The North Korean remote-worker scheme is no longer an IT-department problem. Research published across Huntress, Recorded Future's Insikt Group, Nisos, Microsoft, Group-IB and FLARE now places fraudulent applicants in healthcare, financial services, and sales and marketing roles.

One documented case was a sales and marketing hire. Another was at an Australian healthcare company. The applications span software, technology, staffing, consulting, healthcare and biotechnology — more than 1,100 companies from a single cluster.

The numbers describe a factory, not a con

  • 22 fabricated personas maintained simultaneously
  • 60+ applications a day, across 10 platforms
  • $1.97 million generated between December 2025 and February 2026
  • One hire went 13 days before detection

That is not somebody talking their way into a job. It is a pipeline with throughput targets, and it is measured the way a sales team is measured.

The tooling matches. Multi-account browsers with a separate Chrome profile per identity. Spreadsheets tracking which persona applied where. Astrill VPN and IPRoyal proxies. PiKVM and TinyPilot-style KVM-over-IP so a laptop in someone's spare room can be driven from elsewhere. USB capture cards to feed video into interview calls. Rented AnyDesk accounts. Identity-brokering services, and a TrustID Card service for documents.

For faces: AI-generated profile photos, and — in one finding — face substitution using arrest mugshots.

The detail that should change how you interview

Interviews are being answered by AI transcription and chatbot tools generating responses in real time. Researchers report candidates "often repeating ChatGPT responses verbatim".

That is a behavioural tell, and it is the one that scales. Everything else on the list — the VPN, the KVM, the document — is infrastructure the operator controls and can improve. A candidate reading a generated answer aloud is a property of the interview itself.

It is also the tell that a structured, question-bank interview is worst at catching, because a generated answer to a standard question is fluent and complete. What breaks it is interruption: following up on the specific thing they just said, asking them to disagree with their own answer, asking about a decision they claim to have made and why they made it that way.

The advice does not match the world

The recommended controls are rigorous pre-onboarding background checks, identity document review, verification of employment history, monitoring for VPN and proxy connections during work, watching for unusual device attachment patterns — and in-person interviews.

In-person interviews are the control that works. They are also the control that remote-first hiring deliberately removed, which is why the scheme exists at this scale. A company that could conduct in-person interviews for every hire is mostly not the company being targeted.

The controls that survive contact with remote hiring are narrower and worth naming separately:

  • Ship the laptop to the address on file and watch what happens to it. Laptop farms are the physical chokepoint; a device that immediately appears behind a KVM or a residential proxy is the finding.
  • Record interviews and review the ones that felt smooth. The tell is in the cadence, not the content.
  • Treat VPN-during-work as an exception requiring an explanation, not as a preference.
  • Verify employment history by contacting the employer, not the reference the candidate supplied.

The uncertainty Huntress flagged

Huntress notes there is "still the possibility that these documents contained legitimate information or pictures from others who have had their identity information stolen or borrowed".

That deserves to stay attached to every number in this story. "Fabricated persona" and "a real person whose identity was stolen" are not the same thing, and from the outside they look identical. Some of the 22 personas may be inventions. Some may be people who have no idea their documents are in circulation.

Prosecutions

The facilitators — the people in the destination country hosting the laptops — are the ones being sentenced.

  • Matthew Isaac Knoot and Erick Ntekereze Prince, May 2026: 18 months each. Around 70 US companies affected, roughly $1.2 million in revenue.
  • Kejia Wang and Zhenxing Wang, April 2026: 108 and 92 months for a New Jersey laptop farm. More than 100 American companies, around $5 million.
  • Four further operatives sentenced across February and March 2026.

Eleven governments — the US, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the UK — have issued a joint alert.

This connects to the fake crypto startup that hired North Korean IT workers — same scheme, earlier and narrower.

What is not established

  • Where the workers themselves are. Multiple operators are assessed as likely based in China; the article does not confirm locations.
  • How many of the 1,100 companies actually hired anyone. Applications are not placements.
  • Whether the healthcare and sales roles were sought for access or purely for salary. Nothing reported either way, and the distinction matters a great deal to the companies involved.
  • Whether the identity documents are fabricated or stolen. Explicitly open, per Huntress.