Hired, Fired, Extorted: What North Korean IT Workers Reveal About Hiring Fraud

by
North Korea Blog Post Header

What Unverified Identity Costs Enterprises Every Year

An industry-by-industry breakdown of what unverified identity costs enterprises every year.

TL;DR:

  • A fraudulent hire collects salary for a median of 122 days before detection
  • North Korean IT workers have shifted from collecting wages to stealing IP and extorting companies on the way out
  • 309 US companies named in a single federal case. 166,000+ applications from 22 operatives. $800M generated in 2024.
  • Gartner estimates candidate fraud accounts for 25% of application volume in remote tech roles
  • Annual cost: $699K to $1.99M per enterprise before OFAC exposure of up to $26.7M per placement
  • The hiring pipeline was not designed to catch this. Verifying the human before hire is the missing control.

In late 2024, a contractor at a US company was terminated after security flagged suspicious activity. Within hours of being let go, the contractor sent the company's stolen source code and proprietary data back to the organization with a ransom demand: pay, or the data goes public. However, the contractor was not a disgruntled employee, they were a North Korean operative who had been placed through a standard hiring process, using a stolen identity, and had been exfiltrating data from the day the job started.

The North Korean IT Worker Defense Checklist 7 hiring checks that actually work (because the ones in the multi-country alert don't). Get the checklist

From Wage Fraud to Extortion: How North Korean IT Workers Escalated

The original story was simple, North Korean IT workers were using stolen and fabricated identities to land remote jobs at US companies and funnel wages back to fund the regime's weapons programs. The risk to the employer was primarily financial. If the worker turned out to be a sanctioned individual, OFAC liability applied. The worker collected a paycheck. The regime collected the revenue. The company, if it ever found out, faced a compliance problem.

That is no longer the primary risk.

In January 2025, the FBI issued a public service announcement that changed the framing. NK IT workers were now conducting data extortion. After being discovered on company networks, they held stolen proprietary data and source code hostage until companies met ransom demands. The FBI observed workers exfiltrating sensitive data, facilitating criminal activity, and conducting revenue-generating operations from inside company networks.

The shift was from passive collection to active aggression. CSIS documented operatives installing backdoors for follow-on operations and threatening data leaks after termination. Some workers have filed legal complaints and workers' compensation claims after being caught, buying time before their access is fully revoked.

As Palo Alto Networks' Threat Vector podcast detailed, the shift is a direct result of increased identification. Because the operation is more widely recognized, operatives are more aggressive on exit. The primary threat is no longer sanctions from the Treasury. It is operatives who enter looking for crown jewels and use them as leverage the moment they are caught.

The 122-day median dwell time cited in Nametag's Cost of Doing Nothing report is not just the window during which a fraudulent hire collects salary. It is four months of access to internal systems, customer data, source code, and trade secrets, held by someone with an explicit mandate to extract value by any means available.

166,000 Applications, 309 Companies, $800M in Revenue

This is not a handful of incidents. The operation is industrial.

A single 2025 federal case named 309 US companies that had unknowingly placed North Korean operatives on payroll, including Fortune 500 firms in technology, aerospace, automotive, and media. Mandiant's Chief Technology Officer stated publicly that every Fortune 500 company has received NK IT worker applications, and that nearly every CIO he has spoken to has admitted hiring at least one.

Amazon blocked over 1,800 suspected DPRK applications between April 2024 and mid-2025, with attempts rising 27% quarter over quarter. Research from Nisos found that just 22 North Korean operatives submitted 166,893 job applications between December 2024 and September 2025, securing over 21,000 interviews and 76 job offers.

On the enforcement side, the DOJ announced coordinated nationwide actions in July 2025. The FBI searched 21 locations across 14 states and seized 137 laptops from domestic "laptop farms" where US-based accomplices hosted equipment to make NK workers appear to operate from American locations. In May 2026, two US nationals were sentenced to 18 months in prison for running one of those farms. OFAC reported the scheme generated nearly $800M in 2024 alone.

A Gartner survey found that candidate fraud now makes up roughly 25% of application volume in remote technology roles. One in four applications. And the techniques are getting harder to spot. Palo Alto Networks' Unit 42 has documented NK operatives using real-time deepfake technology during video interviews, with a single operator able to interview for the same position multiple times under different synthetic identities. Experian's 2026 Future of Fraud Forecast rates deepfakes outsmarting HR as the second-highest fraud threat of the year.

The Annual Cost of Hiring Fraud Across Industries

Nametag's Cost of Doing Nothing report models the hiring fraud cost for a 15,000-employee organization across three buckets.

The first is investigation labor. Screening suspect applicants, cross-referencing profiles, validating headshots, and verifying employer histories runs to roughly 2,600 recruiter hours and $112,000 per year, whether or not those investigations catch anyone.

The second is the cost of the hires that get through. A fraudulent hire draws salary against the 122-day median dwell time, produces effectively zero output, and leaves a vacancy and ramp cost behind. For a typical enterprise, that runs to roughly $1.08M annually across approximately eight successful fraudulent placements per year.

The third is OFAC sanctions exposure. Civil penalties for paying a sanctioned individual are strict liability. Intent does not matter. Awareness does not matter. The penalty runs at up to $377,000 per paycheck, and every paycheck is a separate violation. Nine paychecks over a 122-day dwell. That is up to $26.7M from a single hire.

Across industries, the annual hiring fraud cost before OFAC ranges from $699K in hospitality and retail to $1.99M in technology. Healthcare runs to $1.24M. Education runs to $1.19M.

One note on enforcement: to date, no OFAC actions have been filed against companies that inadvertently hired NK IT workers. Those companies have been characterized as "victims." How long that characterization holds as the threat becomes more documented and the expectation of due diligence rises is an open question. The Gartner data and the FBI advisories are building the public record that makes 'we didn't know' harder to argue.

Why Background Checks, References, and Video Interviews Aren’t the Solution

Background checks confirm that records match a stated history. They do not confirm the person presenting the records is the person those records belong to. Reference checks confirm that an employment history is plausible. Video interviews confirm that a face matches a document. Document verification confirms that documents are formatted correctly.

NK operatives beat all four. They use stolen identities with real, clean records. They build fabricated reference networks. They use real-time deepfakes to present synthetic faces that match stolen identity documents during live video interviews. They submit correctly formatted documents that belong to someone else.

Each step in the hiring process does what it was designed to do. None of them answer the question the entire hiring fraud cost dimension depends on: is the person behind this application the person they claim to be?

What Identity Verification Changes for Hiring

When the human behind the identity is verified before hire, the 122-day dwell time drops to zero. The salary, ramp, and vacancy cost never accumulates. The OFAC exposure never lands. The IP never leaves. The extortion never starts.

The $112,000 in annual recruiter investigation labor shifts from manual screening into a process that produces a verified identity record. The eight fraudulent placements per year that succeed under current processes do not make it through. The $26.7M in OFAC exposure per placement becomes a risk that was identified and stopped before the first paycheck was issued.

That does not require a new hiring process. It requires one additional step in the existing one: verifying that the human presenting the identity is the person it belongs to. That is the control the hiring pipeline has never had.

For the full breakdown across all four cost dimensions and six industries, read the Cost of Doing Nothing report.

Secure your helpdesk against social engineering and impersonators.
Decline
Accept All Cookies