The fake employee economy

The Fake Employee Economy: How North Korea Built a Nine-Figure Business Inside American Hiring

At 9:55 on the evening of July 15, 2024, a security alert fired inside KnowBe4, a company that trains corporate employees to recognize scams. A laptop the company had shipped to a newly hired software engineer had just come online, and in the company’s own words, “it immediately started to load malware.”

The device was contained 25 minutes later. Then came the uncomfortable part: reconstructing how the person on the other end of that laptop had been hired at all.

The answer, which KnowBe4 published on its own blog eight days later, was that nothing in the hiring process had failed in the way processes usually fail. Nobody skipped a step. The company had conducted four separate video interviews, matching the candidate’s face to the application photo each time. It ran a background check. It verified references. Everything came back clean, because the identity was real. It belonged to an American whose personal information had been stolen. The face on the application was a stock photograph that had been altered with AI. The engineer was, according to the company, a fake IT worker operating on behalf of North Korea, working the laptop remotely through an address inside the United States. KnowBe4 reported that no data was lost and turned its evidence over to the FBI, then did something unusual for a company that had just been fooled: it told everyone exactly how it happened.

At the time, it read like a strange story about one company’s bad week. Two years later, it reads like the first public glimpse of an industrial operation. The United States Treasury now attributes nearly $800 million in a single year to North Korean IT worker schemes. Federal courts have sentenced the scheme’s American enablers to terms as long as nine years. And in July of this year, six governments issued a joint alert that quietly abandoned the previous advice on catching fake candidates, because the fakes had outgrown it.

This is the story of how a job application became a weapon, told through court records, Treasury designations, and the accounts of companies that got hit. Every figure in it is attributed, because this is a subject where the numbers get embellished in the retelling, and the documented reality does not need embellishment.

The laptop farm

Start with the mechanics, because they explain everything else.

A North Korean IT worker cannot apply for an American remote job as himself. He needs three things: a stolen or borrowed American identity, an American address where company hardware can be shipped, and a way to work on that hardware from the other side of the world without the company noticing. The first is bought or stolen. The second and third are provided by a domestic industry that prosecutors have spent two years dismantling: the laptop farm.

The canonical case is Christina Chapman, an Arizona woman sentenced in July 2025 to 102 months in federal prison. According to the Department of Justice, Chapman ran a farm out of her home. Companies believed they had hired an American engineer; they shipped the laptop to Chapman’s address; overseas workers connected to those machines remotely and did the jobs. When investigators raided the house in October 2023, they recovered more than 90 laptops. Another 49 devices had been shipped overseas, including to a Chinese city on the North Korean border.

The scale of that one operation is worth sitting with. According to the same DOJ sentencing release, the scheme used 68 stolen American identities, defrauded 309 U.S. businesses, and generated more than $17 million in revenue, most of which flowed to North Korea.

The farms that came after Chapman show how professionalized the model became. In the case that produced the nine-year sentence, two New Jersey men ran farms dressed up as businesses, registering shell companies with names like Hopana Tech LLC and Tony WKJ LLC to receive equipment and payments. They attached keyboard-video-mouse switches to the laptops, the class of hardware that lets someone elsewhere operate a machine that appears to sit idle at its shipping address. DOJ says their scheme ran from roughly 2021 until October 2024, defrauded more than 100 U.S. companies using the identities of more than 80 Americans, and generated more than $5 million for North Korea. The two men collected nearly $700,000 for their trouble. Their victims spent at least $3 million on legal fees and network cleanup.

And the labor was not always civilian. Among the five people who pleaded guilty in DOJ’s November 2025 nationwide action was an active-duty U.S. Army soldier stationed at Fort Gordon, who hosted a laptop farm while serving and was sentenced in March to 12 months and a $193,265 forfeiture, according to court records.

The identity supply chain

The farms solve the hardware problem. The identities come from somewhere else, and that somewhere turns out to be a market.

One of the November 2025 guilty pleas belonged to Oleksandr Didenko, a Ukrainian man who ran a website called Upworksell.com. Its product was other people’s employability: accounts on freelance platforms and the stolen American identities to operate them. Didenko admitted to 871 proxy identities, according to court records, and his operation touched some 40 U.S. companies. He agreed to forfeit more than $1.4 million, according to the Justice Department.

That detail changes the picture. If identities are inventory, then any individual fraudster’s arrest removes a customer, not the store. It also explains a fact that surprises most hiring teams: the background check is the control these operations defeat most reliably, because a background check confirms that an identity exists and is clean. It does not confirm that the person in the interview owns it.

