Breaking
SecurityDeveloping Story

Fake Hires: The Identity Gap in Onboarding

State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.

··1 hour ago·3 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

Security teams often brace for phishing or exploits, but a quieter threat enters through the hiring process. In July, the US Department of State released an alert warning of North Korean IT workers impersonating nationals of other countries to obtain work. Once employed, these workers send salaries back to parent agencies in North Korea.

The FBI has also warned that fraudulent workers may use their access to copy source-code repositories, exfiltrate proprietary information, and support other cybercriminal activity. After being discovered or dismissed, some have attempted to extort employers by threatening to publish stolen code and data.

These operations expose a gap between checking an identity and proving who is using an account. A résumé may look credible, and a laptop may arrive at a domestic address, but neither control proves the person interviewed is the person who receives the device or ultimately signs in.

The Tactics of Fake Remote Workers

Criminals often change their nationality or identity, falsifying information when registering for online platforms. This may include forging identification documents, impersonating another person, or using a proxy to register an account.

They also create fake profiles using AI to add legitimacy. These profiles match the tone and language of real IT professionals, making them harder to spot.

Unorthodox payment methods are another red flag. Fake workers may avoid direct deposit, favoring money transfers or cryptocurrency. North Korean workers have been observed using a third party for salary deposits, paying that party for account use.

Tools like VPNs and remote desktop software help disguise location, and overseas facilitators receive employer-issued computers at a domestic address, keeping them powered on for remote control from abroad.

Why Employment Checks Fall Short

Background checks, right-to-work checks, and identity screening confirm that candidate details are credible, but they don't prove who is actually using the laptop. An organization may confirm an identity exists, that the person is eligible to work, and that a device was delivered to an approved address—yet still issue credentials to an account controlled by someone else.

The tactics in these operations satisfy specific controls: stolen or proxy-supplied documents satisfy identity checks; fabricated résumés pass recruiter reviews; proxies or skilled workers handle interviews; facilitators' addresses meet equipment delivery; laptop farms meet location and device expectations; and third-party accounts handle payroll.

Warning Signs of a Fake Hire

No single indicator proves an applicant is part of a fake worker operation, but the State Department outlines several warning signs: frequent changes to registered information, a mismatch between the account holder's name and the name on the registered payment account, multiple accounts created using the same ID, multiple accounts accessed from the same IP address or a single account accessed from multiple IPs in a short period, and unusually high hours logged in.

Securing Onboarding with Identity Proofing

Organizations need robust vetting for freelance and remote hires. Solutions like Specops Secure Onboarding add government-issued identity-document scanning and biometric liveness detection to the onboarding process. The document check confirms the identity document is genuine, while the biometric check compares the person completing onboarding with the photograph on that document.

Liveness detection establishes that a real person is physically present, rather than a photograph, recording, or manipulated video. A valid document might be stolen, and a matching face could be a replay or deepfake, but document validation and biometric liveness together provide stronger evidence than either alone. Specops Secure Onboarding supports more than 16,000 document types for international hiring scenarios.

Identity as an Ongoing Access Control

The central lesson is that identity should not be treated as a one-off hiring record. Organizations must confirm the approved identity belongs to the live person receiving access, and they need a reliable way to repeat that check when access is recovered or changed. By combining document validation with biometric liveness from day one, then requiring identity confirmation before service-desk agents act, Specops Secure Onboarding provides checkpoints at the moments most likely to be targeted.

Why This Matters for Your Hiring

Fake remote workers exploit a gap between identity verification and actual account usage. For security teams, this suggests that onboarding should include identity proofing at the point of access, not just at hiring. The risk of credential compromise and data exfiltration is real, as highlighted by the FBI and State Department warnings. Implementing stronger verification, such as document validation and liveness detection, could reduce the chances of a fake hire gaining legitimate access.

#fake remote workers#north korean it workers#onboarding#identity verification#biometric liveness

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories