North Korean IT workers use deepfakes to get hired

NEW YORK, UNITED STATES — Eleven allied nations warned that North Korean information technology (IT) operatives are using real-time artificial intelligence (AI) deepfake video to defeat live job interview identity checks — channeling an estimated $800 million to Pyongyang’s weapons programs in 2024.
Live deepfake video defeats standard hiring screens
The operatives deploy real-time video inference: a deepfake model running live during a call maps a stolen or synthetic face onto the operative’s actual video feed, routed through a virtual camera driver that video-conferencing platforms treat as a normal webcam.
According to a report from Tech Times, this allows operatives based in North Korea, China, Russia, or Southeast Asia to appear seated in a United States home office.
Beyond video manipulation, operatives use voice changers, AI-generated headshots, forged identification documents, and large language models (LLMs) to craft communications that mask their origins. The scheme targets freelance and contract roles in software development, graphic design, database management, and IT support.
Cybersecurity firm CrowdStrike, which tracks the operation as FAMOUS CHOLLIMA, found that the group accounted for 47% of all state-sponsored hands-on-keyboard intrusions against U.S. technology companies in the twelve-month period ending March 2026 — the single largest state-actor share.
Accepting video feeds without liveness verification exposes companies to an adversary that has already infiltrated major corporate networks.
Eleven nations respond as scheme funds weapons program
“North Korea continues to rely on a network of skilled IT personnel who use false identities, third-party proxies, and increasingly sophisticated methods to conduct malicious cyber activity and generate revenue in support of its unlawful weapons programs,” the Federal Bureau of Investigation (FBI) stated in co-issuing the advisory.
Eight individuals have been sentenced to prison in 2026 for roles in these schemes, in an operation now tracked by 11 allied governments.
An estimated 100,000 North Korean workers across 40 countries earn the regime up to $500 million annually, with $800 million funneled to weapons programs in 2024.
The advisory urges employers to require in-person identity verification, implement liveness detection, and monitor hired accounts for name changes, location discrepancies, and credential-sharing.
Remote hiring without verified identity controls is no longer a procedural gap — it is a national security and sanctions-compliance risk.
For business process outsourcing (BPO) providers hiring remote IT contractors, standard video interviews are no longer sufficient for identity verification.
Liveness detection and secondary ID verification have moved from best practice to baseline requirement. BPO providers that strengthen hiring protocols protect clients from the legal and reputational exposure of inadvertently onboarding a sanctioned operator.
Related news
- LinkedIn faces Texas probe over fake job posts · 22 Jul
- South Korea’s AI boom faces widening talent shortage · 1 Nov 2025
- U.S. labor market hits ‘slack water’: Indeed Hiring Lab · 17 Jul
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.

Independent




