Latest Blog

North Korean IT Workers: What Recruiters Can Catch That Security Cannot

Researcher

5 min read

No headings found. Add headings to your CMS content to populate the table of contents.

Share this post

When a North Korean IT worker gets hired, the failure has already happened in recruiting before security ever sees it. By the time an endpoint agent flags something, the person is already an employee. They are badged, paid, inside the VPN and holding whatever access the role came with. The controls that could have stopped them cheaply all sit in the recruiting funnel, and most of them are behavioural signals a recruiter sees and a SOC never will.

If you think you have one right now. Stop payment before anything else. Do not contact the worker. Preserve the interview recordings, the application file and the identity documents. Call counsel before you start HR process. Take the disclosure decision and the law-enforcement decision together, because taking one first can cost you the other. The full first-day sequence is below. Book an Incident Walkthrough. If you are inside the first 48 hours, we will walk your escalation order with you today. No product demo.

On 31 July 2026, eleven governments issued a joint alert about North Korean IT workers getting hired at Western companies. The United States, Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom all signed it.

The document is useful, but it was written for security teams. It tells you what to watch for, but not where in your hiring process you would catch it or whose job it is to act on it. Below, each of its indicators is set against the hiring stage where somebody can catch it.

Is this a real risk for an ordinary employer, or a story about crypto startups?

The risk reaches ordinary employers, at scale, including ones with working security programmes. In April 2026 a federal court sentenced Kejia Wang to 108 months and Zhenxing Wang to 92 months for running laptop farms. The DOJ's case described 80+ stolen US identities used to place workers at over 100 US companies, many of them Fortune 500, generating $5M+ for the DPRK. As The Record reported from the DOJ announcement, victim companies were left with at least $3M in remediation and legal costs. Treasury put the revenue from these schemes at nearly $800 million in 2024 alone when it designated six individuals and two entities on 12 March 2026.

One case is clearer than the rest, because a company disclosed it about itself. KnowBe4, a security awareness training vendor, hired a DPRK operative in July 2024 who cleared four separate video interviews and a background check. That check passed because the identity was a real stolen one. Those four interviews passed because an AI-enhanced stock photo on the application matched the face on the call. Nothing in that pipeline was broken. It was designed against ordinary candidate misrepresentation, not against a state programme working from stolen identities.

Treat KnowBe4 as your base rate. It shows what an ordinary hiring process catches on its own, which in that case was nothing until the person had been hired and issued a laptop.

Book a Pipeline Infiltration Review. Thirty minutes walking your current screening sequence against the joint alert's indicator list. You get the mapping whether or not you buy anything.

What do the eleven governments tell employers to look for?

The alert lists four families of indicators, plus a set of due-diligence steps. It flags profiles suggesting inaccurate machine translation, refusal to appear on video or manipulated video feeds, offers to work at below-market rates, and requests for payment in cryptocurrency. On the platform side it adds frequent changes to registered account information, mismatches between an account holder's name and the payment account, multiple accounts tied to the same identification document or IP address, and forged or altered identification documents.

One indicator in the alert is the one a hiring team can see directly. It flags "signs that the account is being operated by multiple people," and explains why: "North Korean IT workers often operate in teams, and the individual whom a hiring or procuring official interacts with may change depending on the time of day." A recruiter is usually the only person in the company positioned to notice that.

The FBI guidance that came with the alert is blunter than most employers expect. Verify prior employment and education directly with the institutions rather than with the contacts the candidate supplied. Compare payment account details across your existing workforce for matches. Ship equipment only to an address matching the identification document. And require in-person meetings to confirm identity and location.

Three of those four sit outside a recruiter's control.

Where in the funnel can a recruiter act on each signal?

When you see a signal changes how much it is worth to you. Several of the strongest ones appear only during a live conversation, and only the person on the call can see them.

Signal

Where it surfaces

What the recruiter does with it

Payment account matches another worker's, or changes late

Offer and onboarding

Hold before first payroll run, then escalate to finance and counsel. Never to the candidate

Equipment ship-to address differs from the ID address

Onboarding

Do not ship. Treat any request to redirect to a third address as terminal

Employment history checks out only via candidate-supplied contacts

Screening

Re-verify direct with the institution's own published number

Answers arrive after an unexplained lag, or eyes move off-camera before each one

Live interview

Ask an unscripted follow-up on something the candidate said two minutes earlier

The person on the video differs subtly across sessions, or availability tracks a foreign business day

Second and third interviews

Compare recordings side by side and note who was scheduled and who appeared

Below-market rate volunteered without negotiation, or crypto payment raised by the candidate

Offer

Stop and escalate. The least ambiguous indicator on the list

Two of those rows need explaining. An unscripted follow-up works because a live translation or assistance pipeline is tuned for the question in front of it, not for an unannounced callback to something said two minutes earlier. A candidate answering for themselves finds that easy, and a relay finds it expensive. An infiltration that survives one call will often fail a comparison across three, which is why recordings and a stable record of who was invited to which session are worth keeping.

