Remote IT worker identity fraud happens when someone other than the person a company interviewed and hired actually does the job, typically through a stolen identity, a real-time deepfake video interview, and a facilitator who hosts the company’s laptop. North Korea has run this scheme against hundreds of US companies since 2022, and on July 31, 2026, eleven governments jointly warned it is still expanding.
Key Takeaways
- A standard background check can return clean results in this scheme, since many operatives use real, stolen American identities with genuine credit and employment histories rather than fabricated ones
- North Korean IT workers have used real-time AI deepfake video during live interviews, not just static photos or recorded clips, defeating the assumption that “camera on” proves identity
- The US Treasury’s Office of Foreign Assets Control found this activity generated nearly $800 million for North Korea’s weapons programs in 2024 alone
- A “laptop farm,” a US resident hosting company equipment and enabling remote access by an overseas operative, lets a hired identity keep working long after a hiring decision should matter
- Closing the gap takes two layers: stronger identity confirmation at hire, and ongoing confirmation the person working is still the person hired
What Remote IT Worker Identity Fraud Actually Means
Remote IT worker identity fraud is when the individual who interviewed for a role, passed a background check, and was hired is not the individual who shows up to actually do the work. It is narrower than the general credential inflation GCheck’s own research has documented across the US workforce. A developer who overstates familiarity with a programming language has committed credential fraud. A developer whose interview, background check, and daily login belong to someone else entirely, most often a real American whose stolen identity is being used with their knowledge or without it, has committed identity fraud.
The distinction matters because the two problems call for different controls. Credential fraud is surfaced by skills assessments and reference checks that test what a candidate claims to know. Identity fraud requires confirming the person behind the resume, the interview, and the login is one real, consistent individual, a question skills testing was never built to answer.
North Korea’s remote IT worker scheme is the highest-profile version of this problem currently active against US employers, but it is not an isolated case study. Federal guidance on it has kept escalating rather than resolving:
| Date | Guidance or action |
| May 2022 | FBI, State, and Treasury issue the first joint advisory on North Korean IT worker schemes |
| 2023 | Follow-up guidance issued with South Korea on operational patterns |
| May 2024 | FBI updates guidance on witting and unwitting US-based facilitators |
| January 2025 | FBI PSA names AI face-swapping in video interviews as an observed tactic |
| July 2025 | FBI publishes expanded facilitator red flags and in-person verification guidance |
| July 2026 | Eleven nations, including four in Europe for the first time, issue a joint advisory |
The scheme specifically targets remote technical roles because those roles are the ones where a company can go months without anyone in the building ever meeting the person doing the work.
How the Scheme Works: Laptop Farms, Facilitators, and Deepfake Interviews
A background check confirms who someone claims to be on the day it runs. It does not confirm who is sitting at the keyboard six months later, and the North Korean scheme is built around that gap.
The mechanics start with identity. Operatives obtain and use real, stolen identities belonging to US citizens, or in some cases construct fabricated ones, to apply for remote developer, IT specialist, and coder positions. Because the underlying Social Security number and history are often genuine, standard identity checks and background screening can clear the application without detecting anything unusual. The fraud lives in who is actually behind the application, not in the data it contains.
Getting past the interview used to be the harder step, but that control has weakened. The FBI’s January 2025 public service announcement stated that North Korean IT workers have been observed using artificial intelligence and face-swapping technology during video job interviews to obscure their true identities. Later reporting describes the current version as real-time video inference: a deepfake model runs live during the call, routing its output through a virtual camera driver that most video-conferencing platforms accept as an ordinary webcam feed. That is a meaningfully different failure mode than swapping in a static photo or a recorded clip, which is part of why the technique keeps working against hiring teams who assume a live video call proves enough.
Once hired, staying inside the company is solved with a “laptop farm”:
- The company ships a laptop to what it believes is the new hire’s US home address
- A US-based facilitator, sometimes a witting participant paid a fee and sometimes an unwitting person duped into hosting equipment, receives it there
- The facilitator connects the laptop to a keyboard-video-mouse switch or installs remote desktop software
- The actual overseas operative then controls the physical machine from abroad, while the company’s network sees a legitimate US IP address and a company-issued device logging in as expected
The Justice Department’s prosecution of Kejia Wang and Zhenxing Wang, two US nationals sentenced in April 2026, shows exactly how this works at scale. From roughly 2021 to October 2024, the two ran a scheme that compromised the identities of more than 80 US persons to obtain remote jobs at more than 100 US companies, including multiple Fortune 500 firms, using shell companies with no employees or operations to receive and launder wages. Kejia Wang was sentenced to 108 months in prison and Zhenxing Wang to 92 months, with $600,000 in ordered forfeiture. During the scheme, an overseas co-conspirator used the access gained through it to steal technical data controlled under the International Traffic in Arms Regulations from a California-based defense contractor that develops AI-powered equipment. This was not a payroll inconvenience. It was a pathway into sensitive US company systems that a foreign government used because the access looked, from the outside, exactly like an ordinary remote hire.
Why This Escalated in 2026
The July 2026 advisory matters because of who signed it, not just what it said. It was the first time France, Germany, Italy, and the Netherlands co-signed a warning on this scheme, signaling that targeting has expanded well beyond the US and South Korean companies most earlier coverage focused on. The advisory named laptop farms directly and called on all UN member states to repatriate North Korean nationals earning income in their jurisdictions.
The scale behind it is not abstract. In March 2026, the US Department of the Treasury’s Office of Foreign Assets Control sanctioned six individuals and two entities across North Korea, Vietnam, Laos, and Spain for facilitating these schemes, and stated the activity generated nearly $800 million for North Korea’s weapons of mass destruction programs in 2024 alone. That figure describes one year, not a cumulative total.
For a technology company evaluating how seriously to take this, the trend line only moves one direction: new techniques appear as older ones get caught, and real-time deepfake video is simply the newest layer.
What a Background Check Confirms, and What It Doesn’t
This is worth naming clearly, because it shapes everything a company can reasonably expect from screening alone. A background check confirms identity, criminal history, and employment records as they existed on the day the check ran, matched against the information the applicant provided. It was never designed to detect whether the person who provided that information is the same person who will be logging in six months later.
That single fact explains why this scheme survives contact with completely normal, compliant hiring practices. A company that runs an FCRA-compliant background check, verifies employment history, and conducts a standard video interview has done everything a conventional workflow asks, and can still end up with an overseas operative on payroll, because none of those steps answer the question this fraud depends on: is the person behind this application the same, real individual at every step?
GCheck’s own Shadow Workforce research reflects a version of this problem at a broader, non-DPRK-specific scale. A third of US workers, 33%, have either heard of or personally know situations where someone was offered money to let another person use their identity or work authorization to obtain employment. That figure is not about North Korea specifically. It describes a workforce-wide pattern the DPRK scheme sits at the far, most consequential end of: paying for access to someone else’s identity to get hired is not a rare or exotic idea to the American workforce. It is something a meaningful share of workers already know happens.
Closing the Gap at the Point of Entry
Point-of-entry identity verification is the first layer, and it matters because a background check is only as reliable as the identity underneath it. If the identity data feeding the screening process is compromised from the start, the result is trustworthy in a narrow, technical sense and useless in the sense that actually matters to the company relying on it.
A few specific tools address this layer directly:
- Digital Identity Verification cross-references document data and independent sources to confirm an identity before screening even begins, rather than accepting self-reported information at face value
- Biometric Liveness Detection confirms a real, present person during remote identity checks, distinguishing a live individual from a static image or recorded media
- Deepfake Fraud Detection analyzes video and audio signals during virtual interviews and onboarding specifically for the kind of real-time manipulation that basic liveness checks were not built to identify
- Verified Entry anchors the background check itself to a confirmed identity at the point of entry, so everything downstream in the screening process starts from a verified identity rather than a self-reported one
None of this is about treating remote candidates as suspects. Most people applying for remote technical roles are exactly who they say they are, and confirming that clearly protects them too, since a legitimate candidate has every reason to want impersonation ruled out before it creates doubt about their own hire.
Collecting biometric data through liveness detection or deepfake analysis carries its own compliance layer. States including Illinois, under its Biometric Information Privacy Act, along with Texas and Washington, require specific notice, consent, and retention practices before collecting a facial scan or voiceprint, separate from standard background check authorization. Build those requirements from the outset rather than as an afterthought.
