Stopping IT Worker Scams Requires Revamped HR Process

Silouette of a worker at a computer in a manufacturing fab
Source: DC Studio via Shutterstock

When a suspected North Korean operative applied for a remote AI engineering position at human-risk management firm Nisos in June 2025, the company decided to run its own operation on the fraudster. Nisos notified law enforcement, conducted an HR interview, "hired" the worker, and sent a laptop to that person's US address in Florida — a laptop "farm" — with surveillance implants.

"When they opened the laptop, we could see that [the computer was] in a closet with a bunch of other companies' computers," says Ryan LaSalle, the firm's CEO. "We could see it so well that we could see the names of the other companies on the screens across the closet."

Over the following months, Nisos' team monitored the operator as he used Gmail to apply to other jobs, logged into Discord to chat with other operators — 22 in total — and worked with four different facilitators in the US, all while connecting from a location on the border of North Korea and China.

Last week, law enforcement and security agencies from the US, Japan, Australia, and Germany released an updated advisory informing companies of the risks posed by fake IT worker operations coming from the Democratic People's Republic of Korea (DPRK). Dubbed WaterPlum — or Contagious Interview by other threat-intelligence firms — the threat actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets, according to the advisory. Their goal: embed themselves in companies worldwide to provide a stable source of income for the North Korean regime.

Five years ago, the operations were relatively unknown, and the IT worker campaigns had significant success. The reliance of many companies on remote workers — especially in the IT sector — and the increasing capabilities of AI have made the efforts more pervasive.

But today, human-resource groups should have the tools and the processes to detect suspicious applicants and escalate efforts to determine whether they pose a risk to the company. From the use of voice-over-IP (VoIP) for calls to a lack of a digital footprint, there are a variety of signs that can indicate a risky applicant and help companies detect them early, says Nicholas Kowalczyk, vice president and chief risk, compliance, and privacy officer for Kelly Services, a staffing and workforce solutions company.

"There's probably not any one silver bullet here," he says. "It's stacking enough pieces within the recruiting process itself where it's a hurdle to the people who are potential bad actors, but not enough of a hurdle to the good candidates."

Generating Regular Income for North Korea

The goals of the North Korean IT worker campaigns are about providing regular funds to the regime, experts say. While there have been major thefts of cryptocurrency and bank funds by North Korean-sponsored hackers, the IT worker campaigns tend to refrain from overt theft because the goal is to maintain a constant inflow of cash to the North Korean regime as long as possible, Kowalczyk says.

"If you look at the long scale of it, it's better for them to, say, not [steal data], not do that suspicious type of activity, because then they continue to have access to the IP and have access to those funds coming in," he says.

Table of signs of IT worker fraud

Some of the common signs of IT worker fraud and whether they were seen in the Nisos incidents. Source: Nisos

In 2024, security awareness firm KnowBe4 had its own well-publicized incident. The company needed to hire a software engineer for its AI team, and following a standard HR process with four video conference interviews, it hired a person and sent them a Mac workstation. In reality, the hire was a North Korean IT worker, detected when they started installing malware on the company-owned machine.

"Two years ago, it was not widely known — I think there was maybe a very, very light bulletin about it," says Brian Jack, chief information security officer (CISO) at KnowBe4. "It's been a couple of years in now; there are enough stories, [and] the government has come out about it. If you're hiring remote technology workers at all, you're doing yourself a disservice by not knowing at least the basics."

Nations Strike Back, but AI Is Aiding Attackers

While governments have warned organizations about the threat for the past five years, companies should not rely on government policy to solve the problem. In addition, AI is now making the IT worker scheme more effective and pervasive, says Jim Desmond, CISO at HireRight, an employment background-checking firm.

"While federal law enforcement efforts are having an impact, threat actors are adapting quickly, with AI reducing the cost and skill required to conduct fraud at scale," he says.

Talent-acquisition and human-resources groups are being inundated with resumes that describe — through the help of AI — seemingly perfect candidates for specific jobs. And the attackers are applying at scale; during the 10 months of the Nisos operation, they witnessed the pod of North Korean IT workers apply for 170,000 positions. The result: They landed 76. (Nisos contacted the affected companies, LaSalle says.)

The automation and scale of the operations have placed a heavy burden on recruitment efforts, says Kelly Services' Kowalczyk.

"It creates this glut of applications at the top of the funnel that starts to muddy up the system of everyone doing that recruiting cycle," he says.

Companies also need to worry about not just vetting their own hires, but any contractors as well, HireRight's Desmond points out. "These contingent workers may have the same levels of access to sensitive information, proprietary data, intellectual property, and critical infrastructure as an organization’s employees, so it is crucial to have an appropriate, role-specific screening process for these workers before access is granted," he says.

Danger Signs Not Hard to Spot

Initial telltale signs of a possible DPRK employment scam are fairly simple. The candidate uses a VPN to send documents and email, has a relatively new email address not appearing in breach notifications, uses VoIP as their primary phone number, and has resume content appear in different profiles across multiple accounts. While none of these signs are definitive by themselves, in aggregate they constitute a significant indicator of risk.

Yet a short or inconsistent digital footprint is generally one of the strongest indicators, says Nisos's LaSalle.

"Their LinkedIn profile was created three months ago and they've got 15 years of experience, [or] their email address didn't exist before six months ago," he says. "They start to add up; as they start to combine, you get more and more indicators that this person isn't who they say they are."

Contact information is a big key because the threat actors have to change it so often to stay off of blocklists, says KnowBe4's Jack. Companies that know of the threat and train their HR departments in a process designed to escalate risky applicants should be able to catch them early, he says.

"The difference is knowing that this is a threat and then having the basic understanding of how you go about detecting it early," Jack says. "Early in the process [is important] because if you wait till it gets too far down the line, now you are transitioning away from a hiring threat and into more of just general insider threat."

Other signs may be harder to spot. HR groups and the IT teams that handle provisioning a new employee may not communicate well and miss evidence of a suspicious hire — such as the person's address changing when a corporate laptop is ordered — that could catch an operator.

Training recruiters and creating a good process to raise suspicions and track them through the recruitment chain are two important steps that the human-resource side of the business can take to combat the problem, Kowalczyk says.

"They're on the front lines of this to be able to identify these schemes through the start of the process, really pre-sourcing that area where you're building up your base and then all the way down to the point of which you're hiring and placing them on a customer location," he says. "So there are steps throughout that entire process ... to try to mitigate the risk of [hiring DPRK operatives]."

In addition, HR processes that focus on spotting fraudulent candidates can actually save time and money because the recruiters aren't spending time on likely fake candidates, says KnowBe4's Jack. The company has automated much of the information checks for their recruiters, performing phone-carrier determination, email lookups, LinkedIn scanning, and duplicated contact information across resumes.

"If you catch this with indicators earlier on, then you save the time that you would have normally spent taking that candidate, who looks good on paper, further down the process than they should ever go," he says. "So you can spend more time vetting what you believe to be non-fraudulent candidates in the first place and not waste your time on candidates that are very likely not real."

Dive deeper

Free tools to verify and analyze what this article covers:

source: DarkReading