The Hiring Funnel Is Now an Insider-Threat Surface
Huntress investigated five suspected DPRK remote workers in 2026, at healthcare and financial-services employers, in sales and medical roles as well as IT. Fraudulent remote employment is an identity-and-access problem that starts at hiring, and the evidence to catch it sits in systems that do not share a queue.

In August, Huntress investigated a recently hired employee at a financial-services company. The endpoint contained a PiKVM, hardware that can let someone control a computer remotely before its operating system even starts.
Days later, investigators found a USB capture device capable of feeding video into Zoom. They also found an altered profile image downloaded from a file-sharing service. The employee had passed through normal hiring and onboarding, but the device did not behave like it belonged to one person working where the company thought they were.
Huntress assessed that case as suspected DPRK-worker activity. The employee was one of five such workers across three 2026 investigations at healthcare and financial-services employers. Their roles covered IT, sales and marketing, and the medical profession. Other cases in the set showed VPN use, inconsistent working hours, and browser tools that redirect screen, video, and audio. The firm does not offer any of that as a rule for identifying an applicant. Its cases needed identity, device, cloud, browser, and access evidence together.
The attacker arrives as a hire
Fraudulent remote employment is not the familiar story of an attacker breaking into a company. The attacker gets hired, completes enough ordinary work to remain credible, and enters through the systems built to welcome a new employee.
The established model includes false or stolen identities, a U.S.-based facilitator, a company laptop hosted at a residence, and remote access to that laptop from elsewhere. In April, the Justice Department announced sentences in one scheme involving more than 100 U.S. companies, more than 80 stolen identities, and more than $5 million in illicit revenue.
That prosecution does not measure every operation, but it explains why a normal-looking device location is not enough. Investigators call the arrangement a laptop farm. A laptop can be in the right country while the operator is not.
The FBI describes what a facilitator does in practice: receive company devices, enable remote access, set up financial and job-search accounts, and attend virtual interviews on a worker’s behalf. Each of those actions lands in a different corporate system, and none of them looks like an intrusion.

Recorded Future observed one cluster applying to more than 1,100 companies between late 2024 and early 2025, at a pace that reached 60 positions a day. It counted at least 22 fabricated personas and, in some cases, AI-generated profile photos and real-time interview assistance. Those are applications, not confirmed infiltrations; the firm assessed that at least ten organizations were likely employing operators. The volume shows why a hiring manager cannot be expected to catch the operation alone.

The control is coordination
Security teams often see the device. HR sees the documents. Finance sees the payment change. No one sees the whole pattern unless the company designs for it.
Microsoft frames the same problem as a detection opportunity. Its guidance treats the hiring workflow itself as telemetry: career-site activity before an offer, then identity, payroll, and device-onboarding records after one. The data to catch a fraudulent hire usually exists, collected by teams that do not share a queue.
The FBI recommends verifying identity through hiring, onboarding, and employment; monitoring address changes before a device ships; and reviewing the use of prohibited remote-access tools.
The first control is not more suspicion of remote workers. It is a defined process for high-trust roles and new-device onboarding: independently verify identity, tie delivery to that identity, limit early access, and make anomalous access visible to the people who can investigate it.
A genuine employee should not be harmed by that process. A false identity depends on the gaps between those systems.
Sources
Huntress: Insights into Suspected DPRK Workers
U.S. Department of Justice: DPRK remote IT-worker scheme sentencing
FBI: Guidance for U.S. businesses
Recorded Future: PurpleDelta’s fraudulent employment operations
About Common Defense
Common Defense is an AI cyber lab built by security veterans and AI researchers, whose team has helped protect more than $300B in assets across 1,100+ security engagements. We help AI companies, fintechs, and crypto protocols secure the communication channels and operations that attackers target most.