It is also worth being direct about what point-of-entry verification cannot do. It answers who someone is on the day the check runs. It says nothing about who is behind the keyboard a year into the role, which is exactly the gap the laptop farm model is built to exploit. Point-of-entry controls are necessary. They are not, on their own, sufficient.
Keeping Confirmation Current After Hire
GCheck’s research frames this specific limitation as the Verification Half-Life: the assurance a company buys with a one-time background check begins to decay the moment onboarding ends, because nothing in a standard screening workflow reconfirms who is actually doing the job as time passes. This is a way of describing a pattern in how verification works, not a measured decay rate, and it applies to background screening broadly rather than to any single scheme or industry.
The laptop farm model is, in effect, an exploit of exactly this decay. A company verifies an identity once, ships a laptop to what it believes is that person’s home, and from that point forward has no mechanism that reconfirms the identity behind the login unless something goes visibly wrong. The FBI’s own guidance points directly at signals that can close this window without requiring a new background check every month:
| Signal to monitor | What it can indicate |
| Multiple logins to one account from different IP addresses in a short window | Remote access by someone other than the credentialed employee |
| Unusual concurrent audio or video call software on an endpoint | Laptop farm infrastructure supporting simultaneous sessions |
| A change in payment platform or banking details shortly after onboarding | A facilitator redirecting wages rather than the hired individual |
| Data exfiltration through shared drives, personal cloud accounts, or private code repositories | Unauthorized access using a legitimately issued login |
Continuous Criminal Monitoring, Driver Monitoring, and Professional License Monitoring were built for different specific risks, but they share the same logic: treating the assurance from a background check as something renewed, not granted once and assumed to hold indefinitely. Applied to remote technical hiring, that means monitoring login geography, session patterns, and payment changes as a standing practice rather than a one-time gate.
What Employers Can Do Right Now
The FBI’s guidance on strengthening remote hiring is specific enough to act on directly, and does not require new technology:
- Implement identity verification during interviewing, onboarding, and throughout employment, not only at hire
- Cross-check hiring systems for other applicants with the same resume content or contact information
- Review applicant communication accounts, since North Korean IT workers have reused VoIP numbers and email addresses across resumes purportedly belonging to different applicants
- Use specific, checkable interview questions about a candidate’s stated location or educational background, since operatives frequently claim non-US institutions
- Verify that any third-party staffing firm involved conducts, and routinely audits, its own robust hiring practices
- Complete as much of hiring and onboarding in person as the role reasonably allows, and for virtual meetings, ask a candidate to briefly point their camera out a window or describe their surroundings, since this can prompt visible glitches in real-time deepfake video
Apply these steps the same way to every remote applicant, not selectively to candidates whose name, accent, or background prompts a hunch. Uneven application creates exposure under Title VII’s prohibition on national origin discrimination, and it undercuts the fraud-detection purpose besides, since the real red flags here (reused phone numbers, mismatched video feeds, resume duplication) are behavioral and technical, not tied to where a legitimate candidate happens to be from.
Individuals whose Social Security numbers have been compromised also have a direct, no-cost option worth knowing about, even though it sits on the employee side of this problem. The Department of Homeland Security’s E-Verify system offers Self Lock, which lets a person lock their own SSN so it cannot be used to confirm employment eligibility at any E-Verify-participating employer until they unlock it themselves. It will not stop every version of this fraud, since not every employer uses E-Verify, but it closes one specific pathway at no cost to the person protecting themselves.
One more point belongs here rather than a footnote. If an employer identifies suspected impersonation through a consumer report, including a continuous monitoring product, and terminates the employee as a result, that decision is an adverse action under the FCRA regardless of whether the person was a new hire or already on staff. The same sequence applies as at the point of hire: a pre-adverse action notice, a copy of the report, a reasonable opportunity to respond, and a final adverse action notice once the decision is made. Discovering fraud does not create an exception to that process.
What This Means Beyond North Korea
It would be a mistake to read this as a story only about one country’s intelligence apparatus. The identity verification gap this scheme exploits is a structural feature of how screening works, not a DPRK-specific vulnerability. Any actor willing to buy or rent someone else’s identity can walk through the same door.
