North Korean IT Workers Are Allegedly Getting Jobs Inside Fortune 500 Companies, Shares Hany Farid

Deepfake expert Hany Farid warns that North Korean IT workers are allegedly using fake identities, AI tools and remote hiring systems to secure jobs inside major U.S. companies.

0
24
Hany Farid

North Korean IT workers are allegedly using fake identities, remote hiring systems and increasingly sophisticated technology to secure jobs inside major American companies, according to digital forensics and deepfake expert Hany Farid.

Speaking during a discussion on deepfakes, artificial intelligence and online manipulation, Farid highlighted the growing security threat posed by fraudulent remote workers who manage to enter companies not by hacking through traditional cybersecurity systems, but by successfully passing through recruitment and human resources processes.

Farid said his team had spoken with one of the world’s largest employers that had identified around 1,800 potential North Korean applicants or workers. He also claimed that a U.S. defense contractor discovered five North Korean workers within its organisation. The companies were not identified in the discussion, so those specific figures cannot be independently confirmed from the transcript alone.

However, the broader threat described by Farid is supported by U.S. authorities.

The U.S. Department of Justice has documented schemes in which overseas IT workers allegedly used stolen identities to obtain remote jobs at more than 100 American companies, including several Fortune 500 businesses and a defence contractor. In one major case, authorities said the operation compromised the identities of more than 80 U.S. residents and generated at least $5 million for overseas IT workers.

Deepfakes Are Making Remote Hiring More Vulnerable

One of the more concerning developments is the use of artificial intelligence during online job interviews.

Farid explained that real-time “face swap” technology can allow a person appearing on a video call to digitally replace their face with another identity. The technology can follow facial movements, blinking and speech while maintaining the artificial face during the conversation.

The FBI has separately warned companies about this technique. In guidance concerning North Korean IT workers, the agency said such workers have been observed using artificial intelligence and face-swapping technology during video interviews to hide their true identities.

This creates a fundamentally different cybersecurity challenge for businesses. Instead of attempting to break through a company’s firewall after being hired, an attacker may potentially obtain legitimate employee credentials, equipment and network access by successfully passing the recruitment process.

“They’re actually going through HR, getting jobs,” Farid said during the discussion, describing the recruitment system itself as an entry point for attackers.

Fake Candidates and ‘Laptop Farms’

The schemes can involve considerably more than manipulated video.

U.S. authorities say some operations have relied on stolen identities and so-called “laptop farms” located inside the United States. Company-issued computers are sent to U.S.-based addresses, helping make employers believe their new workers are physically located in the country. Overseas workers can then remotely access those machines.

In another case, an Arizona woman was sentenced to 102 months in prison for participating in a scheme that helped North Korean workers posing as U.S. citizens and residents obtain remote IT positions at more than 300 American companies. According to the Justice Department, the operation generated more than $17 million in illicit revenue.

Farid also highlighted a wider vulnerability in remote recruitment: “bait-and-switch” interviews. In such cases, one person may complete the technical interview while somebody else ultimately performs the job.

Why Companies Should Be Concerned

The danger extends beyond companies unknowingly paying salaries to fraudulent workers.

The FBI warned in January 2025 that North Korean IT workers had increasingly engaged in data theft and extortion after obtaining access to U.S. businesses. According to the agency, workers have copied proprietary company code, extracted sensitive information and, in some instances, attempted to extort employers after being discovered.

The Justice Department has also said that sensitive information accessed through such schemes has included employer data, source code and, in some cases, export-controlled U.S. military technology.

The problem therefore represents more than conventional employment fraud. A person who successfully passes an interview can potentially receive a genuine corporate laptop, employee credentials and authorised access to internal systems.

Farid’s warning comes as AI makes digital identity increasingly difficult to verify through a video call alone. With face-swapping, voice manipulation and fake identities becoming more sophisticated, remote hiring is emerging as another frontline in the battle against AI-enabled fraud.

For companies, the message is increasingly clear: cybersecurity may now need to begin before an employee is even hired.

LEAVE A REPLY

Please enter your comment!
Please enter your name here