Getting your Trinity Audio player ready...

Author: John Farley

null

A rapidly growing cyber risk facing organizations is the infiltration of corporate environments through fraudulent remote workers. These are often referred to as "DPRK IT worker schemes," "imposter employees," or "fraudulent remote hiring operations." Unlike traditional cyberattacks that originate externally, these incidents begin as employment fraud but many times evolve into advanced cyberattacks that involve unauthorized network access, intellectual property theft, privacy breaches and insider threats that can lead to regulatory exposure and/or sanctions violations. This risk is particularly concerning because the attack vector bypasses many traditional perimeter security controls by embedding a malicious actor inside the organization with legitimate credentials, approved access and trusted status.

How it works

Fraudulent workers often obtain employment through stolen identities, falsified documents, fabricated resumes, fraudulent references, AI-enhanced personas and third-party facilitators. Once hired, these individuals can gain access to internal systems while simultaneously generating revenue that may support sanctioned foreign actors. These incidents can involve malware deployment, data exfiltration, sanctions evasion and intellectual property theft.

The US State Department and FBI, jointly with their regulatory counterparts in the UK, Canada, Japan, South Korea, Australia, Germany, France, Italy, the Netherlands and New Zealand issued an advisory on July 31, 2026 highlighting instances of North Korean IT workers deploying these tactics.

Risk mitigation best practices

There are several strategies organizations can deploy that may mitigate this risk. Specifically, organizations should consider certain technical controls and risk management techniques during the pre-hire and post-hire phase of employment.

Insurance considerations

Organizations should evaluate whether cyber policies respond to insider threats, unauthorized access, data theft, privacy events and fraudulent employee incidents. Potential coverages may include access to incident response experts, forensic investigations, breach counsel and remediation expenses. If personal information is compromised, coverage may help address defense costs, regulatory investigations, notification requirements, credit monitoring and third-party claims. There should also be a review of other policies, including crime policies. These may cover employee dishonesty, payroll fraud, social engineering and funds transfer fraud exposures.

Are Your Insurance Policies Ready for AI Risks?

Explore how AI-related risks are evolving and what organizations should consider.

Assess Your Coverage

Takeaways for risk managers

The rise of DPRK-linked remote worker schemes represents a convergence of employment fraud, cybercrime, insider threat activity, intellectual property theft and sanctions risk. Organizations should resist viewing these incidents solely as HR issues. Once these employees obtain system access, the risk evolves to that of a cyber event, requiring coordinated response among HR, legal, operations, cybersecurity, compliance and risk management teams.

Based on government guidance, the most effective defense combines enhanced hiring controls, continuous identity verification, endpoint monitoring, Zero Trust security, geolocation validation and disciplined access management. From a risk transfer perspective, organizations should carefully evaluate cyber, crime and any other insurance policies to ensure that fraudulent worker events, insider threats, privacy incidents, forensic investigations and resulting liability exposures are adequately addressed before an incident occurs.

Author Information