It’s been one week since The Wall Street Journal published a landmark documentary detailing how North Korea is stealing American identities to get operatives hired into IT jobs at U.S. companies. Now that the dust has settled, what can we learn?
On August 12, The Wall Street Journal published a video documentary detailing how North Korean IT workers get hired at U.S. companies. It includes never-before-seen data and interviews, but much of the tradecraft described has already been uncovered in prior reporting: a joint security alert from July 31 describes operatives using AI-written résumés, forged identity documents, and laptop farms in American suburbs. Much of that security alert, in turn, describes tactics, techniques and procedures (TTPs) that already featured in the FBI’s original public service announcement from October 2024.
From this, an important question takes shape: Why hasn’t the growing awareness of North Korea’s IT fake workers stopped companies from getting breached?
The Journal's yearlong investigation is built on a leaked trove of browser histories, emails, calendars, and screen recordings. It shows how a single DPRK team was able to infiltrate at least eight U.S. companies, using AI at nearly every stage. Screen recordings show North Korean operatives reading interview answers directly from ChatGPT. As hiring managers got better at spotting them, the team adopted AI face-swapping tools.
“The entry criteria for having your identity stolen by a North Korean employment fraud operation is as simple as having a LinkedIn profile, a common name, a developer job title, and no profile picture.” – Hayden McKenzie, Security Researcher
So why does the "fake IT worker" scheme keep working?
Despite growing awareness, breaches continue because the checks and signals that companies rely on to vet their job candidates detect indicators of fraud, not fraud itself.
Most companies focus on spotting things like fake social media profiles, machine-translated messages, suspicious VPN exit nodes, virtual phone numbers, inconsistent language skills, or a mismatch between the email on a résumé and the email on a Zoom invite. But each of these signals is easy to spoof, bypass or exploit, or explain way. None can truly be relied upon.
Moreover, an operator manual newly uncovered by security researcher Hayden McKenzie shows that the attackers are now bypassing this arms race entirely. North Korea is increasingly recruiting real Americans who earn a 20% commission for the use of their identity and infrastructure, or 30% if they appear on live video calls as a stand-in for the North Korean.
How to Close the Door on North Korean IT Workers
The failure that lets North Korean IT workers in the door is twofold:
- Hiring checks which verify information about a person, not the person themselves.
- Hiring processes which treat identity verification as a gate someone must pass through only once.
The crisis won't be resolved by simply adding more checks and signals into your candidate evaluation regimen. The only way to truly close the door on North Korean IT workers is to combine those signals (resume validation, background checks, etc.) with deterministic identity assurance embedded into your hiring and onboarding processes, with periodic re-verification throughout employment to prevent proxy swaps.
“The era of implicit trust in hiring is over. Preserving the integrity of the workforce means making identity verification the foundation on which every subsequent hiring decision is built.” – Aaron Painter, CEO at Nametag
Companies must verify people — not just information — using verification techniques that answer four questions definitively:
- Who is this person claiming to be?
- Are they really that person?
- Where are they actually located?
- Are they the same person as before?
The most reliable way to answer these questions is through workforce-grade identity assurance technology embedded into your hiring and onboarding processes, and then repeated at intervals afterward. Look for a vendor that:
- Prevents the use of deepfake selfies and forged IDs using cryptography.
- Establishes where a person physically is beyond spoofable network signals.
- Integrates directly into your existing HR, IAM, IT, and security systems.
- Re-verifies people in seconds with a selfie alone, skipping the ID scan.
Nametag is the first identity assurance platform purpose-built to protect your workforce against advanced threat actors like North Korean IT workers. Read the North Korean Defense Checklist below, or learn more about our workforce solutions.


