North Korea Expands Remote Worker Infiltration Scheme, Now Recruiting Abroad to Bypass U.S. Hiring Checks

NewsData.io · United States · Sep 11, 2026

North Korea's scheme to plant remote IT workers inside U.S. companies has expanded beyond its own nationals, with operatives now recruiting individuals from Iran, Lebanon, Syria, South Africa, and other countries to conduct on-camera job interviews on their behalf, according to U.S. government agencies and cybersecurity researchers. Once a role is secured through a foreign proxy, a North Korean agent typically takes over the position, funneling salary earnings back to the regime — generating an estimated $600–$800 million annually. The tactic is a direct counter to anti-fraud measures HR and security teams have implemented, such as live video checks and identity challenges. Staffing agencies and corporate recruiters are urged to scrutinize remote candidates more rigorously, as the scheme now targets LinkedIn-sourced developers across Nigeria, Pakistan, India, and Latin America as facilitators.

FlareKudelski SecurityDTEXcybersecurityremote workrecruiting fraudIT staffingsanctions compliance

Related stories