In March 2025 EBN wrote that fake candidates were not new and that employers had simply got worse at spotting them. Eighteen months on, that reads as optimistic.
On 12 August 2026 the Wall Street Journal published Infiltrated: North Korea's Secret U.S. Workforce, a documentary built on a year of reporting and a trove of hacked data pulled from the computers of one North Korean IT worker team. The material included browser history, emails, stolen identity documents and screen recordings of the workers' own job interviews. The Journal says it reached out to nearly 300 companies, recruiters and hiring managers who appear in the film. Many did not respond or declined to comment.
What the data showed is worth contemplating, because it is an operations story before it is a security story.
In just over three months, one small team applied to more than a thousand companies. A single week of the team leader's Google Calendar from January 2025 shows 22 job interviews using at least seven identities. The team was hired for at least nine roles at companies in the US and the UK. Three men appear on camera under three names. A private Discord server coordinates resumes and cover letters. Their shared Google Docs include interview prep for four employers under three applicant names, plus notes on how to pronounce their own cover names.
Read that as an org chart. It describes a recruitment agency.
The screening advice has moved on since March 2025
Our first piece recommended running CVs and cover letters through AI detection tools. That was the standard advice at the time, repeated by vendors and by most of the trade press. It has since been overtaken, and it is worth saying why.
Two things moved. The first is that AI-written application material became ordinary, so a positive result now tells you almost nothing about intent. The second is that the detectors turned out to be unfair. A Stanford-led study published in Patterns in July 2023 tested seven detectors on 91 TOEFL essays written by non-native English speakers and found an average false positive rate of 61.3%. The same detectors correctly identified over 90% of essays by US-born eighth-graders as human-written. Deploy that at the top of a funnel and you filter out honest applicants who learned English as a second language, while the actual operation (which has a dedicated resume team) sails through.
The March 2025 piece framed this as a detection problem for hiring managers, which is where the whole industry was looking at the time. The more useful frame, eighteen months later, is a supply chain problem.
The numbers, and how much to trust them
Estimates of what this earns Pyongyang vary a lot, and the variance matters.
The Journal cites roughly $800 million a year. A Center for Strategic and International Studies analysis published on 24 March 2026 by Yena Kim and Donghee Kim puts the range at $350 million to $800 million annually as of 2024. UN Panel of Experts figures cited in a June 2026 Skadden client alert give a narrower $250 million to $600 million. All three are estimates of a deliberately obscured cash flow, and none should be quoted as a hard number.
The figures on scale inside hiring funnels are firmer, because companies are counting.
Your employees know the truth. Does your EVP? At Fathom we measure the "Credibility Gap" between your promise and their reality.
Amazon told the Journal it has blocked more than 2,900 suspected North Korean operatives from joining since April 2024, and that it has never directly hired one. In December 2025 the company's chief security officer, Steve Schmidt, put the figure at 1,800, and said Amazon was detecting 27% more DPRK-affiliated applications quarter on quarter. Both counts are company-supplied and cover blocked applications rather than confirmed operatives, and the 2,900 figure appears only in the WSJ film, so EBN could not independently verify it.
Okta's threat intelligence team published the widest count. In a report dated September 2025, it linked more than 130 identities to over 6,500 initial job interviews at more than 5,000 distinct companies between 2021 and mid-2025. CrowdStrike's 2026 Global Threat Report, published on 24 February, found DPRK-linked incidents up more than 130%. Activity by the group it calls FAMOUS CHOLLIMA more than doubled during 2025.
Europe is now in scope too. Google Threat Intelligence analyst Jamie Collier reported in April 2025 that one worker ran at least 12 personas across Europe and the US, with fabricated references. His targets included employers in Germany, Portugal, the UK, Serbia and Slovakia.
Gartner's forecast is the one most often quoted in HR circles: by 2028, one in four candidate profiles worldwide could be fake. It is a prediction rather than a measurement. The measured figure underneath it is smaller and more awkward: in a Gartner survey of around 3,000 candidates, 6% admitted to taking part in interview fraud themselves.
Procurement is where the weak point sits
The most useful finding in the WSJ film for talent teams has nothing to do with deepfakes.
Tim and Charlie Richardson, a father and son running a startup called Visual PT, hired a software developer in early 2025 through an external recruiter. "The recruiter had told us that his English wasn't good, but once you reviewed his code, there was a sense like, hey, this guy might be our guy," Tim Richardson said. They found out the developer was misrepresenting himself when the Journal contacted them for an interview. "My mind is blown right now," he said.
The same operative worked under a different name at Subly, a British tech company, where a manager can be seen on a recorded call telling him his communication is not good enough.
Third-party recruiters are described in the documentary as a force multiplier for the scheme. One submitted application gets pushed to hundreds of open roles, and agencies that are paid on placements have thin incentives to slow down and verify. A US official interviewed for the film put it bluntly:
"We've seen this at our government. They got in and they got in because a third-party service they didn't do their due diligence and they hired an IT worker."
On 28 July 2026 an FBI official confirmed the bureau is investigating a North Korean who worked as a remote IT staffer for a US federal agency. The agency has not been named and the FBI declined to comment to TechCrunch.
If your organisation uses agencies, RPO, staffing marketplaces or contractor platforms, that is where the exposure sits. Vetting standards are only as good as the least rigorous supplier in the chain, and most contracts do not specify them at all.
The detection game is moving off camera
Hiring teams have got better at the live interview. The film shows recruiters ambushing candidates with questions about local weather and location, and one investigator describes a test involving an insult to Kim Jong Un that the workers will not say out loud.
Those tricks are already being engineered around.
Real-time face swapping has improved to the point where the operation's next move, according to investigators in the film, is getting North Korean faces off camera entirely. "Next year, we will be talking about where did all the IT workers go," one said. "I can't find them anymore."
Two other adaptations are worth logging. The first is subcontracting: win the contract, then repost the job at a lower price and pocket the difference. Investigators describe a $5,000 job passed to a worker in the Middle East for $500. The second is recruiting English-speaking facilitators to sit the interviews in person, which removes the accent and hesitancy tells that most current screening depends on.
Employer branding works better when people share what they know. EBClub brings practitioners together to exchange ideas, compare experiences, and learn from the people doing the work.
Derrik Goon, an Ohio man who ran a laptop out of his home for the cell, described the arrangement to the Journal in his own words. "They would schedule up interviews and then I'd sit and do these interviews with 'em. All I had to do was just show up and, you know, land the job." He says he split the salary and was paid in crypto, and that he did not know the team was North Korean. He later received a 1099 from Upwork showing nearly $100,000 in freelance income under his name that he says went to them.
He is not a sympathetic figure. He is also, on the evidence, not the last one: the cell asked him to recruit more people like himself, offering around $500 a referral.
Enforcement is real, and it is not the answer on its own
The prosecutions since our last piece have been substantial.
On 30 June 2025 the Department of Justice announced coordinated nationwide action covering two sweeps: 21 searches across 14 states that month, which yielded around 137 laptops, and 8 locations across 3 states in October 2024, which yielded more than 70. Media coverage aggregated the two as 29 laptop farms across 16 states.
The sentences followed. Christina Chapman, who ran roughly 90 laptops from her Arizona home and helped place workers at 309 companies generating $17.1 million, got eight and a half years in July 2025. Kejia Wang received nine years and Zhenxing Wang seven years and eight months for a scheme that touched more than 100 American companies. In May 2026 two more US nationals, Matthew Knoot and Erick Ntekereze Prince, were sentenced to 18 months each.
"North Korean IT worker schemes would not be successful without U.S.-based facilitators," Assistant Attorney General John Eisenberg wrote in a sentencing memo.
Then came the joint alert. On 31 July 2026, twenty agencies across Australia, Canada, France, Germany, Italy, Japan, South Korea, the Netherlands, New Zealand, the UK and the US named AI-assisted identity obfuscation and third-party interview proxies as the current tactics. Their advice to employers includes mandatory in-person interviews.
An official in the film is honest about the limits: "We're under no grand illusion that we're gonna arrest our way out of this problem."
What this means for employer brand
Verification is now a TA cost centre. Identity checks, live coding under observation, reference calls placed through switchboards rather than to candidate-supplied numbers, kit shipped only to the address on the ID: all of this sits in the recruiter's workflow rather than security's. It lengthens time-to-hire and it costs money. Most TA teams have been handed the responsibility without the budget or the training, and often without anyone to escalate to. Rivka Little of Socure described that gap to The Register in July 2025: "It's not uncommon that an HR leader wouldn't be exposed to a CTO or a CISO or a head of fraud, and so they may be experiencing this pattern and not necessarily knowing what to do with it."
Employer branding now has a measurement standard. The Talent Gravity Standard is a six-driver framework for quantifying employer attractiveness and the gap between brand promise and employee experience.
Friction may cost less brand equity than assumed. Gartner's July 2025 survey found 62% of candidates were more likely to apply when a role required in-person interviews, and only 26% trusted AI to evaluate them fairly. Read carefully, that is permission to slow down. The trade-off is geographic: a mandatory in-person round narrows the pool and quietly penalises carers, disabled candidates and anyone who cannot travel, which is a fairness problem employers should own rather than absorb silently.
The profiling risk is the real reputational exposure. The behavioural tells being circulated in hiring circles (accented English, delayed answers, a thin online footprint, an East Asian face paired with a Western name) describe an enormous number of legitimate people. "You can't profile people," Little said, and she is right, though the pressure to do so is rising. An employer that gets this wrong will not face a security incident. It will face a discrimination claim, a viral post from a rejected candidate, and a reputation for treating applicants as suspects.
There is one more group, and it has no voice in any of this. Michael Brown, whose stolen identity was used to work at companies he had never heard of, told the Journal that Department of Labor records showed him employed across eleven states and roughly $100,000 in income he never saw. He says he has been blacklisted, cannot open a bank account and cannot rent in his own name. "Somebody else is living like me right now."
Employers holding payroll records built on stolen identities are sitting on the paperwork those victims need. Very few have a process for handing it over.
The question worth asking internally
The uncomfortable read on the last eighteen months is that the North Korean operation industrialised hiring faster than most employers did. Twenty-two interviews in a week off one calendar, an aliases roster, a resume team, a dedicated interview specialist, a facilitator network and an AI-assisted answer pipeline. Set against the average corporate hiring process, it is better resourced and better instrumented.
Deepfake spotting is the wrong internal question, because it has no answer anyone can act on. Here is a narrower one. Who in your organisation is accountable for confirming that a new starter is the person who was interviewed, and does that person know it is their job?
If the answer is a name, you are further ahead than most. If the answer is a shrug in the direction of IT, that is your gap.
Takeaways
How big is the North Korean IT worker scheme in 2026?
Estimates of annual revenue for Pyongyang range from $250 million to $800 million depending on the source, with CSIS putting it at $350 million to $800 million as of 2024. Amazon told the Wall Street Journal it has blocked more than 2,900 suspected operatives since April 2024. Okta linked more than 130 identities to over 6,500 job interviews at more than 5,000 companies between 2021 and mid-2025. Treat all revenue figures as estimates of a deliberately hidden cash flow.
Why do fake candidates get through interviews?
Because the operation is industrialised. WSJ reporting on one cell found 22 interviews in a single week using seven identities, dedicated staff for resumes and for interviews, and real-time use of ChatGPT to answer technical questions read verbatim off screen. The team applied to more than a thousand companies in three months.
Where is the biggest vulnerability in the hiring process?
Third-party recruiters, staffing agencies and contractor platforms. They are paid on placements and work at volume, which gives them thin incentives to verify. The WSJ film documents operatives reaching companies (and at least one government) through third-party suppliers rather than direct applications.
Do AI detection tools help screen out fake candidates?
Not reliably, and they carry a fairness cost. A 2023 Stanford-led study in Patterns found seven GPT detectors wrongly flagged 61.3% of TOEFL essays written by non-native English speakers as AI-generated, while correctly identifying over 90% of US-born eighth-graders' essays as human. AI-assisted application writing is now normal, so a positive result says little about intent.
Should employers bring back in-person interviews?
The July 2026 multilateral alert from the US, UK, Canada, Japan, South Korea and others recommends in-person interviews as a verification step. Gartner's 2025 survey found 62% of candidates were more likely to apply when a role required them. The trade-off is a narrower geographic pool and a fairness cost for candidates who cannot travel.
What is the discrimination risk in fake candidate screening?
High. Commonly shared red flags (accented English, slow answers, a thin digital footprint, a Western name with an East Asian face) describe large numbers of legitimate applicants. Screening on those signals invites discrimination claims and public complaints from rejected candidates, and it damages employer brand faster than any security incident.
What happens to people whose identities are stolen?
They carry the consequences. One victim told WSJ that Department of Labor records showed him working across eleven states and earning roughly $100,000 he never received, leaving him unable to open a bank account or rent in his own name. Employers holding payroll records built on stolen identities hold evidence those victims need.
What should talent teams do first?
Assign named accountability for confirming that the person who starts is the person who was interviewed. Then write verification standards into agency and RPO contracts, verify references through corporate switchboards rather than candidate-supplied numbers, and ship equipment only to the address on the verified ID.
SOURCES
| # | Source | Publisher | Used for |
|---|---|---|---|
| 1 | Infiltrated: North Korea's Secret U.S. Workforce | The Wall Street Journal, 12 Aug 2026 | One cell's 1,000+ applications in three months; 22 interviews across seven identities in a single January 2025 week; at least nine roles won in the US and UK; Amazon's 2,900 blocked figure; the Visual PT and Subly hires; Derrik Goon and Michael Brown accounts. Paywalled. |
| 2 | Responding to the Evolution and Global Expansion of the DPRK IT Worker Threat | Center for Strategic and International Studies, 24 Mar 2026 | $350m to $800m annual revenue estimate as of 2024; expansion into Europe from the second half of 2024. |
| 3 | North Korean Remote IT Worker Fraud: Managing Insider Threat, Sanctions and Employment Risk | Skadden, Arps, Slate, Meagher & Flom, 8 Jun 2026 | UN Panel of Experts $250m to $600m annual range; the sanctions and vetting exposure carried by employers. |
| 4 | 2026 Global Threat Report | CrowdStrike, 24 Feb 2026 | DPRK-linked incidents up more than 130%; FAMOUS CHOLLIMA activity more than doubled during 2025. |
| 5 | North Korea's IT Workers Expand Beyond US Big Tech | Okta Threat Intelligence, Sep 2025 | 130+ identities linked to 6,500+ initial job interviews at 5,000+ distinct companies, 2021 to mid-2025. Note: a later Okta post renders this as 500 companies, which appears to be an error. |
| 6 | DPRK IT Workers Expanding in Scope and Scale | Google Cloud Threat Intelligence, 1 Apr 2025 | One worker running at least 12 personas across Europe and the US with fabricated references; targets in Germany, Portugal, the UK, Serbia and Slovakia. |
| 7 | Gartner Survey Shows Just 26% of Job Applicants Trust AI Will Fairly Evaluate Them | Gartner, 31 Jul 2025 | The 1-in-4-fake-profiles-by-2028 forecast; 6% of candidates admitting interview fraud; 62% more likely to apply where in-person interviews are required; 26% trust in AI evaluation. Figures draw on several surveys of around 3,000 candidates each. |
| 8 | Alert to countries, companies and other entities regarding North Korean IT workers | Global Affairs Canada, 31 Jul 2026 | The 20-agency joint alert across 11 countries; AI-assisted identity obfuscation and third-party interview proxies named as current tactics; the in-person interview recommendation. |
| 9 | Justice Department Announces Coordinated Nationwide Actions to Combat North Korean Remote IT Worker Schemes | US Department of Justice, 30 Jun 2025 | 21 searches across 14 states in June 2025 yielding around 137 laptops, plus 8 locations across 3 states in October 2024 yielding 70+. The widely quoted 29 farms across 16 states is a media aggregate of both sweeps. |
| 10 | Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote IT Worker Schemes (Wang) | US Department of Justice, 15 Apr 2026 | Kejia Wang 108 months and Zhenxing Wang 92 months; more than 100 US companies targeted; at least $3m in victim remediation costs. |
| 11 | Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote IT Worker Schemes (Knoot, Prince) | US Department of Justice, 6 May 2026 | Matthew Knoot and Erick Ntekereze Prince sentenced to 18 months each; nearly 70 victim companies across both schemes. |
| 12 | Arizona woman sentenced to 8.5 years for running North Korean laptop farm | The Record, Jul 2025 | Christina Chapman: 102 months, roughly 90 laptops run from her home, 309 companies, $17.1m generated. |
| 13 | North Korean IT workers are stealing remote jobs and raking in billions, and Americans are helping them do it | Fortune, 25 Apr 2026 | John Eisenberg's sentencing-memo line that the schemes "would not be successful without U.S.-based facilitators". |
| 14 | North Korean remote IT staffer worked for US government agency, says FBI | TechCrunch, 11 Aug 2026 | FBI confirmation on 28 July 2026 of an investigation into a DPRK remote IT staffer at an unnamed federal agency; the FBI declined to comment. |
| 15 | Fake North Korean IT workers: How companies can stop them | The Register, 13 Jul 2025 | Rivka Little of Socure on HR teams operating without access to a CISO or fraud lead; her "you can't profile people" caution on screening red flags. |
| 16 | Amazon blocked 1,800 suspected North Korean scammers seeking jobs | The Register, 18 Dec 2025 | Steve Schmidt's 1,800 blocked applications since April 2024 and 27% quarter-on-quarter growth in DPRK-affiliated applications. The comparator for the WSJ's 2,900 figure. |
| 17 | GPT detectors are biased against non-native English writers | Patterns (Liang et al.), 10 Jul 2023 | 61.3% average false positive rate across seven detectors on 91 TOEFL essays by non-native English speakers; over 90% of US-born eighth-graders' essays correctly identified as human. |
Related EBN coverage


