outward, "with a notable focus on Europe."
The legal exposure follows. France, Germany, Italy and the Netherlands all co-signed the July 2026 alert. UN Security Council Resolution 2397 binds every UN member state, and EU member states implement DPRK sanctions through their own regime. For an EU company, a suspected case also engages the GDPR Article 33 breach assessment inside 72 hours if personal data was reachable.
Two gaps the 12 controls do not close
Contractors and staffing firms. Contract IT work is one of the most common entry paths, and when you outsource the hiring you outsource the twelve controls with it. Donald Blersch, a former senior government official who advises the risk assessment firm Clearspeed, framed the exposure this way:
"If you're a contractor supporting a company, even if you're nowhere near the government contract itself, you may still have access to corporate networks, systems, and information that can ultimately provide a pathway into government environments. When those individuals aren't vetted in a way comparable to the access they're given, you're potentially hiring a Trojan horse."
Push the controls into the contract: require the agency to run identity verification and device controls to your standard, to disclose subcontracting, and to notify you of any personnel change. Add the questions to your vendor security questionnaire and treat a staffing supplier for engineering roles as a high-criticality vendor, because that is what it is.
BYOD and virtual desktops. Companies that avoid shipping laptops by letting people connect from a personal device through a VM have removed the evidence trail, not the risk. GTIG is explicit about the consequence: personal devices under BYOD "may lack traditional security and logging tools," which means "typical evidence trails linked to IT workers, such as those derived from corporate laptop shipping addresses and endpoint software inventories, are unavailable." GTIG assessed that operatives identified BYOD environments as ripe for their schemes and were running operations in them from January 2025.
If you run BYOD for engineering, controls 8 and 10 do not exist for you, and controls 9, 11 and 12 have to move into the virtual desktop layer to compensate.
If you suspect a current hire: the first 48 hours
Timeline of the first 48 hours after suspecting a DPRK IT worker hire, from cutting access at hour zero through evidence preservation, counsel, payment freeze, reporting and backward threat hunting
The order matters more than the speed.
- Hour 0. Cut access in one action, and do not announce it. Revoke SSO, VPN, repository and cloud tokens simultaneously. A staged revoke tells the operator to start exfiltrating.
- Hour 1. Preserve, do not wipe. Snapshot the endpoint, place a legal hold on EDR, SSO and VPN logs, and freeze the mailbox. Re-imaging the laptop destroys the evidence you will need for the sanctions analysis, the insurance claim and any disclosure.
- Hour 4. Run it under counsel, cross-functionally. Security, HR, legal and finance in one channel with one owner. Document objective, articulable indicators at each step.
- Hour 8. Freeze the payment. Paying on can itself be the violation, and OFAC sanctions liability is strict. Block or escrow anything owed before the next payroll run and take advice on the sanctions position before releasing funds. Expect the possibility that extortion arrives framed as a severance negotiation.
- Hour 24. Report, and assess your breach duties. In the US, report to IC3 and to your local FBI field office private sector coordinator. In the EU, run the GDPR Article 33 assessment inside the 72-hour window if personal data was accessible. Establish the law enforcement relationship before you need it, not during.
- Hour 48. Hunt backwards, then watch the front door. Replay their egress IPs, device identifiers and account activity across your full log history. Then expect a re-application.
That last point is the one companies consistently underestimate. Megan Mocho, a partner at Holland & Knight, described the pattern from her own casework:
"I've represented companies that have been targeted. They were alerted to that person and were able to remove them or the person had already been removed, but then subsequently, the company is targeted by new individuals. Well, thankfully the company had lessons learned and so knew what to look for, knew how to do interview validation, knew how to validate their resume, and check their profile integrity."
Terminated operatives return under new identities, with insider knowledge of your stack, your team structure and your open roles, and CVs tailored accordingly. Flag applications to any role a suspected operative recently vacated, and run control 3 against them specifically.
Doing this without creating a discrimination problem
This is the part most people skip, and it is the part that will actually block your programme in legal review.
Screening built around nationality, accent, surname or perceived ethnicity is both unlawful in most of the jurisdictions you hire in and useless as a detection, because the identities in use are borrowed from citizens of the countries you would be screening for. As noted above, GTIG documented personas claiming Italian, Japanese, Malaysian, Singaporean, Ukrainian, American and Vietnamese nationality.
Holland & Knight frames the employer's position as two competing legal risks: failing to detect fraudulent applicants, and overcorrecting into discrimination claims under Title VII of the Civil Rights Act or the anti-discrimination provisions of the Immigration and Nationality Act. Four rules keep the programme defensible on both sides:
- Screen for fraud indicators, not for origin. Every control above tests an objective, verifiable fact: is this number VoIP, does the serial match, does the first login geolocate where you said you live. None of them requires an assumption about where someone is from.
