North Korea
North Korea is reportedly expanding its long-running remote IT-worker scheme by using individuals from third countries as interview proxies Everyday Cyber Defense/YouTube

North Korea is reportedly expanding its long-running remote IT-worker scheme by using individuals from third countries as interview proxies, according to a joint government alert issued on 31 July and research by cybersecurity firm Flare.

The tactic gives North Korean workers another layer of cover as employers increasingly use identity checks and other screening methods to detect fraudulent applicants.

The foreign recruits can appear on video interviews while posing as the job applicant, while a North Korean operator may take over the position after the company makes an offer.

Some recruits have reportedly been approached through LinkedIn and paid in cryptocurrency, with one arrangement offering about $500 a month for part-time interview work.

The issue matters because these jobs are not simply a hiring fraud problem. The income is channelled back to North Korean organisations and helps fund North Korea's unlawful nuclear weapons and ballistic missile programmes, according to US and allied authorities.

The workers can also gain access to corporate networks, sensitive information and cryptocurrency.

Foreign Proxies Help North Korean Workers Evade Hiring Checks

North Korean operators have reportedly recruited third-country nationals, including some technology workers, to participate in interviews and other parts of the hiring process. The foreign national can present a credible identity and appearance to an employer before the North Korean worker assumes the role.

That approach is particularly useful because companies have introduced new checks designed to catch fake applicants. These can include asking candidates to perform spontaneous actions on camera or answering questions intended to establish their real location and background. A foreign stand-in can make those checks harder to defeat.

Research by Flare found evidence that at least 14 Iranian nationals had entered recruitment pipelines connected to the North Korean operation. At least two received formal job offers from US employers, although it was not clear whether they ultimately accepted those positions.

The Scheme Has Become an International Recruitment Network

The use of third-country nationals marks a significant evolution from earlier versions of the operation. North Korea has for years used skilled IT workers based abroad and online, particularly in China and Russia, where they can work remotely while presenting themselves as nationals of other countries.

US authorities have documented stolen identities, fraudulent websites, proxy computers and US-based facilitators being used to make the workers appear legitimate.

The Justice Department said in April 2026 that two US nationals were sentenced for helping North Korean IT workers obtain jobs at more than 100 US companies. The operation used the stolen identities of at least 80 Americans and generated more than $5 million in illicit revenue for the North Korean government.

Earlier cases have also shown how company-issued laptops can be sent to US residences, where facilitators host the devices and allow overseas workers to access them remotely.

Why US Companies Face a Wider Security Threat

The concern extends beyond companies unknowingly paying North Korean workers. The FBI warned in a January 2025 advisory that these workers can use legitimate employment to gain access to corporate networks and sensitive information.

US authorities have warned that some North Korean IT-worker operations have been linked to data theft, extortion and theft of proprietary information.

In June 2025, the Justice Department said investigators had identified North Korean IT-worker schemes involving more than 100 US companies. In one case documented by the Justice Department, an overseas worker remotely accessed technical data controlled under US defence export regulations.

Another investigation involved the theft of cryptocurrency worth more than $900,000. The US Treasury said in March 2026 that North Korean IT-worker schemes generated nearly $800 million in 2024.

Governments Warn Companies To Tighten Identity Checks

A 31 July 2026 statement issued by Australia and supported by governments including the US, UK, Japan and South Korea warned that North Korean IT workers were using false identities, third-country proxies and AI to expand the operation.

It urged companies to strengthen identity checks, scrutinise identification documents and use in-person interviews where possible.

The legal risks are also substantial. US authorities have warned that people who knowingly facilitate North Korean IT-worker schemes can face criminal prosecution, sanctions or other legal consequences, depending on their conduct.

Companies that are deceived may also face fraud losses, cybersecurity remediation costs and potential compliance concerns, particularly where sensitive or export-controlled information is involved.