Inside the DPRK Threat: The Hiring Scheme Funding a Nation-State & How to Spot It

Pindrop’s Katelyn Halbert sat down with Michael Barnhart (Barney), a nation-state threat researcher with 20+ years tracking North Korea, for a deep dive into the DPRK IT worker operation: how it runs, what the operatives are after, and the real cases that show the pattern.

Key takeaways:

  • DPRK-linked applicants are surging. In Pindrop’s own hiring data, the rate jumped from 1 in 343 applicants to 1 in 47 in a single year. Barnhart found IT workers at 18 of 20 mid-size companies he sampled. It’s less “will they target us” than “can you find them.”
  • It’s a criminal enterprise, not just a paycheck. North Korea operates these workers like a sanctioned mafia, routing hundreds of millions back to the regime. Sometimes the salary is the goal. Sometimes it’s cover for access, malicious insiders letting others in or acting themselves.
  • The tells keep moving. Fresh LinkedIn profiles became aged, purchased ones. Camera-off requests became subcontractors from Pakistan, Nigeria, and India sitting in on interviews. Operatives now use AI interview assistants and correct you on their own time zone. A one-time check at hire doesn’t hold.
  • Hiring is now a security checkpoint. Call references by phone, not email, and verify continuously that the person who interviewed is still the person on the job in week 1, week 5, week 20.
6 High Cost AI Attacks Image:Text
FEATURED RESEARCH

The six AI attacks you can’t afford to ignore

Understand which attacks are hitting enterprises the hardest, get a practical checklist to address it, and dive deep into how detection works.

See what continuous identity verification looks like for your team.

Talk to a real human