For years, TA leaders have worried about résumé fraud, credential inflation, candidates receiving outside help during technical assessments, and people secretly holding multiple remote jobs.
Those problems suddenly look quaint.
A recent Wall Street Journal investigation documented an extraordinary operation in which North Korean IT workers used stolen identities, fake résumés, AI, American intermediaries and remote-work infrastructure to obtain jobs at Western companies.
This isn’t simply another recruiting scam. It represents something much more significant: the hiring process itself has become a cybersecurity vulnerability.
The scale of the operation is remarkable. The WSJ estimates that North Korea collects over eight-hundred million dollars annually from employers in the US and Europe.
Investigators followed one North Korean team that applied to more than a thousand companies in three months. They got twenty-two interviews in a single week using seven identities and were hired for multiple jobs.
The FBI has warned that the North Korean government has dispatched thousands of IT workers around the world who deceive companies into hiring them as remote employees using stolen identities, proxy computers and third parties located in the US to appear legitimate.
Recruiting is unwittingly complicit in this scheme. Once hired, these employees get a laptop and credentials that allow them to access sensitive company and customer information. In other words, the company gives them exactly the access that traditional cybersecurity systems are designed to prevent outsiders from obtaining.
The most important lesson for recruiting leaders is the sophistication of the operation. According to the Journal investigation, North Korean teams divide recruiting into specialized functions that:
The FBI says facilitators have helped establish US-based internet connections, set up remote access to employer laptops, create job-site accounts, establish financial accounts and attend interviews or meetings on behalf of the supposed employee. Some are unknowing participants who do not realize that they are working for North Korea, but many are actively involved in perpetrating the fraud.
Don’t assume a background check provider will catch this. The entire operation is designed to exploit conventional verification systems.
Workers may use identities belonging to real Americans, including legitimate Social Security numbers and other personal information capable of passing automated checks. They precheck identities through the eVerify system to ensure they will pass employment authorization.
The FBI recommends that employers scrutinize identity documents, cross-reference photographs and contact information, independently verify employment and education, and perform identity verification not simply during hiring but throughout employment.
The warning signs may be surprisingly ordinary. Some of the detection techniques described by investigators sound almost too simple. For example:
Recruiters should ask questions that require spontaneous answers rather than polished technical responses.
TA leaders should work with cybersecurity, HR operations, legal and IT to reconsider the hiring architecture for remote technical roles.
Recruiters have long operated on the assumption that candidates might exaggerate who they are, but fundamentally they are the people sitting across the table. But now that assumption is weakening because of AI, remote work, identity theft and organized fraud.
Recruiting technology spent the last decade making it easier for people to apply and easier for companies to hire. The next challenge is very different. We need to make sure the person we are hiring actually exists—and that the person who shows up for work is the same person we hired. Because in the era of AI-enabled recruiting fraud, identity is one of the most important hiring qualifications of all.
Editor’s note: Next month’s ERE Recruiting Innovation Summit will feature a conversation with Stacey Zapar of Tenfold and Magen Gicinto of Nisos, the company that was instrumental in the operation that shed light on the entire North Korean operation via a trojan horse laptop.