Morning Overview

North Korean operatives are landing remote U.S. tech jobs using deepfake interviews and stolen identities

Operatives working on behalf of North Korea are slipping into remote technology jobs at companies across the United States by combining stolen identities with artificial intelligence that can fake a face and voice in real time during video interviews. Governments warn that the salaries these workers earn are funneled back to the sanctioned regime, helping to bankroll its nuclear weapons and ballistic missile programs. The scheme has grown sophisticated enough that a hiring manager may never realize the person on the screen is not who the paperwork claims.

An eleven-nation alert and a federal-agency breach

The threat drew a coordinated response on July 31, 2026, when authorities from the United States and ten allied nations, including Japan, South Korea, Australia, Canada, the United Kingdom and several European governments, issued a joint alert warning companies about North Korean IT workers. The advisory said the operatives increasingly integrate AI to obscure their identities and often work in teams, so the person a recruiter deals with may change from one shift to the next.

The warning followed a striking disclosure days earlier, when the FBI confirmed that investigators had found a North Korean IT worker performing work for a U.S. federal agency, the first such case publicly acknowledged inside the government. The episode underscored that the infiltration reaches beyond the private sector and into sensitive public institutions.

How deepfakes defeat the video interview

The interview is where the deception is most audacious. During live video calls, operatives deploy real-time deepfake technology to impersonate the stolen identity listed on their application, mapping a synthetic face and voice onto the interviewer’s screen. Security researchers note that creating a convincing real-time deepfake now takes little more than an hour, no prior experience and inexpensive consumer hardware.

Because the fabricated persona can pass an initial screening, the individual who aces the interview is not always the one who later does the job. Investigators have observed cases in which one operative clears the hiring gate while a different worker performs the day-to-day tasks, a hand-off that makes identity verification after onboarding just as important as the interview itself.

The role of U.S.-based facilitators and laptop farms

Landing the job is only part of the operation. As the FBI has detailed in guidance to U.S. businesses, North Korean workers rely on facilitators inside the United States to supply a domestic footprint that hides their true location. Those facilitators receive company laptops at U.S. addresses, install remote-access software so the machines can be operated from abroad, and sometimes reship the hardware overseas.

The same networks help set up bank accounts, create profiles on job-search sites, purchase AI and background-check services, and even attend virtual meetings on the operatives’ behalf. Some of these so-called laptop farms have placed workers at dozens or hundreds of companies, and prosecutors have secured prison sentences against U.S.-based operators who ran them, in one case reaching a defense contractor’s controlled technical data.

Sanctions exposure and stolen data

Employers who fall for the scheme face legal as well as security consequences. Paying a North Korean IT worker, even unknowingly, can violate U.S. sanctions administered by the Treasury’s Office of Foreign Assets Control, as well as the sanctions laws of other countries that signed the July 2026 alert. The regime’s IT workforce has generated hundreds of millions of dollars in revenue in a single year, according to government estimates.

The risk does not stop at wages. The FBI has warned that once inside a network, these workers have been observed stealing proprietary data, harvesting IT credentials and positioning themselves for follow-on cyberattacks or extortion. What begins as an employment fraud can therefore turn into a data breach and a longer-term intrusion.

The financial scale helps explain the persistence of the scheme. Government estimates have put the revenue generated by North Korea’s overseas IT workforce in the hundreds of millions of dollars annually, money that flows back to a heavily sanctioned state with few legitimate ways to earn hard currency. Enforcement actions have seized cryptocurrency and secured convictions, but investigators describe the effort as a resilient, industrial-scale operation rather than a handful of rogue applicants.

What red flags companies are told to watch

Investigators offer practical countermeasures aimed at the interview and onboarding stages. Recruiters are advised to insist on unobscured video backgrounds, to ask candidates to hold their camera up to a window or wave a hand in front of their face, movements that can disrupt AI-generated video, and to capture images for comparison across later meetings in case the worker is swapped out.

Beyond the interview, the guidance urges firms to scrutinize identity documents for inconsistencies, verify prior employment and education directly with the institutions named, flag applicants who share banking details or documentation with other hires, and ship equipment only to the address on a worker’s identification. Companies that outsource technology work to third parties are told to extend the same vetting to those vendors, since contract arrangements are a common entry point. Suspected cases can be reported to a local FBI field office or the Internet Crime Complaint Center.

Because the operatives often work in coordinated teams across time zones, experts also advise employers to watch for behavioral inconsistencies after someone is hired, such as a worker whose expertise or communication style shifts unexpectedly, or who resists turning on a camera during routine meetings. Those patterns can betray a hand-off that identity checks at hiring never caught.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview