Fake Hires: The Identity Gap in Onboarding
State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.
Security teams often brace for phishing or exploits, but a quieter threat enters through the hiring process. In July, the US Department of State released an alert warning of North Korean IT workers impersonating nationals of other countries to obtain work. Once employed, these workers send salaries back to parent agencies in North Korea.
The FBI has also warned that fraudulent workers may use their access to copy source-code repositories, exfiltrate proprietary information, and support other cybercriminal activity. After being discovered or dismissed, some have attempted to extort employers by threatening to publish stolen code and data.
These operations expose a gap between checking an identity and proving who is using an account. A résumé may look credible, and a laptop may arrive at a domestic address, but neither control proves the person interviewed is the person who receives the device or ultimately signs in.
The Tactics of Fake Remote Workers
Criminals often change their nationality or identity, falsifying information when registering for online platforms. This may include forging identification documents, impersonating another person, or using a proxy to register an account.
They also create fake profiles using AI to add legitimacy. These profiles match the tone and language of real IT professionals, making them harder to spot.
Unorthodox payment methods are another red flag. Fake workers may avoid direct deposit, favoring money transfers or cryptocurrency. North Korean workers have been observed using a third party for salary deposits, paying that party for account use.
Tools like VPNs and remote desktop software help disguise location, and overseas facilitators receive employer-issued computers at a domestic address, keeping them powered on for remote control from abroad.
Why Employment Checks Fall Short
Background checks, right-to-work checks, and identity screening confirm that candidate details are credible, but they don't prove who is actually using the laptop. An organization may confirm an identity exists, that the person is eligible to work, and that a device was delivered to an approved address—yet still issue credentials to an account controlled by someone else.
The tactics in these operations satisfy specific controls: stolen or proxy-supplied documents satisfy identity checks; fabricated résumés pass recruiter reviews; proxies or skilled workers handle interviews; facilitators' addresses meet equipment delivery; laptop farms meet location and device expectations; and third-party accounts handle payroll.
Warning Signs of a Fake Hire
No single indicator proves an applicant is part of a fake worker operation, but the State Department outlines several warning signs: frequent changes to registered information, a mismatch between the account holder's name and the name on the registered payment account, multiple accounts created using the same ID, multiple accounts accessed from the same IP address or a single account accessed from multiple IPs in a short period, and unusually high hours logged in.
Securing Onboarding with Identity Proofing
Organizations need robust vetting for freelance and remote hires. Solutions like Specops Secure Onboarding add government-issued identity-document scanning and biometric liveness detection to the onboarding process. The document check confirms the identity document is genuine, while the biometric check compares the person completing onboarding with the photograph on that document.
Liveness detection establishes that a real person is physically present, rather than a photograph, recording, or manipulated video. A valid document might be stolen, and a matching face could be a replay or deepfake, but document validation and biometric liveness together provide stronger evidence than either alone. Specops Secure Onboarding supports more than 16,000 document types for international hiring scenarios.
Identity as an Ongoing Access Control
The central lesson is that identity should not be treated as a one-off hiring record. Organizations must confirm the approved identity belongs to the live person receiving access, and they need a reliable way to repeat that check when access is recovered or changed. By combining document validation with biometric liveness from day one, then requiring identity confirmation before service-desk agents act, Specops Secure Onboarding provides checkpoints at the moments most likely to be targeted.
Why This Matters for Your Hiring
Fake remote workers exploit a gap between identity verification and actual account usage. For security teams, this suggests that onboarding should include identity proofing at the point of access, not just at hiring. The risk of credential compromise and data exfiltration is real, as highlighted by the FBI and State Department warnings. Implementing stronger verification, such as document validation and liveness detection, could reduce the chances of a fake hire gaining legitimate access.
Sources
- BleepingComputer Original source
Continue Reading
Stealthy Guest-Access Attacks Hit Salesforce, ServiceNow
Researchers uncover 'City-Forum' campaign using a custom toolset to exploit unauthenticated guest access in Salesforce and ServiceNow.
UK records office reprimanded for CMS patch failures
ACRO's unpatched Kentico CMS exposed sensitive data of up to 10,920 people, with alerts unread for months.
Fake CCleaner sites push Chrome spyware
Malwarebytes finds fake CCleaner downloads installing GhostDesk Chrome extension for credential theft and surveillance.