That is also why Transparent Compliance belongs alongside Protective Compliance under Compliance for Good™, GCheck’s operating standard for treating verification as something that builds trust rather than suspicion. GCheck’s own research found that workers are not resistant to this: 78% of the general US workforce strongly support stronger skills and identity verification, and 59% specifically want stronger identity verification (GCheck, The Rise of the Shadow Workforce). The mandate for closing this gap is not coming only from federal advisories. It is coming from a workforce that would rather have identity clearly and consistently confirmed than work alongside colleagues nobody can verify.
Frequently asked questions
What is remote IT worker identity fraud?
Remote IT worker identity fraud is when the person who interviewed for and was hired into a remote technical role is not the person actually performing the work. It commonly involves a stolen or fabricated identity, a deepfake video during interviews, and a US-based facilitator who hosts company equipment to enable remote access by an overseas operative.
How do North Korean IT workers pass video interviews if they are not physically the person hired?
Since at least 2024, operatives have used real-time AI deepfake video during live interviews, running a face-swapping model that outputs through a virtual camera driver most video-conferencing software accepts as a normal webcam feed. This defeats the assumption that a live video call proves who is on the other end.
What is a laptop farm?
A laptop farm is a US residence or facility where a facilitator receives company-issued equipment shipped to a new hire’s address and connects it to remote-access hardware or software, letting an overseas operative control the physical machine while the company’s network sees a legitimate US-based login.
Can a standard background check identify this kind of fraud?
Not reliably on its own. Many operatives use real, stolen American identities with genuine credit and employment histories, so a background check can return clean results even though the person behind the application is not who they claim to be. Background checks confirm identity as of the day they run; they do not confirm who is behind the keyboard afterward.
What is the Verification Half-Life?
The Verification Half-Life is a conceptual frame describing how the assurance from a one-time background check decays the moment onboarding ends, since nothing in a standard screening process reconfirms who is doing the job as time passes. It describes a pattern in how verification works, not a measured or claimed statistic.
What should employers do if they suspect they have hired someone through this scheme?
Report the suspected activity to the FBI’s Internet Crime Complaint Center at IC3.gov and evaluate network activity from the suspected employee’s devices using internal intrusion-detection tools. If discovery comes through a consumer report, including an ongoing monitoring product, and leads to termination, that decision is an adverse action under the FCRA and requires the standard notice sequence, the same as at the point of hire.
Sources cited
- Federal Bureau of Investigation. (2025, January 23). North Korean IT Workers Conducting Data Extortion (Alert Number I-012325-PSA). https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-workers-conducting-data-extortion
- Federal Bureau of Investigation, Internet Crime Complaint Center. (2025, July 23). North Korean IT Worker Threats to U.S. Businesses (Alert Number I-072325-4-PSA). https://www.ic3.gov/PSA/2025/PSA250723-4
- U.S. Department of Justice, Office of Public Affairs. (2026, April 15). Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People’s Republic of Korea. https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker
- U.S. Department of the Treasury. (2026, March 12). Treasury Sanctions Facilitators of DPRK IT Worker Fraud Targeting U.S. Businesses. https://home.treasury.gov/news/press-releases/sb0416
- U.S. authorities, jointly with Japan, the Republic of Korea, the United Kingdom, Australia, Canada, and other partner governments, via the FBI’s Internet Crime Complaint Center. (2026, July 31). Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers. https://www.ic3.gov/CSA/2026/260731.pdf
- E-Verify (U.S. Department of Homeland Security). Self Lock. https://www.e-verify.gov/employees/employee-self-services/mye-verify/self-lock
- GCheck. (2026). The Rise of the Shadow Workforce. Proprietary survey of 1,500 U.S. employed adults, fielded June 2026.
- Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq.
- Fair Credit Reporting Act, 15 U.S.C. § 1681b(b)(3)
- Title VII of the Civil Rights Act of 1964, 42 U.S.C. § 2000e-2
Charm Paz, CHRP
Recruiter & Editor
Charm Paz is an HR professional at GCheck, specializing in background screening, fair hiring, and regulatory compliance. She holds from the Professional Background Screening Association (PBSA) and helps organizations navigate employment regulations with clarity and confidence.
With a background in Industrial and Organizational Psychology, she translates policy into practice to build ethical, compliant, human-centered hiring systems that strengthen decision-making over time.