Stolen Names, AI Fakes Put North Koreans on U.S. Payrolls

URL has been copied successfully!

Here is how the scheme works. A software developer sitting in Pyongyang, China or Russia applies for a remote American IT job using the name, Social Security number and date of birth of a real American whose identity was stolen or rented. Artificial intelligence writes the résumé and cover letter, and pastes the applicant’s face onto forged identity documents. When the video interview comes, AI generates a live deepfake so the face on screen matches the stolen paperwork. Once hired, the company ships a laptop to a U.S. address belonging to a paid American accomplice, who plugs it in and installs remote-access software so the login traffic looks like it is coming from Phoenix rather than North Korea. The salary lands in a U.S. bank account, and the bulk of it is wired to the regime.

That pipeline has now reached inside the federal government. Todd Hemmen, deputy assistant director of the FBI’s Cyber Division, disclosed during a July 28 panel at the Digital Government Institute’s conference in Washington that the bureau had identified a North Korean remote IT worker employed by the federal government the week prior. The individual reportedly worked for the agency for several months before being detected. The FBI has not named the agency or described the worker’s duties, and it remains unclear whether sensitive information was accessed or taken. The case marks a rare confirmed instance of a sanctioned North Korean working inside a government agency.

The disclosure landed days after Washington and its allies escalated their warnings to American employers. On July 31, authorities from eleven countries — the United States, Japan, South Korea, the United Kingdom, Australia, Canada, New Zealand, France, Germany, Italy and the Netherlands — issued a joint alert urging companies to strengthen identity verification and hiring controls, warning that the labor was generating foreign currency for Pyongyang’s nuclear weapons program. It was the first time France, Germany, Italy and the Netherlands co-signed a warning on this specific threat, a signal that the targeting has spread well beyond American and South Korean employers.

The dollar figures already established in U.S. courtrooms explain the urgency. An Arizona woman, Christina Chapman, helped North Korean workers obtain jobs at 309 U.S. companies including Fortune 500 corporations, using 68 identities stolen from American victims, and was sentenced to eight and a half years in prison in a scheme that generated more than $17 million for the regime. In a separate case, Kejia Wang of Edison, New Jersey, and Zhenxing Wang were sentenced for placing North Korean workers at more than 100 U.S. companies using the stolen identities of at least 80 Americans, producing over $5 million for the North Korean government. Kejia Wang received 108 months. The cleanup cost businesses in 28 states and the District of Columbia at least $3 million in legal fees and computer remediation. The FBI said eight individuals have been sentenced to prison in 2026 alone.

The exposure is broader than the prosecutions suggest. Security researcher Stykas told WIRED ahead of a Black Hat briefing that he found evidence of 1,640 companies across 57 countries affected by North Korean operations, with roughly 700 to 800 suffering damaging intrusions including root-level access to servers and cloud environments. CrowdStrike reported that the North Korea-linked group it tracks as Famous Chollima accounted for 47% of all state-backed hands-on-keyboard intrusions against the technology sector between April 2025 and March 2026. The workers are not only collecting salaries. They have also stolen proprietary data from U.S. companies and used it for extortion.

For employers, the practical fix starts at the point of hire, not at the firewall. The joint alert recommends rigorous review of identification documents, a preference for in-person interviews or closely scrutinized live video, and monitoring systems that flag anomalous account behavior — frequent changes to names or bank details, payment accounts whose names do not match the employee, multiple accounts sharing an identification document or IP address, altered identity images, unnaturally long login sessions, and profiles full of translation errors. Payment preferences are a recurring tell: applicants who refuse direct deposit and ask instead for money transfer services, cryptocurrency, or wages routed to a third party.

The harder problem is that the one control most hiring managers trusted has been compromised. The alert lists in-person interviews as an example of stronger verification, but also warns that third-party proxies may sit for interviews or make in-person contact on the operative’s behalf — in one documented case, a real American walked into a facility with a genuine government ID and passed screening for someone he had likely never met. Hemmen said AI now runs through the entire operation, from application through employment.The federal case suggests gaps in government hiring and contractor vetting despite years of warnings

, and it moves the question out of the security department and into human resources. Verification of who is actually doing the work — not just who appeared on the call — is now a continuing obligation rather than a one-time check at onboarding.

JBizNews Desk | New York

© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.

Please follow us:
Follow by Email
X (Twitter)
Whatsapp
LinkedIn
Copy link