The consequences of that gap are not hypothetical. In December 2025, a Maryland man named Minh Phuong Ngoc Vong was sentenced to 15 months for a scheme in which he obtained jobs at more than 13 companies that paid more than $970,000 for work actually performed by an overseas co-conspirator, a man in Shenyang, China, whom DOJ describes as likely a North Korean national. More than $28,000 of that came from a Virginia company for work on an FAA contract involving a national-defense-related software application. Read that again: work on federal aviation systems, performed by an unvetted stranger overseas, billed through a rented American face.

The money, and where it goes

For most of this saga there was no official national figure, only case totals. That changed in March, when the Treasury Department sanctioned a facilitation network and stated that these schemes generate revenue for North Korea’s weapons programs “including nearly $800 million in 2024.”

That sentence deserves more attention than it received. It is a specific, single-year, U.S. government dollar figure for fake employees, and it does not include North Korea’s cryptocurrency theft, which is tracked separately and is larger still.

The sanctions trail also maps the operation’s geography, which is broader than most coverage suggests. The March 2026 designations named a DPRK company, a Vietnamese front company, and facilitators in Vietnam, Laos, and Spain. An August 2025 action named a Russian national who facilitated nearly $600,000 in cryptocurrency conversions, a Russia-based North Korean official, and a Chinese front company whose delegation of IT workers had earned over $1 million in profits since 2021. A November 2025 action reached the financial layer, designating eight individuals and two entities tied to moving the money, including Ryujong Credit Bank. This is not a hacker in a basement. It is a supply chain with HR, payroll, and treasury functions, distributed across at least half a dozen countries.

The workers themselves see little of the money. A joint State, Treasury, and FBI advisory has estimated that individual workers can earn more than $300,000 a year in some cases, with the regime withholding up to 90 percent of wages. The Justice Department said in January 2025 that hundreds of millions of dollars a year flow through these schemes to sanctioned entities including North Korea’s Ministry of Defense and its weapons programs, according to a DOJ indictment announcement. The person debugging a U.S. company’s code at midnight is, functionally, a revenue instrument.

And the losses are not confined to salaries. In the New Jersey case, DOJ says the stolen material included ITAR-controlled defense contractor data involving artificial intelligence technologies. In August of this year, FBI Deputy Assistant Director Todd Hemmen told Federal News Network that the bureau had identified a North Korean remote IT worker employed by the federal government itself.

The volume nobody sees

The prosecutions describe the operations that succeeded. The more unsettling numbers describe the ones still knocking.

Amazon’s chief security officer wrote, as reported in December 2025, that the company had stopped more than 1,800 suspected North Korean operatives from getting hired since April 2024, and that applications linked to North Korea were rising about 27 percent per quarter. SentinelOne, a cybersecurity firm, published an analysis of roughly 360 fake personas behind more than 1,000 applications to its own job postings, including applications to its intelligence engineering team, the group that produced the analysis. The CEO of Pindrop, a voice security company that itself sells deepfake detection, told Fortune his firm was finding one in 343 of its own job applicants to be North Korean.

Those are three companies with unusually good visibility into their own applicant pools. Most employers have none. As Checkr found when it surveyed 3,000 U.S. hiring managers in 2025: 31 percent said they had interviewed a candidate who turned out to be using a fake identity, while only 19 percent were extremely confident their process would catch one.

Catching one in the act

A few companies have published, in detail, what it takes to unmask one of these candidates. The accounts are instructive, and a little absurd.

Kraken, the cryptocurrency exchange, described a 2025 case that began when a recruiter noticed the applicant had joined the call under a different name than the one on his resume, and that he appeared to switch voices mid-call. Industry partners had circulated a list of email addresses linked to North Korean operations; one matched the applicant’s. Open-source research linked him to multiple fake identities, VPN use, and altered identity documents. Rather than cutting the process short, Kraken advanced him to a final interview built as a trap.

The candidate believed it was a friendly chemistry conversation. Kraken’s security team sprinkled ordinary-sounding verification into the small talk, asking the candidate “to verify their location, hold up a government-issued ID, and even recommend some local restaurants in the city they claimed to be in.” In Kraken’s words, “the candidate unraveled. Flustered and caught off guard, they struggled with the basic verification tests.”

KnowBe4, after its own incident, went further. “Occasionally, we accept a few and interview the fake employees to learn more about them,” the company wrote in a February 2025 follow-up. One such applicant claimed to be from Dallas, then stumbled through technical questions and failed to catch a deliberately planted error about who runs Microsoft.

There is a temptation to read these stories as reassurance: ask about restaurants, and the fraud collapses. The security teams involved read them the opposite way. Both catches required a suspicious human, an unhurried process, and in Kraken’s case, threat intelligence most employers will never see. The candidate who reaches a chemistry interview has already survived resume screening, recruiter screening, and often several technical rounds. These were saves at the goal line, made by professional goalkeepers, and they were published precisely because the companies involved know most organizations would not have made them.

