Black Hat USA 2026 is over, but the real work is just beginning. One of the most important briefings this year came from threat researcher Vangelis Stykas, who presented findings from 22 months spent inside North Korean command-and-control infrastructure. Five days earlier, agencies from 11 countries had issued a joint security alert regarding North Korean IT workers. The two announcements describe the same problem from opposite ends: one is a warning about who you might hire; the other is a count of what it has already cost. In this dispatch from Black Hat, we explain what each report tells us and what’s missing from the larger story.
1,640 Companies Infiltrated
Ahead of his Black Hat briefing, Stykas told WIRED he found evidence that 1,640 companies across 57 countries have been affected by North Korean operations. Of those, roughly 700 to 800 suffered what he described as damaging intrusions, including root-level access to servers and cloud environments.
Nearly all of it began the same way: a developer received a job offer with an unusually good salary, then was asked to run a coding exercise as part of the interview using a tool which installed malware on the engineer's device. Microsoft and others have tracked this technique, commonly known as Contagious Interview, since as early as 2022.
11 Countries Join the Fight
On July 31, security agencies from the United States, Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom issued a joint alert regarding North Korean IT workers.
Most of the tradecraft in it will be familiar to anyone who has followed this threat for any length of time: Forged and altered identity documents, third-party proxies who sit for the interview while someone else does the job, laptop farms in the United States that make a worker in Pyongyang look like a worker in Phoenix, payments routed through a facilitator's bank account or requested in cryptocurrency.
What's new is the length of the signature block. Eleven governments have now put their names to the same alert recommending that companies strengthen identity verification procedures.
That request is the right instinct. It is also, as this week's research showed, harder to satisfy than it sounds.
Every Common Hiring Fraud Indicator is Heuristic, Not Deterministic
The advisory closes with a list of warning signs. It's a good list, assembled by people who have studied these operations closely. It is also, item by item, a set of things that a well-resourced adversary already knows how to defeat.
- Profile and language quality. The advisory flags awkward machine-translated phrasing as a signal, then immediately concedes that North Korean operators use AI-powered translation services to produce convincing profiles and communications.
- Video interviews. The advisory lists manipulated or artificially generated video feeds as a signal, but relying on humans to spot these signs is unreliable at best. In other cases, the person on camera is a real human being interviewing as a proxy for the fraudster.
- IP address and location signals. Basic location checks can easily be fooled by VPNs, remote desktop software, and US-based laptop farms operated by collaborators.
- Document review. The advisory itself notes that identity documents used for verification often appear forged or altered with image editing software. Others are real documents borrowed from a proxy in a third country while the actual work is done elsewhere.
- Behavioral flags. Frequent changes to payment details, accounts operated by multiple people, unusual hours. Every one of these is observable only after the person is already inside.
- Background checks. Fraudsters simply use the stolen information of real people to pass background checks, which only verify information, not the person presenting it.
The reason infiltration keeps happening is not a failure of diligence. The failure is in the checks companies rely on. These checks aren't wrong, per se, but they were built for a time when producing a convincing false identity was expensive, and that time is over.
The Missing Ingredient to Stop North Korean Hiring Fraud
Traditional hiring checks evaluate artifacts: social media profiles, video streams, behavior, IP addresses, identity information, and so on. The missing ingredient is to verify the actual human behind those artifacts, which is precisely the gap Nametag fills.
Nametag embeds directly into an enterprise’s ATS/HRIS systems to automatically verify that every job candidate is a real person, a legitimate person, and the same person across interviews, hiring and onboarding. Our patent-pending Location Integrity™ technology closes the laptop farm vector by generating a tamper-resistant record of a person’s true physical location at the moment of verification. A proxy in Phoenix holding the laptop no longer covers for an operator working from somewhere else.
Learn more about how Nametag restores integrity to your hiring.


