Author: John Farley
A rapidly growing cyber risk facing organizations is the infiltration of corporate environments through fraudulent remote workers. These are often referred to as "DPRK IT worker schemes," "imposter employees," or "fraudulent remote hiring operations." Unlike traditional cyberattacks that originate externally, these incidents begin as employment fraud but many times evolve into advanced cyberattacks that involve unauthorized network access, intellectual property theft, privacy breaches and insider threats that can lead to regulatory exposure and/or sanctions violations. This risk is particularly concerning because the attack vector bypasses many traditional perimeter security controls by embedding a malicious actor inside the organization with legitimate credentials, approved access and trusted status.
How it works
Fraudulent workers often obtain employment through stolen identities, falsified documents, fabricated resumes, fraudulent references, AI-enhanced personas and third-party facilitators. Once hired, these individuals can gain access to internal systems while simultaneously generating revenue that may support sanctioned foreign actors. These incidents can involve malware deployment, data exfiltration, sanctions evasion and intellectual property theft.
The US State Department and FBI, jointly with their regulatory counterparts in the UK, Canada, Japan, South Korea, Australia, Germany, France, Italy, the Netherlands and New Zealand issued an advisory on July 31, 2026 highlighting instances of North Korean IT workers deploying these tactics.