North Koreans are working in the U.S. Information Technology (IT) sector — and a lot of companies are not aware of them. Fraudsters connected to the North Korea IT Worker Scheme made almost $800 million in 2024 using stolen identities, bogus resumes and AI-generated interview software and U.S.-based laptop production facilities. The impact of these ripples is already being felt by legit job applicants vying for the same US remote positions: slower hiring, increased scrutiny at hiring stages and a heightened wariness regarding the use of remote working.
Quick Facts
| Fact | Detail |
| Revenue generated (2024) | ~$800 million to North Korea |
| Fortune 500 firms targeted | Of the 18 samples that were taken, 18 were positive for infiltration. |
| The three companies impacted by one facilitator are U.S. companies. | Including major TV, tech and auto brands 300+ |
| Tools used | Use of AI for recruitment, deepfakes, stolen identities |
| Intermediary countries | Pakistan, India, Nigeria |
| U.S. facilitator sentence | Identity Fraud and wire conspiracy 8+ years |
How the North Korea IT Worker Scheme Works
The North Korean remote workers scheme is not ad hoc, but rather systematic and organized, in the hands of the state. They are taught to code as children and their education in systems engineering have been completed before they are sent overseas to make hard currency for a well-sanctioned regime.
Three things to get hired: fake identities and resumes, AI hiring tools and a U.S. address so they can be sent company equipment. It’s not just a scam, it’s a systemic operation that North Korean IT workers are working on in the USA.
The starting point is through fake identities and fake resumes. Stolen identities of real Americans are used to create plausible profiles for operatives. Most of the fake resumes look polished and are optimised for keywords and most automated screening programs. It’s difficult to detect such employment fraud because the credentials — their social security numbers, addresses, work history, etc. — are real people’s credentials.
The recruitment interview stage is managed using artificial intelligence tools.The interview stage of the recruitment process uses AI tools. In video calls, the operatives use generative AI and interview assistance software to respond to technical questions live. Deepfakes can make it easier to disguise accents and to change appearance. It’s the use of AI that makes this generation of “help-wanted” scams so hard to catch: Signs that used to alert people no longer do.
Closes the Loop Laptop Farms. After hiring a fake IT worker, the company mails a laptop to a seemingly legit United States address. It’s an address of a recruited American, either a knowingly involved one or a fool who took it upon himself to bring in equipment for an easy passive income. Then, the device is accessed remotely from overseas, allowing North Korea to gain access to a network of a U.S. company.
Why Remote Workers Should Pay Attention
The first impact of IT workers from North Korea in the USA infiltrating a company network is not espionage, it’s friction for legitimate applications for work.
Meanwhile, U.S. companies are already reacting to the hiring of IT employees. Employers are now doing more than background checks as they become more aware of the risks of hiring an individual with a criminal past, or that a scam could be an IT hire, as both have become a prime concern in the cyber security sector.
The days of employment verification are increasingly becoming days of identity verification – the person on the video call is the same individual whose ID was provided. That doesn’t just apply to freelance IT workers or IT contractors who’ve applied through third-party platforms — it’s the very avenues the North Korean IT worker scheme used the most.
Hiring scams of this magnitude also create insider risk in companies that they are not expecting. If the hacker is able to obtain proper credentials and access to the system from a valid company, the threat is no longer from outside but from within. This could be even more dangerous than regular remote work scams, as workers are lured into defence contractors, research firms or critical infrastructure operators that can provide a gateway for wider North Korean cyber operations.
What Needs to Change in Remote Workforce Security
There are no quick and easy solutions to such a massive scheme, and cybersecurity experts know that law enforcement is no match for it. The answer to securing remote employees must lie within the hiring process.
That means you need to verify the identity of the individual online at the time of interview, not after. It’s about acknowledging fake IT workers as an insider threat type of problem and not just a hiring error. It means understanding that there’s a double side to AI hiring platforms—they can also be used to maneuver in with bogus job candidates.
The obvious request for the U.S. labor force is that they be prepared to prove who they are. Hiring identity fraud is now well established, and has become a state-sponsored crime that costs hundreds of millions of dollars annually.
FAQs on North Korean IT Workers in the USA
What makes North Korean IT workers hard to detect in remote job interviews?
North Korean IT professionals are difficult to spot at the job interview stage, when conducting a job interview remotely. They leverage generative AI and interview assistance to respond to inquiries on the spot, and use deepfake technology to mask appearance and accent – making remote hiring scams much more difficult to detect than they were 3 years ago.
How does this impact the legitimate applicants of US remote work?
Be prepared to go through additional identity verification, slower offers, and additional scrutiny on freelance sites. US Companies are sparing no pains to trim down the hiring process for IT workers, especially due to the North Korea IT worker scheme.
What makes North Korean IT workers hard to detect in remote job interviews?
Yes. The Treasury Department has said a new type of remote employment fraud is helping North Korea’s weapons of mass destruction and ballistic missile program — making cyber security threats here a direct national security threat.
The Bottom Line
The story of the North Korean IT workers in the USA is not just a cybersecurity bulletin. It’s changing the way we do our jobs, it’s changing the definition of proof of employment and it’s changing how Americans prove their identities in a fully digital job market. The North Korea cyber threat is in the front door — and for every remote job seeker, any employer or IT contractor, it can mean trouble.





