North Korea has launched a sophisticated, industrial-scale cyber operation targeting Western companies by masquerading as legitimate IT workers. This "phantom workforce" uses stolen American identities, AI-generated faces and voices, and remote laptop farms to infiltrate organizations, gain access to source code, internal systems, and sensitive data, and extort ransomware or steal intellectual property. The operation began with traditional fraud—such as fake resumes and remote work—but has evolved dramatically with the advent of generative AI, which enables near-perfect deepfakes and automated resume and interview preparation. These actors apply to thousands of jobs, often passing interviews, receiving salaries, and becoming insiders who can exploit organizational trust. Despite FBI raids and arrests, the threat persists, as AI allows one individual to assume infinite personas across multiple companies and geographies. Security gaps stem from the absence of continuous identity verification—no system currently confirms a person’s identity throughout the entire employment lifecycle. As North Korean operatives now leverage AI to manipulate human intuition, companies face a new frontier where trust is not just in authentication, but in continuous, real-time identity validation. The CISO signal warns that the next major cyberattack may not come from a breach—but from a seemingly legitimate job applicant. To defend against this, organizations must adopt zero-trust frameworks that verify identity across all interactions—using biometrics, device behavior, and behavioral analytics—ensuring that the person behind a screen remains consistent and authentic from application to exit. As North Korea's operations grow in scale and sophistication, the need for proactive, AI-aware identity protection becomes critical.
"You have North Koreans knocking at your door, no matter the position on every single
job that you have."
Welcome to the CISO signal, I'm Jeremy Ladner.
For years, North Korean hackers have broken into banks, robbed cryptocurrency exchanges,
and deployed ransomware against some of Western democracies' largest corporations.
And then, they found an even more dangerous and profitable way to attack the foundations
of our economy, get hired, get paid, and then get privileged access.
What investigators have uncovered is not a single hacker or a single spy.
It is an industrial-scale operation involving North Korean operatives, stolen identities,
financial facilitators, laptop farms, and ordinary people recruited to help conceal one of
the largest covert enemy workforces in modern history.
Hundreds of American companies have already been infiltrated.
Millions of dollars have been funneled back to a sanctioned regime and trusted employees
were given legitimate access to source code, internal systems, and the sensitive information
of the companies that hired them.
But the laptop farms were only the beginning.
The arrests didn't stop them, the FBI raids didn't stop them.
And now, artificial intelligence is allowing the operation to manufacture the face and the
voice and the person applying for the job.
How did North Korean operatives convince some of the world's largest companies to hire
them who built the hidden infrastructure that made it all possible and how is AI transforming
in an already massive operation into something even harder to detect?
Because the next cyberattack may not begin with someone trying to break into your company's
work, it may begin with someone applying for a job.
This is the story of North Korea's phantom workforce.
And to help us with this investigation, we're joined by VJ Balasub Rumanian, CEO and co-founder
of Pindrop.
Pindrop is also the sponsor of today's episode.
For more than two decades, VJ has dedicated his career to solving one of the most fundamental
challenges cybersecurity faces.
How do you know the person on the other end is who they claim to be?
Today, Pindrop helps organizations answer that question by detecting AI-generated deception
and continuously verifying identity across voice and video and digital interactions, restoring
trust while reducing fraud and lowering operational costs and improving customer experience.
Trusted by many of the top 10 US banks, leading insurers and healthcare providers, Pindrop's
technology is powered by models trained on more than five billion real world interactions
and protected by more than 300 patents.
And in 2026, time named Pindrop, one of the 10 most influential software companies.
So VJ, you certainly have a lot to be proud of.
Welcome to the CISO signal.
Jeremy, that was a great introduction.
Thank you for having us.
Our pleasure.
Are you ready to begin the investigation?
I am absolutely ready.
We are in the midst of a ceaseless war.
Not of bombs or bullets, but of breaches, firewalls, and silent incursions.
The targets, our borders, our banks, our commerce, and the critical infrastructure that underpins
a free civilization.
The enemy is cloaked in code, fueled by greed, glory, and a desire for chaos.
This is the story of the unseen protectors, the nameless generals, the CISOs, chief information
security officers.
They are the guardians at the gate, the watchers on the wall, ever vigilant, and always listening
for the CISO signal.
Act one, the perfect employees.
There's two ways in which you can attack an organization from the outside and then from
the inside.
What the North Korean operatives have figured out is the outside is a long, arduous journey,
and often you are having to constantly guess at the controls that the organization has.
Once you're inside the organization, as an insider threat, you have very little.
Employment is the best way to that.
It's Monday morning.
Samantha, 24-year-old HR recruiter, takes a moment to prepare for her next back-to-back interview.
Her coffee is getting cold next to her keyboard, there's no time to drink it.
She's already interviewed two candidates this morning and has another to go, with five
more lined up after lunch.
On the floor below her, an engineering manager is waiting for a short list of approved candidates
for a position that's been open for far too long.
Samantha's screen flickers, a face appears against a bookcase.
The resume matches the position and when the technical questions begin, the candidate
knows all the answers.
