October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

North Korean IT Worker Fraud: What Mandiant’s Michael Barnhart Says Employers Should Know

North Korean IT-worker fraud can begin in recruiting and continue through company devices and valid credentials. Here’s how employers can detect inconsistencies, limit access and respond to a suspected hire.
From TheFinanceBase Team8 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

North Korean IT-worker fraud is more than a fake résumé or a payroll scam. DPRK-linked workers have used false identities and intermediaries to secure legitimate remote jobs, then collected wages while gaining access to company systems and data. Mandiant’s Michael Barnhart discussed the threat with CyberScoop’s Greg Otto in a Safe Mode interview published October 3, 2024. The practical lesson for employers is that hiring, device delivery and ongoing access controls are all part of the security perimeter.

What is the North Korean IT-worker scheme?

Mandiant, part of Google Cloud’s Google Threat Intelligence Group, tracks identified DPRK IT-worker activity under the designation UNC5267. The label does not necessarily describe a conventional, centrally organized threat group. Mandiant says it has tracked the activity since 2022 and has observed workers located primarily in China or Russia, with smaller numbers elsewhere, presenting themselves as workers in the United States or other countries. See Mandiant’s account of the operation.

The basic scheme is to obtain a remote job under a stolen or fabricated foreign identity. A worker may use a false résumé, professional profile and references; a facilitator may help with interviews, identity checks, banking, tax paperwork or receipt of company equipment. The worker then performs assigned duties, sometimes while holding multiple jobs, and salary payments are routed through intermediaries or other channels.

In some cases, the employer ships a laptop to an address controlled by a facilitator. The worker accesses that machine remotely, making the device appear to be operating from the claimed location. Mandiant has documented overlapping résumé language and inconsistent names, contact details, universities and employment histories across personas.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why North Korea wants the jobs

The immediate objective is revenue for the DPRK regime and sanctions evasion. A legitimate job can also provide access to source code, credentials, cloud systems, internal communications and customer information. That access creates opportunities for espionage, data theft or later intrusion, but a fraudulent hire should not automatically be described as a confirmed espionage operation. Mandiant has said its incident-response engagements often found workers initially performing ordinary assigned duties.

What a laptop farm is

A laptop farm is a location where a facilitator physically hosts multiple employer-issued computers. A worker elsewhere may connect to a laptop farm device using remote-management software or an IP-based keyboard-video-mouse (KVM) device. Mandiant has observed tools including GoToRemote/LogMeIn, GoToMeeting, Chrome Remote Desktop, AnyDesk, TeamViewer and RustDesk in investigations. None of these products, by itself, proves fraudulent employment; each also has legitimate uses.

Which employers and roles face greater exposure?

Risk depends less on a single industry label than on the hiring arrangement and access granted. Mandiant has observed applications across sectors and work of varying complexity, not only advanced engineering.

  • Fully remote, contract and freelance roles, especially when identity checks and device handoff are entirely remote.
  • Software development, DevOps, cloud administration, IT support and other technical positions.
  • Jobs with privileged access to source code, production systems, CI/CD pipelines, secrets, cloud consoles or customer data.
  • Organizations that ship devices without confirming who receives and physically controls them.
  • Employers whose HR identity checks are disconnected from IT provisioning and access reviews.
  • Hiring processes that rely heavily on automated résumé screening or a single remote interview.

What warning signs should hiring teams check?

These indicators are reasons to verify more carefully, not proof of DPRK affiliation. A legitimate candidate may have an unusual address, use a VPN or need an accommodation. Assess evidence across several independent sources, and do not screen people based on nationality, ethnicity, accent or appearance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identity and résumé inconsistencies

  • Education, employment dates, job titles or contact details differ across the résumé, professional profiles, references and background-check records.
  • Several supposedly unrelated candidates use identical or unusually similar résumé wording, work histories or portfolio material.
  • A claimed address, university or past employer cannot be independently verified, or the candidate’s online profiles appear to describe different people.
  • A phone number or profile photograph raises questions that cannot be resolved through ordinary, lawful verification.

Interview and background checks

  • The candidate’s answers about location, education, employers or technical experience are inconsistent across interviews.
  • The person on a live interview does not appear to match identity documentation, or the candidate repeatedly avoids reasonable live verification.
  • References can be contacted only through details supplied by the candidate, or cannot substantiate the stated work history.

A camera issue, delayed answer or reluctance to use video may have an innocent explanation, including accessibility, privacy or connectivity needs. Use a consistent process that allows reasonable accommodations and escalates unresolved discrepancies rather than making assumptions.

Equipment delivery and physical control

  • The worker claims to live in one location but requests delivery to another, without a credible explanation.
  • A third party receives or stores the company laptop, or the employee cannot explain who has physical possession of it.
  • Device location or network activity repeatedly conflicts with the employee’s declared work location.

Mandiant has observed devices delivered to facilitator-controlled locations, including laptop farms. A shipping discrepancy merits follow-up; it is not conclusive evidence on its own.

Why ordinary cybersecurity tools may not catch a fraudulent hire

A worker who uses valid credentials and performs assigned tasks may not trigger a malware alert. The risk begins when the organization trusts a false identity and grants access. That access can include the ability to view or change code, administer systems or reach sensitive infrastructure. Security teams therefore need to connect hiring and device records with identity, endpoint, network and data activity throughout employment.