There is no row in that table for accent, name, apparent nationality or English fluency. Adding one would be bad detection and a legal problem at the same time. National origin is a protected characteristic under Title VII of the Civil Rights Act, and the EEOC treats accent and fluency decisions as national-origin issues except where the job requires fluency. The EEOC's guidelines take the same view of language generally. 29 CFR 1606.7, which addresses English-only workplace rules, records that "the primary language of an individual is often an essential national origin characteristic." That section governs workplace rules rather than screening and carries a business-necessity exception, so read it as illustrative of how the EEOC thinks about language, not as the authority on screening. A screen that downgrades second-language speakers discriminates against a large number of candidates who have done nothing wrong, and it still misses a competent operative, because fluency is the one thing this adversary can buy.

Book an Interview Integrity Walkthrough. Bring one role you consider exposed and we will go through the six rows above against how it is screened today.

What did researchers see when they deliberately hired three of them?

They saw more than any company disclosure has shown so far, because they controlled the environment. Security researchers Mauro Eldritch and Heiner García, working with ANY.RUN, built a fake DeFi startup called Ballena Azul LTD and hired three suspected operatives through an ordinary recruitment process, publishing on 10 August 2026 and presenting the work at DEF CON. Attribution to the group tracked as Famous Chollima is the researchers', not a government's.

All three arrived on faked or stolen documents. There was a forged Texas licence with a valid Social Security number, a California licence whose image metadata carried Google Gemini traces and a SynthID watermark, and a New York licence belonging to a real, unrelated person obtained through an image leak.

The interview-stage signs were ordinary. They're the kind of thing a recruiter notices and then forgets about. One candidate glanced repeatedly off-screen before answering, consistent with the live translation software researchers later observed in team meetings. The operatives also referred each other, so if a second suspicious hire arrives on a referral from your first, that is worth a question.

All three did the same things on their first day. Each ran dxdiag, systeminfo and wmic to profile the machine, then checked what country their connection appeared to originate from. One installed Google Remote Desktop and synced a personal Google account into the sandbox, handing researchers his own browsing history and saved passwords. If onboarding hands a new hire a laptop and nobody reviews telemetry in the first week, that sequence runs invisibly.

You think you have found one. What happens in the first day?

The order you do these things in decides how much the incident costs you, so agree on it before you need it.

Stop payment before anything else. The payment is the sanctions exposure. Payroll that keeps running while you investigate turns an ambiguous personnel matter into a series of transactions somebody will later have to explain to a regulator, one line item at a time.

Do not confront the worker. Access revocation, evidence preservation and notification all get harder once the account holder knows. Preserve the interview recordings, the application file, the identity documents and the device telemetry first.

Bring in counsel before HR process, and before the step below. A voluntary self-disclosure to OFAC halves the base civil penalty under OFAC's Economic Sanctions Enforcement Guidelines. In a non-egregious case the base becomes one-half of the transaction value, capped at $188,850 per violation. In an egregious one it becomes one-half of the statutory maximum. The halving happens in the penalty calculation itself. No official has to decide to grant it. But it only counts as voluntary if it comes before the apparent violation is discovered by OFAC "or any other federal, state, or local government agency or official," and that includes the FBI. Read that against the next bullet. Disclosing and reporting are one decision, and counsel should be making it early.

Report to the FBI. The FBI's IC3 public service announcement on DPRK IT worker threats, issued 23 July 2025, is the documented route, alongside your local field office. Reporting is not mandatory, but it is how you establish that you were a victim rather than a participant.

Then work backwards through the pipeline. Find out which recruiter, which source and which referral brought them in, and whether any other candidates arrived the same way. Ballena Azul's referral graph is why this step is not optional.

Book a 30-Minute Detection Session. If you are mid-incident, we will talk through your sequence and your escalation path. No product walkthrough. Come with questions and no purchase intent.

What is the exposure if one already got in?

The exposure does not depend on what you knew, and so far no employer has been enforced against for it. Sanctions liability under the North Korea regulations does not require that you knew, so a company paying an operative in good faith has technically transacted with a sanctioned interest. Against that, Skadden's June 2026 analysis records that neither DOJ nor OFAC has filed an enforcement action against a company that inadvertently hired one of these workers, and that such companies have been characterised in government filings as victims who were systematically targeted. They add a qualifier: "companies are not in the clear."

So the standard is strict, but enforcement discretion has so far run in employers' favour, and there is mitigation credit for firms that can show reasonable diligence. In practice that means a documented screening process you can produce afterwards, showing what you checked and when.

What does none of this solve?

Three limits stay in place no matter how well you screen remotely, and the first one cuts against how most companies now hire.