To Samantha, nothing about the interview feels like a nation-state attack, and that is
why it is so effective.
The employment itself gives you steady income, sanction-free, goes to funding the nuclear
programs, and a lot of these North Korean operatives have either been caught within the first
day to as long as seven months to a year, and in that time, what they're able to do is
plant in the malware, plant in the ransomware, if they're part of a cryptocurrency firm, steal
the wallets, understand the entire IT infrastructure, what does a password reset look like within
the organization?
So once they've left the organization, they have such a blueprint of what the inside
of the organization looks like, that you can completely use that as a way to continue
these attacks well after you've gone.
North Korea did not invent the remote employee threat.
It simply recognized the opportunity remote employees made possible.
For decades, international sanctions restricted the regime's access to foreign currency.
Cybercrime became one way around those restrictions.
There are a lot of things that you need to do to get hired.
I'll give you a couple of examples.
When you think about the hiring process itself, you typically have a recruiter who's going
to do the first phone screen, and then you have the hiring manager and multiple interviews
thereafter.
Along this entire journey, no one is actually describing who they actually talked to.
So we have to create a great resume, but even through the process, there is nothing that
a recruiter is saying to the hiring manager that tells them they're actually interviewing
Jeremy.
But for example, interviewing me VJ, the recruiter isn't saying, "Man, I talked to VJ."
He was a great interviewer.
He's wearing glasses, and he's Indian.
In fact, some of these things they can't say because they're H.R. violations.
Breaking into a bank or stealing cryptocurrency requires entering without permission.
The fake IT worker campaign inverted the model.
You don't have to break into the company.
Just become the employee the company is already searching for.
The recruiter confirm your experience, let the engineering manager vouch for your ability
and let IT issue your credentials.
Then enter through the remote front door every morning with permission.
So just saying, "Create resume, great interview, and passing it on to the hiring manager."
The hiring manager could go talk to someone completely different and not know what we
find is 6% of the second interview, someone completely different shows up, which is mind-boggling.
Then the person who actually shows up for the job, we've seen some of these folks between
interviews and sometimes they look fairly similar.
And that is the issue, right?
The fact that there is no notion of identity all across these interviews, there's no notion
of continuous identity, and who actually finally shows up.
You actually don't know whether they were the ones who interviewed.
And there's all of these gaps through the entire process.
US authorities say North Korea dispatched thousands of skilled workers around the world, many
operating from China and Russia.
They pursued jobs in software development, blockchain and artificial intelligence, all
while posing as citizens or residents of other countries.
They weren't pretending to be engineers.
They were engineers.
They could discuss cloud architecture, self-coding exercises and write production, quality, software.
And aside from their engineering ability, everything else was a lie.
Their name, their face, their location.
And then, in 2020, COVID-19 emptied offices around the world.
Interviews moved on to computer screens contracts arrived by email, company laptops criss-crossed
the country inside cardboard boxes, and distance no longer looks suspicious.
It looked like a safety precaution.
The deception has to continue all day, every day, from the time that you get hired moving
forward.
What sort of hidden infrastructure allows North Korea to pull off this sort of heist?
There's a lot of cases where people who say they're a fully in-person company don't realize
how remote they are.
Fully in-person sometimes means you're showing up two days a week.
Sometimes means you have contractors who are completely remote.
Fully in-person means you have offshore units in India that you have no clue those people
really showing up.
So, there is the myth that you're in-person, but that myth is one that is completely shattered
by what happened during COVID.
And the convenience that when you are a really good employee, remote versus in-person actually
doesn't matter.
When we talk to some of these customers and we say, "Hey, what are the signals you saw?
Whatever is a signal, the quality of work output?"
It's another Monday morning.
and the new employee joins the team stand up.
Later, he answers messages, reviews, code,
and requests access to another system.
For a time, many of these victims
genuinely perform the jobs they'd been hired to do
because the salary was the first objective, only the first.
In December of 2024, 14 North Korean nationals
were accused of generating at least $88 million
for the sanctioned regime.
And that is incredibly important for us to realize
because these are North Korean IT workers
who know how to face swap, create resumes,
create ransomware.
And in fact, their technical prowess is so strong
when we profile the laptops from which they come,
they're super old laptops, Windows 95,
whenever you ever heard of anyone using Windows 95,
or Windows NT, but some of them use those laptops
and are still able to do their job at great levels.
And we see them not just holding one job,
we see them holding multiple jobs.
And then the final bastion is,
hey, can you be there physically?
And this is where they're actually hiring mules
and people from the United States.
- An engineer has easy access to things
an outside attacker would normally have to steal.
Source code, cloud environments,
development pipelines, and customer information.
The salary, of course, was only the beginning.
The real prize was the access that came with it.
And in January of 2025, the FBI warned
that North Korean IT workers were increasingly stealing
proprietary information.
In some cases, they demanded money
after their employment was terminated.
- What that means is, every time there's a company
in person event, you have to go there.
Whenever you have to collect a laptop
or any of these other things, you have to go there.
And because these guys are such good workers,
the God is down.
And all you're saying is that I'm going to assume
that somewhere during this physical interaction,
someone picks up something's off.
