
by David Head, CEO and co-founder of Endorsed
Since 2018, the UN estimates North Korea has generated between $250 million to $600 million per year by tricking companies into hiring them as remote IT workers. They’ve been so successful that hundreds of Fortune 500 companies have hired them. Sometimes a few dozen each.
That money helps fund North Korea’s weapons program. That gives South Korea a stake in hiring decisions made far beyond its borders.
This started in 2014. When COVID lockdowns came in 2020, the number of remote positions exploded, and so did their operations. When AI became widespread in 2023, they started using the same mass job application tools that normal job seekers were, further growing their operations.
The company I founded, Endorsed, found that now about half of remote IT applications in the United States show DPRK IT worker scheme patterns. I’ll share how this scheme impacted our customers, the obstacles the IT workers have to overcome, and the tactics they use.
For context, we sell recruiting productivity tools. In early 2025, our flagship product was an AI tool that helped recruiters find great job applicants. One day our customers started complaining that most of the “great applicants” were actually “fake.”
Recruiters said during interviews, candidates would appear to be reading off an AI script, they wouldn’t know anything about the location they claimed to live in, and often, different people were showing up from one interview to another. This was happening multiple times per day for each recruiter in some cases.
Our team looked into what was happening, and to our surprise, the North Korean IT worker scheme appeared to be the primary culprit. So to give recruiters their productivity back, we re-focused the company on building tooling to catch fraudulent job seekers.
While learning about the problem, we explored the DPRKs tactics through conversations with US law enforcement, cybersecurity researchers, our own customer base, and conversations with North Korean escapees like Hyun-Seung Lee and anonymous IT workers.
In the United States, getting hired and paid can mean clearing all of these obstacles:
- Get their job application picked for an interview out of ~200-1000 applicants
- Pass multiple camera-on interviews
- Sometimes show up to an on-site interview at the company office
- Pass an ID verification
- Pass a background check
- Accept a laptop at a local address
- Evade their new employer’s security team
- Accept payment
- Wire that payment back to Pyongyang
How they bypass these checks is through the use of AI, local facilitators, stolen identities, and money laundering rings.
Here is how they bypass each corresponding step:
- Use AI to create multiple perfect looking job applications with entirely fake experience. They claim to be someone they found on LinkedIn with an impressive resume, and sometimes no profile picture that a recruiter could cross-reference.
- Have team members specialized in doing interviews in English, while others do live coding behind the scenes, or they use a paid interviewer.
- Hire a local facilitator who will show up on your behalf.
- Buy stolen identity packs on the dark web from lists of millions for ~4.5 each.
- Use e-Verify to test whether the stolen government ID will pass a background check.
- Use the same or another local facilitator to install the laptop at their home
- Install remote desktop software or a KVM device so the IP looks like it’s coming from the home and there is no VPN visible
- Use the same or separate local facilitators to accept the payment
- Launder the money through a crypto network
As you can see, it’s incredibly sophisticated, and when teams like ours evolve our systems to catch them, they adapt their tactics accordingly.
For the companies that accidentally hire them, it can be very scary.
One company accidentally hired a contractor from a $20b staffing firm who may have been a North Korean operative. The candidate passed two government ID checks and a background check. Endorsed however flagged him as having High Risk Patterns.
Upon deeper investigation, the individual didn’t have a trace of a real identity on the internet, wasn’t using his company approved laptop, was making excuses for why he couldn’t turn it on, and at the last minute he installed unapproved remote laptop software, which was the smoking gun.
They ended the engagement, and their senior recruiting and security leadership had a long meeting about how to never have that happen again.
So why does this all matter to South Korea?
Firstly, South Korean companies are impacted as well. These IT workers aren’t just working for the salary either. They are exfiltrating the code and data and using that for extortion.
Then more importantly, this money is reported to fund the DPRK’s weapons program.
Have recruiting and security review your current remote IT workforce together, including contractors. Get executive backing to investigate when the identity, interviews and actual work don’t line up.
Finally, spread awareness. Many companies think that this problem isn’t happening to them. They think it is a sensationalist news article. I did at first too.
If you accidentally hired one, consider sharing intelligence with the community, like Amazon did.Or, if you want to stay a little more private, share it with your cybersecurity peers.
The hiring decision may happen overseas. South Korea still has a stake in getting it right.
David Head is the Co-Founder and CEO of Endorsed, an AI-powered recruiting security company focused on detecting identity fraud and fraudulent job applicants. A technology entrepreneur with experience in talent marketplaces and AI-driven hiring, Head now focuses on the growing intersection of AI, cybersecurity, workforce fraud, and national security, including the threat posed by North Korean IT-worker schemes.