After onboarding, potential consequences include multiple-job salary fraud, unauthorized repository access, copying code to personal accounts or cloud storage, theft of secrets or customer data, and access that could support a later intrusion. The FBI warned on January 23, 2025, that North Korean IT workers had copied company code repositories, including GitHub repositories, to personal profiles or cloud accounts, and had used data extortion. Read the FBI/IC3 advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to reduce the risk before and after hiring

Build identity checks into recruiting

  1. Conduct a live interview and compare the candidate with identity documents through a lawful, privacy-compliant process.
  2. Verify education and employment using independent sources. Contact references using details obtained independently where possible.
  3. Reconcile inconsistent names, dates, addresses, phone numbers and work histories before approving the hire.
  4. Require a clear explanation for a shipping address different from the employee’s verified location; arrange in-person pickup when practical.
  5. Give recruiters and hiring managers a documented route to escalate concerns to security, HR, legal and compliance teams.

Secure devices and remote access

  • Enroll every company device in endpoint management before use; record its serial number and use device attestation and hardware-backed authentication where practical.
  • Use endpoint detection and response, restrict installation of remote-access tools, and alert on unapproved tools or several remote-control products appearing on one device.
  • Monitor for IP-based KVM devices and unusual human-interface-device activity. Correlate endpoint telemetry with device location and identity-provider logins.
  • Investigate unexplained geography, impossible-travel events, anonymization services and location changes. Treat VPN alerts as leads: employees may legitimately use corporate VPNs or travel.
  • Allowlist legitimate remote-support software and require monitored, privileged workflows rather than indiscriminately blocking tools used by the help desk.

Limit access and monitor sensitive data

  • Use phishing-resistant MFA or hardware security keys for privileged accounts and apply least privilege.
  • Separate developer, production, administrative and finance permissions; review contractor access regularly.
  • Monitor unusual OAuth grants, API-token creation, repository cloning, bulk downloads and cloud-console activity.
  • Restrict unauthorized repository mirroring and personal cloud-storage synchronization; use secrets scanning and short-lived credentials.
  • Maintain prompt offboarding procedures for access revocation, and keep administrative and repository activity logs.

Location monitoring and identity checks must comply with employment, privacy and labor rules in the relevant jurisdiction. Give clear notice, limit collected data to what is needed, and review automated flags through a consistent human process.

What to do if a suspicious worker is already employed

Handle the concern as a potential security incident, not as a settled attribution. Avoid an unplanned confrontation that could prompt deletion or data transfer. Coordinate containment with security, HR and legal, and preserve evidence before changing systems wherever practical.

  1. Preserve records. Secure identity and hiring records, interview materials where lawfully retained, shipping details, device logs, VPN and authentication history, remote-access software records, repository activity and relevant payment information.
  2. Contain access proportionately. Revoke privileged tokens, isolate affected devices and disable unexplained remote tools while preserving devices and logs for forensic review.
  3. Establish the scope. Determine which systems, repositories, credentials, cloud accounts and customer data the account could access, and review activity for copying, bulk downloads or unusual changes.
  4. Rotate exposed secrets. Replace API keys, SSH keys, cloud credentials, signing keys and service-account credentials that may have been accessible.
  5. Look for related personas. Search for repeated résumé language, references, phone numbers, email addresses, devices, IP addresses and payment details.
  6. Coordinate reporting and response. In the United States, consider reporting suspected activity to the FBI and IC3; follow applicable legal, regulatory and contractual notification duties. The FBI’s alert to U.S. businesses and the IC3 advisory describe the threat and reporting route.
  7. Plan for extortion risk. Preserve messages and evidence, involve legal and incident-response specialists, and assess what data could be exposed; termination alone may not end the incident.
  8. Update controls. Document what failed and adjust hiring, device-delivery, access and monitoring procedures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the threat has changed—and what the figures mean

In April 2025, Google Threat Intelligence reported activity involving European job sites and HR platforms, as well as facilitators in Europe. The report also described increasing extortion attempts against former employers, including threats involving proprietary data and source code. These are dated observations, not a complete census of all activity. See Google Threat Intelligence’s April 2025 report.

Mandiant described one facilitator-linked case involving more than 60 compromised identities and more than 300 affected companies. It said the case generated at least $6.8 million for overseas IT workers from approximately October 2020 through October 2023. Those figures apply to that case, not the total DPRK program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mandiant’s M-Trends 2026 materials, based on its 2025 investigations, reported a 122-day median dwell time for the categories covering cyber-espionage and DPRK IT-worker incidents. This is a statistic from Mandiant-investigated incidents, not the average duration of every fraudulent hire or an estimate of the total population.

Where security products help—and where they do not

No commercial product should be treated as a standalone North Korean IT-worker detector. Tools can help correlate telemetry after onboarding, but they do not replace lawful identity and employment verification.

  • Applicant and identity verification: supports HR checks before an offer and device shipment.
  • Device management and endpoint detection: provides visibility into company devices, remote tools and unusual endpoint behavior.
  • Identity monitoring and SIEM/SOAR: correlates sign-ins, device location, VPN activity, cloud actions and repository events; useful only when the organization collects relevant data and can investigate alerts.
  • Threat hunting and incident response: helps assess whether a suspected worker, facilitator or remote-access route has affected systems.

For example, Google SecOps and Mandiant services can support detection, hunting or response for organizations with the telemetry and operational capacity to use them. Mandiant Digital Threat Monitoring can identify external exposure or targeting, but cannot prove an applicant’s identity. Mandiant Security Validation can test whether controls detect selected attack behaviors; it is not applicant screening. Product fit depends on the organization’s existing tools, staffing, privacy obligations and incident-response needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.