North Korean ‘Fake Workers’ Exploit AI to Infiltrate European Companies

Pyongyang operatives are using artificial intelligence to pose as legitimate employees, creating a new global cybersecurity threat.

2 mins read
North Korean leader Kim Jong-un [File Photo]

A growing wave of North Korean IT operatives is using AI to masquerade as workers at major European companies, according to a report by the Financial Times. These “fake workers” secure remote jobs, earn wages, and carry out tasks while concealing their true identities, with operations traced back to Pyongyang’s regime. Cybersecurity experts warn that the practice represents a sophisticated form of economic and technological espionage, exploiting vulnerabilities in corporate recruitment processes.

Between 2020 and 2024, North Korean operatives reportedly infiltrated more than 300 US companies, generating at least $6.8 million for the regime, according to Department of Justice figures. Jamie Collier, lead adviser in Europe at Google Threat Intelligence Group, told the Financial Times that similar tactics are now spreading to Europe, where North Korean agents are reportedly establishing “laptop farms” in the United Kingdom. Collier explained that the scam exploits companies’ assumptions about recruitment, saying, “Recruitment has not naturally been seen as a security issue, so it’s an area of weakness in companies’ systems and these operatives are targeting that vulnerability.”

The scheme typically begins with identity theft, often by hijacking dormant LinkedIn accounts or purchasing access to them. Operatives then forge CVs and documents, use accomplices for endorsements, and employ AI tools such as digital masks, avatars, and deepfake filters to pass remote interviews convincingly. Alex Laurie, chief technology officer at cybersecurity firm Ping Identity, told the Financial Times that AI has greatly enhanced the operatives’ credibility. “By using large language models, operatives can generate culturally appropriate names and matching email address formats, ensuring that their communications do not trigger linguistic or cultural ‘red flags’ that previously spotted such scams,” he said.

As companies tightened online recruitment processes, North Korean operatives adapted by hiring real people, or “facilitators,” to conduct interviews on their behalf. Once hired, the operatives intercept laptops sent by employers and remotely complete tasks, sometimes managing multiple roles at once. Rafe Pilling, director of threat intelligence at Sophos’ counter-threat unit, described the operation as a “state-backed enterprise,” adding, “A mini army of North Koreans have been targeting high-salary, fully remote tech jobs. Framing themselves as talent with around seven to 10 years’ experience, getting jobs, drawing a salary — rinse and repeat.”

Amazon has also been affected. Stephen Schmidt, Amazon’s chief security officer, reported in January that the company had blocked over 1,800 suspected North Korean operatives from gaining employment since April 2024. The targeted roles increasingly include positions in AI and machine learning, Schmidt said, warning that the problem is not unique to Amazon but likely affects the broader tech industry.

Cybersecurity analysts highlight that the operatives’ use of AI not only enhances the deception but also allows them to operate across multiple time zones and complete tasks autonomously. This combination of technical skill, state backing, and AI-assisted deception has created a high-stakes challenge for corporate security teams attempting to authenticate remote workers.

The Financial Times report also notes that some operatives have attempted to compromise corporate systems, using remote access to load malware or otherwise interfere with internal operations. KnowBe4, a US-based cybersecurity firm, admitted that a fake North Korean worker had attempted to gain access to its security infrastructure before being identified.

Experts warn that the North Korean operation illustrates how AI can amplify existing cyber threats and complicate workforce security. Laurie said that the future of national and corporate security in Europe will depend heavily on companies’ ability to verify the authenticity of their employees in the face of persistent AI-enhanced adversarial tactics.

As the phenomenon spreads across continents, governments and corporations are under growing pressure to strengthen hiring protocols, implement rigorous identity verification systems, and train staff to recognize potential AI-driven manipulations. Analysts emphasize that while individual companies can take steps to defend against infiltration, the scale and sophistication of the operation suggest a coordinated, state-level strategy designed to generate revenue and gather intelligence abroad.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog