Articles

Why DPRK IT Workers Change Everything

July 28, 2026
Author
Katelyn Halbert
Senior Talent Acquisition Partner
Why DPRK IT Workers Change Everything
Summary
  • North Korean IT worker operations continue to evolve. These networks increasingly rely on layered identities, global facilitators, and remote work to blend into legitimate hiring pipelines.
  • Static hiring checks have a limited lifespan. Traditional red flags, such as new LinkedIn profiles or camera avoidance, are becoming less reliable as attackers refine their tactics.
  • Identity verification shouldn’t end after the interview. The discussion emphasized that organizations should validate identity beyond the interview, especially as AI-generated media and impersonation techniques advance.
  • Recruiting and security teams must work together. Recruiters spot behavioral signals, while security teams identify technical indicators. Together, they create a more complete view of risk.

North Korean IT workers: why identity verification can no longer be a one-time event

In one internal Pindrop analysis, approximately 1 in 47 applicants reviewed during 2026 showed indicators consistent with potential DPRK connections, compared with roughly 1 in 343 during a similar analysis the previous year. While these figures reflect Pindrop’s own observations—not industry-wide measurements—they point to a trend that many security leaders are increasingly confronting: remote hiring fraud is becoming more sophisticated, more persistent, and more difficult to detect.

That shift was the focus of a recent Pindrop webinar featuring Michael “Barni” Barnhart, Principal Intelligence Analyst at DTEX and a longtime researcher of North Korean cyber operations.

Rather than offering a checklist of hiring red flags, the discussion explored a broader question:
What happens when proving someone’s identity during the interview is no longer enough?

Across the conversation, one theme emerged repeatedly: organizations are adapting—but so are the attackers.

What is a North Korean IT worker?

Contrary to common perception, many North Korean IT workers do not operate from inside North Korea.

As Barnhart explained, these individuals often live in countries such as China, Russia, Laos, or Cambodia while posing as remote candidates located somewhere else entirely. A candidate might claim to be working from Thailand while interviewing for a London-based contractor supporting a U.S. company. Multiple layers of geography and identity make attribution intentionally difficult.

The immediate objective is often financial.

Because North Korea faces extensive international sanctions, remote employment has become one method of generating revenue for the regime. But Barnhart emphasized that revenue generation is only part of the picture.

Some fraudulent hires simply collect paychecks. Others gain privileged access, perform unauthorized activity from inside an organization, or create opportunities for additional actors to enter later.

As Barnhart explained during the webinar:

“You can have a fraudulent hire that’s trying to get money… But then you have these guys that are doing malicious activities and letting other people on the inside.”

That distinction matters because organizations may underestimate the risk if they view the problem as payroll fraud alone.

“It Can’t Be Us” is becoming the riskiest assumption

One of the webinar’s most memorable moments came when Barnhart described being asked how widespread the problem had become.

Rather than looking only at the largest enterprises, he examined a sample of mid-sized organizations and found evidence of North Korean IT worker activity across the majority of them. He also described how DTEX published approximately 1,000 email addresses associated with suspected activity and encouraged organizations to investigate whether those identifiers appeared in their own environments.

His conclusion was intentionally blunt:

“Everyone thinks, ‘It can’t be me.’ It is you.”

Whether every organization currently has a fraudulent employee isn’t the point.
The larger takeaway is that organizations with remote hiring programs should assume they are being targeted—even if no incident has yet been confirmed.

As Barnhart noted, his team regularly observes operators searching public job boards using one keyword above all others:

Remote.

Attackers are adapting as quickly as defenders

One of the strongest themes throughout the webinar was how quickly detection methods lose effectiveness.
Signals that once raised immediate suspicion have become less reliable as attackers adjust their tactics.
According to the discussion:

  • Newly created LinkedIn profiles are increasingly replaced with older, repurposed accounts.
  • Instead of refusing to appear on camera, some operations now place subcontractors or facilitators in front of the camera during interviews.
  • Time zone inconsistencies that once exposed fraudulent candidates are now anticipated and corrected.
  • Barnhart also described cases in which operators appeared to leverage their understanding of HR and legal processes to delay termination or create additional pressure on employers after suspicion arose.