The AI turn, and the defenders’ retreat

What transformed this from an espionage story into a hiring-industry story is that the tooling stopped being exotic.

The fake photo on the KnowBe4 application was AI-enhanced. The six-government alert issued this July describes operators using “increasingly sophisticated methods, including the integration of AI, to obfuscate their identities,” and using large language models to write convincing profiles. Gartner, surveying the broader market in July 2025, found that 39 percent of candidates had used AI somewhere in the application process, projected that by 2028, one in four candidate profiles worldwide could be fake, and found that 6 percent of candidates admitted to interview fraud already: posing as someone else, or having someone else pose as them.

You can watch the defenders’ confidence erode in the official guidance. In July 2025, the FBI’s advice for spotting an AI-generated candidate on a video call included asking the person to wave a hand in front of their face, because the motion could glitch the deepfake. It was a good trick, and everyone understood it was a trick with a shelf life.

The July 2026 alert, issued jointly by the United States, Japan, the Republic of Korea, the United Kingdom, Australia, and Canada, does not repeat it. Instead it lists, flatly, as a red flag: “video feeds that appear to be manipulated or artificially generated.” No countermeasure offered. In one year, the guidance moved from here is how to catch it on camera to assume the camera can lie.

The rest of the alert’s red-flag list is worth reading closely, because almost none of it is about video. A candidate who refuses video calls entirely. Rates offered below the market, because when the goal is volume, underpricing wins placements. Signs that one account is being operated by several people. Identification documents that appear altered with image editing software. Payment requested in cryptocurrency. Multiple accounts reached from one IP address. These are consistency failures, visible in documents and records, not performances that must be caught live.

Washington’s other response is still forming. A bill introduced in the House this July, the North Korean FAKER Act, would push the State Department to coordinate detection and disruption with allies. It is a bill, not a law. The eleven-nation Multilateral Sanctions Monitoring Team, a separate body from the six-nation alert, reported in October 2025 that the DPRK has stolen and fraudulently obtained billions of dollars through its combined cyber and IT worker activity. For now, the practical burden sits where it has sat for two years: on whoever reads the application.

And the playbook is no longer exclusive to its inventors, because it was never patented. North Korea is simply the most heavily funded early adopter of techniques anyone can now run with consumer tools. When Checkr surveyed 1,000 business leaders this spring, 49 percent said they had already extended a job offer to a candidate who had misrepresented their qualifications using AI, and 62 percent agreed that AI has made traditional resume screening effectively obsolete. GetReal Security found that 41 percent of enterprise security leaders said their company had hired and onboarded a fraudulent candidate. The nation-state built the machine. The machine does not check passports.

Why every control fired late

Look back at the KnowBe4 case, the one with the most detail on record, and notice what each safeguard actually verified.

The background check verified that the identity was real. It was, it was stolen. The reference check verified a work history. The history was constructed. Four video interviews verified that a live human matched the photo. A live human did, behind an AI-altered photo, and in current cases, increasingly behind an AI-altered face. Endpoint security caught the malware, 25 minutes after activation, which is to say: after the badge was issued, after the laptop was shipped, after the operative was an employee.

Every control fired. Every control fired after the hire.

This is the structural insight the last two years of court records keep repeating. Hiring fraud is not defeated at the moment of onboarding, because by onboarding the deception has already survived every checkpoint. And the earliest signal of all is the document. Every candidate submits one, before any interview is scheduled, before any commitment is made, and it is the one artifact in the process that almost no organization examines for authenticity.

What this means for anyone who hires

The North Korean operation will keep supplying headlines. There will be more indictments, more sanctions, and eventually a public breach traced to a fake employee that makes the KnowBe4 near-miss look lucky. But the durable story is not about one country. It is that the cost of manufacturing a credible candidate has collapsed, the revenue from doing so at scale has been demonstrated to the nine-figure standard of proof, and the standard corporate hiring process, built to assess honest people, verifies almost nothing an adversary cannot fake.

The six-nation alert reads, between the lines, like an admission that governments cannot fix this at the interview stage. Neither can interviewers, not reliably, not at scale, and not once the deepfake stops glitching. The organizations that handle it will be the ones that move verification to the front of the process, where the fraud actually enters: the application, the document, the identity, checked before anyone spends an hour on a video call deciding whether they like the person the camera shows them.

The interview is where fraud gets confirmed. It is almost never where it gets caught.

Sources

QuantumRecruit screens every candidate for position match, content authenticity, and fraud risk, before the first interview is scheduled. Book a demo to see what it finds in your applicant pool.

Similar Posts