The strongest recommendation in the guidance around that alert is an in-person meeting to confirm identity and location. That one is the FBI's, not the eleven governments' own, so check the attribution if you are citing it internally. No remote process substitutes for it, ours included. Where a role is security-sensitive and you can absorb the cost, a single in-person step defeats the whole attack class in a way no signal stack does. Gartner's August 2025 finding, from a survey of 3,000 candidates, that 62% would be more likely to apply if a role required an in-person interview suggests the candidate-experience cost is smaller than teams assume. Companies skip it for distributed hiring and for cost. Say out loud that you are making a trade, because you are.

Detection signals produce false positives, and who they land on is not random. A candidate on a poor connection, in a shared room, reading from notes, or thinking in a second language will trip several of the six behavioural indicators above. Each one needs a human reading full context before it changes an outcome, and you need a documented path for whoever trips a flag innocently. Otherwise you end up with a control that penalises people with bad broadband and no spare room, which catches no adversaries at all.

This adversary also moves faster than the guidance. The SynthID watermark that exposed one Ballena Azul applicant is a detection route that closes the moment operators start stripping metadata, which costs them nothing. If a control depends on one artefact that the other side can remove for free, then it will stop working, and you will not be told when. The controls that last are the structural ones. Verify employment and education with institutions you contacted yourself, keep payment and shipping addresses consistent with the identity document, and keep a record of every session.

Where Tenzo fits

Tenzo cannot tell you that a candidate is a North Korean IT worker. No vendor's software can, and one claiming otherwise is selling an attribution capability that belongs to governments.

What Tenzo does sits earlier than that, on the question of whether the person in the interview is the person who applied. During the AI interview it verifies identity, looks for signs of cheating, and looks for signs that the candidate has been swapped for somebody else. On the application itself it checks the phone number, the IP address, the physical address, the email history and the other records available on the candidate for signals of fraud.

Tenzo runs structured interviews across phone, video and text, sitting alongside your ATS rather than replacing it, with recruiter review over full transcripts, configurable interview design, documented accommodation paths and version history for audit. Humans review throughout and make all final decisions. Underneath, multiple models run in parallel, for redundancy. That leaves a consistent record of what was asked, what was answered, who was invited and what each session looked like, which is the raw material for the cross-session comparison in the table above. Our interview-integrity signal set for web-based interviews is described in detail on our candidate fraud and deepfake prevention page.

None of it substitutes for an in-person interview. Where a role is sensitive enough to justify the cost, do one anyway, ahead of anything we or anyone else can offer remotely.

Treat any vendor's catch rate for identity-fraud signals with suspicion, ours included, because the denominator is unknowable. The number would have to be flags raised against confirmed frauds, and confirmation almost never comes back to a vendor.

To run your current screening sequence against the joint alert's indicators, book a working session. Bring the role you are most worried about.

FAQ

How do North Korean IT workers get hired? Through ordinary recruitment. They apply to remote roles on stolen or synthetic identities, clear video interviews using AI-enhanced photos and in some cases real-time video manipulation, pass background checks because the underlying identity belongs to a real person, and have equipment shipped to a US facilitator who runs it as a laptop farm while the worker connects from overseas.

What are the red flags for a North Korean IT worker in an interview? The 31 July 2026 joint alert lists refusal to appear on video or manipulated video feeds, profiles suggesting inaccurate machine translation, offers to work at below-market rates, and requests for payment in cryptocurrency. In practice, what a recruiter tends to notice is answer lag, eyes moving off-camera before each answer, difficulty handling an unscripted follow-up to something said earlier, and an appearance or availability that shifts between sessions.

Can a background check catch a North Korean IT worker? Usually not on its own. The identities in these schemes are frequently real, stolen US identities, so a standard check comes back clean on somebody who exists and has done nothing wrong. KnowBe4's disclosed 2024 case cleared both a background check and four video interviews.

Is it illegal to have hired one? Sanctions liability under the North Korea regulations does not turn on knowledge, so payments made in good faith can still be violations. As of June 2026, however, no enforcement action had been brought against a company that inadvertently hired one, and such companies have been characterised by the government as victims. Mitigation credit is available for reasonable diligence and for voluntary self-disclosure to OFAC. This is not legal advice, so take it to counsel.

What should I do if I think we hired one? Stop payment, do not confront the worker, preserve the recordings and application file, involve counsel before HR process, and report to the FBI through IC3 and your local field office. Then trace the pipeline backwards to find how they entered and whether anyone else arrived the same way.

Should we screen candidates by nationality or accent? No. National origin is protected under Title VII, and the EEOC treats decisions made on accent or fluency as national-origin issues unless the job requires fluency. Beyond the legal exposure, fluency is cheap for this adversary to buy and common among candidates you want to hire, which makes it a signal that generates false positives without generating true ones.

Related reading

Related Posts