None of these observations were presented as universal indicators.

Rather, they illustrate a larger pattern:

Static indicators eventually become known to attackers—and once they do, attackers evolve.

Barnhart’s advice: join your ISAC, share indicators anonymously, and build direct lines between talent acquisition and security. The stigma of admitting you hired one is exactly what keeps the ecosystem quiet and the operators employed.

Identity verification is becoming continuous

Perhaps the most important strategic takeaway from the webinar wasn’t about North Korea at all.
It was about identity.For years, many organizations have treated identity verification as a point-in-time event.

Verify someone once. Hire them. Move on.

Barnhart argued that this approach is increasingly vulnerable because attackers often separate the interview from the actual work. One individual may complete the interview while someone else performs the job after onboarding.

His recommendation focused on two practices:

  • Verify references through trusted channels rather than relying solely on email or text.
  • Continue validating identity after hiring—not only during recruitment.

That perspective aligned closely with observations shared during the webinar from Pindrop’s own hiring experiences, where identity inconsistencies sometimes became apparent only across multiple interactions rather than during an initial interview.

The broader implication extends beyond hiring.

As AI-generated media continues to improve, organizations may increasingly need to think of identity as something that is continuously validated, rather than permanently established during a single interaction.

This isn’t just an HR problem—or a security problem

Another recurring theme was organizational ownership.

Recruiters notice behavioral inconsistencies.

Security teams see infrastructure, devices, VPN usage, and other technical signals.

Neither group has enough visibility on its own.

Barnhart cautioned against treating fraudulent hiring as solely a talent acquisition issue or solely a cybersecurity issue. Instead, he encouraged organizations to improve information sharing internally and externally, including through industry groups such as ISACs where appropriate.

The challenge is that many organizations hesitate to discuss incidents publicly because acknowledging a fraudulent hire can feel reputationally risky.

Ironically, that reluctance also limits opportunities for the broader community to learn from one another.

The bigger story isn’t North Korea

North Korean IT workers are a highly visible example of how identity-based attacks have evolved.

But the webinar suggested something even more significant.

The larger shift is not simply that attackers are becoming better at impersonation.
It’s that organizations can no longer assume identity remains constant after the initial verification step.

As digital interactions become the norm—and AI continues lowering the barrier to convincing impersonation—the question increasingly becomes:

How do you know the person who joins today’s meeting is the same person who interviewed last month?

That is a different problem than hiring fraud.

It’s an identity problem.

And solving it may require organizations to rethink when—and how often—they establish trust.

Barnhart cautioned, however, that no single indicator should be treated as definitive because attackers regularly change their tactics.

Frequently asked questions

A North Korean IT worker is an individual operating on behalf of the North Korean regime who obtains remote employment using false or stolen identities. As discussed during the webinar, these workers often operate from countries outside North Korea while posing as candidates located elsewhere, making attribution significantly more difficult.

According to Barnhart, organizations that hire remotely should assume they are attractive targets because remote positions provide opportunities to generate revenue and, in some cases, obtain privileged access to corporate environments. He emphasized that organizations across industries—not only large enterprises—have experienced these attempts.

No. One of the central themes of the webinar was that fraudulent hiring spans multiple functions. Recruiters, hiring managers, security teams, fraud teams, and IT each observe different signals, making collaboration essential to identifying suspicious activity.

Barnhart discussed practices such as independently validating references through trusted channels and continuing to confirm identity after hiring rather than relying solely on a single pre-employment check. Organizations should determine the approach that best aligns with their own security, legal, and privacy requirements.

The webinar highlighted that attackers continually adapt to common hiring practices. Barnhart described scenarios where the individual completing the interview may not be the same person performing the work after hiring, making continuous verification an increasingly important consideration.

Digital trust isn’t
optional—it’s essential

Take the first step toward a safer, more secure future for your business.