- Apply the checks uniformly by role, not by candidate. Define the tier of scrutiny by what the role can reach (source code, cloud infrastructure, production, funds), then run it on every applicant in that tier without exception. Blersch put the principle economically: "The objective isn't to clear everyone, but to know with confidence who you're trusting with critical access."
- Do not over-document. Demanding extra identity documents, imposing citizenship requirements without a legal basis, or re-verifying people you are not required to re-verify creates its own liability. In the US this runs into Title VII and 8 U.S.C. § 1324b; in the EU, into equal treatment law and GDPR data minimisation.
- Write down the reason for every escalation. Which indicator fired, on what date, and what happened next. Control 6 exists for this reason.
Five mistakes that keep showing up
- Treating the red flag list as the control. A list of indicators is not a control until someone owns it, a trigger fires it, and the result is written down. Assign each of the twelve to a named team.
- Verifying at offer and never again. The identity that passed vetting is not necessarily the identity that collects the credentials. Control 7 exists because of this gap.
- Blocking on a VPN hit. Commercial VPNs have large legitimate user bases. Treating a single egress match as proof produces false positives, buries the signal, and creates a discrimination risk if the population it flags is not random. Correlate at least two independent signals before escalating.
- Terminating before preserving. A fast termination that destroys the endpoint, closes the mailbox and pays the final salary is worse than a quiet one two days later with the evidence intact and the payment held.
- Stopping at your own payroll. Your contractors, your staffing agencies and your MSP hire into your environment. If the twelve controls are not in those contracts, you have secured one of your two front doors.
Where to start this week
You do not need all twelve to move the risk. In order of effort to value:
- Turn on the VoIP carrier check in your ATS (control 1). One afternoon.
- Write the geolocation gate into your provisioning runbook (control 9). One afternoon, and it is the single highest-value control here.
- Build the RAT detection rule with a fourteen-day shipment window (control 10). One sprint for a detection engineer.
- Add the twelve controls to your staffing agency contract renewals and your vendor security questionnaire.
- Decide the first 48 hours now, on paper, and name the four people in the channel.
Lorna Macfarlane, co-author of an Intelligence and National Security Alliance white paper on the threat, made the case for acting now rather than after:
"Whether a bad actor's intent is to earn a paycheck to fund a weapons of mass destruction program or gain access to sensitive or proprietary information, it's important organizations take action now to strengthen every component of their hiring process to prevent these schemes from happening."
If nobody in your organisation currently owns the cross-functional escalation path between recruiting, HR, finance and security, that is the real finding, and it is what a vCISO engagement is for. Book a 30-minute call and we will walk your hiring funnel end to end and tell you which of the twelve you already have.
FAQ
How do I detect a North Korean IT worker before hiring them?
No single check works, because each individual identity control has been engineered around. Detection comes from correlating independent signals: a VoIP phone number, a shipping address that does not match the ID, references you cannot verify independently, a first login from the wrong country, and reluctance to appear on camera with the ID in hand. Two or more of those together is an escalation. One on its own is not.
Is this only a US problem?
No. Google Threat Intelligence Group found DPRK IT worker personas seeking work in Germany and Portugal, facilitators operating in the UK, and one worker running at least twelve personas across Europe and the US. France, Germany, Italy and the Netherlands all co-signed the July 2026 alert. UN Security Council Resolution 2397 obliges every UN member state to repatriate DPRK nationals earning income in its jurisdiction, so the sanctions exposure is not US-only either.
How much money does the North Korean IT worker programme make?
Estimates differ by source and period. The United Nations estimate puts annual revenue at USD 250 million to 600 million. The US Treasury attributed close to USD 800 million to 2024 alone. At the individual level, the 2022 joint State, Treasury and FBI advisory recorded that a single worker can earn more than USD 300,000 a year in some cases, and a team more than USD 3 million.
We are a 40-person startup. Is this really our problem?
Small, fast-growing, fully remote engineering teams are a good target, not a poor one: hiring pressure is high, the process is compressed, and the access granted on day one is broad. The relevant question is not headcount, it is what a new remote engineer can reach in their first week. If that includes production, customer data or source code, you are in scope.
Are the red flags in the government alert still reliable?
Partly. The alert itself caveats the language-quality signal, noting that large language models now produce convincing second-language profiles, so its absence proves nothing. The durable signals are the ones tied to physical and financial facts that are expensive to fake at scale: device location, serial number possession, payment routing, and identity documents reused across accounts.
What do I do if we find one already on payroll?
Cut access in one action, preserve the endpoint and logs before doing anything else, bring legal in within hours, freeze the payment before the next payroll run, and report to IC3 or your national authority. Then hunt backwards through your logs and prepare for a re-application under a new identity. The full sequence is in the first 48 hours section above.
More info (Sources)