We've always known the human is the weakest link.
And if you have a physical presence
for each of these IT workers, that's all that matters.
And you've completely beaten the system.
- The Phantom employee was becoming an insider threat.
And then there was no before.
A security awareness company built around teaching
other organizations to recognize deception.
In 2024, no before hired a software engineer
using a valid but stolen American identity
and an AI enhanced photograph.
He passed four video interviews.
He cleared a background check.
And then of course, he received the job.
On July 22nd, one week after his company computer arrived,
alerts appeared inside No Before's Security Operation Center,
attempts to manipulate session history,
potentially harmful files, unauthorized software.
No before contained the account within roughly 25 minutes,
the security team moved quickly.
But by then, the hiring process had already done exactly
what the attacker needed.
- So this is what shocks us the most.
What we're finding is one in six applicants applying for jobs
is completely fake.
That's 16.8% of your applications are completely junk,
completely made up.
In that bucket, last year, we were trending
one in 343 applicants being from North Korea.
And this year, we've seen a 630% jump to that number
where one in 47 applicants are actually from North Korea.
If you have 100 applicants, two of them are North Korean.
Most jobs, remote jobs get 800 applicants.
You have North Koreans knocking at your door
on every single job that you have.
The identity had been accepted.
The account had been created
and the endpoint had been supplied by the company itself.
The name could be stolen.
The photograph could be altered.
And of course, the interview could cross an ocean.
But the laptop, the laptop still had weight.
Someone inside the United States had to receive it.
Who opened the box, who connected the computer,
who made a machine inside an ordinary American home
appeared to be the employee sitting behind it.
The answer would lead investigators away
from the face on the screen and into the homes
keeping the phantom workforce alive.
And the crazy thing about it is because these North Koreans
need to look like Christina Chapman
or they need to avoid being on the FBI's most wanted list.
They're also face swapping themselves.
And we have examples of the same North Korean IT worker
applying for multiple jobs
and with two completely different personas
to completely different faces.
And the only way we got them is the same voice.
You're having one North Korean IT operative
who can assume essentially infinite personas,
apply for infinite jobs and infinite varieties of jobs.
They just have to get in once.
And that is what creates the scale.
But also the sophistication of the tools that they're using
and finally the believability that you're actually
talking to someone really good, who's named Michael Johnson,
who's a great lawyer, who we really, really want to applaud.
Before we continue, I'd like to take a moment
to thank the more than 22,000 people
who've already subscribed to the channel.
If you haven't subscribed yet and you're enjoying the show,
please take a moment to do that now.
Leave us a like and a comment with your ideas
for future episodes or guests that you like to see on the show.
And please share this episode with other cybersecurity
professionals that really helps us grow the CSO signal.
And now, act two, the American address.
It's typically overwhelmingly technical role
software developers, cloud engineers,
DevOps professionals.
On the surface, you might assume it was because,
well, like, command high salaries.
Is that the whole story?
What COVID and all these platforms have shown
in remote work is if you are actually from the US,
you command a higher salary than if you said somewhere else.
That's the first thing.
The second thing is these guys are very good
in the software engineering and IT profession.
What they've realized is success begets success.
That's where they're able to keep the con the longest,
get the salary for the longest, inflict the maximum amount
of damage 'cause IT folks have most access.
So that is absolutely a place where they're focused.
But we are seeing them branch out.
We are seeing interestingly some of these other functions,
but IT is absolutely the predominant one.
A laptop cannot pretend to be in Arizona
and has to be there.
That single constraint created an American support industry
around North Korea's phantom workforce.
Company computers arrived at residential addresses.
Inside, they were unpacked, connected,
and left running while workers overseas
control them remotely.
The IP address looked American.
The company asset remained inside the country
and the employee appeared to be sitting behind.
Investigators called these locations laptop farms.
The name suggests a massive sprawling warehouse.
The reality is usually much smaller.
A spare room, a folding table,
and a row of blinking routers.
So what we're seeing is a hierarchy of issues.
The first thing that North Koreans are trying to get
is just a basic paycheck.
And when you get a $200,000 salary
and you can multiply it by having five, six jobs,
you're actually making close to a million dollars
as an individual.
And depending upon the environment they're in,
they're trying to get other things.
In cryptocurrencies, we've seen them train crypto wallets.
And they're able to do all kinds of things,
like wallets that are not monitored,
haven't been used for a long time.
Let me go after that.
We're also seeing things like corporate espionage, right?
IP and information that they're collecting
that they potentially can sell to higher speeders.
For example, in supply chain companies,
where they are fundamentally infiltrating
those companies to do corporate espionage.
When they're infiltrating and they happen to be
in third party conversations,
they're getting crazy information from vendors.
- Computers from unrelated employers
it's side by side on shelves,
power cords criss-cross the floor
and handwritten post-it notes connect each machine
to the American identity it is meant to impersonate.
The illusion on the screen depends on ordinary work behind it.
Someone has to receive the delivery, open the box,
keep all of the computers running.
Then investigators began hunting down
the people behind the machines.
One was named Alexander Didenko,
a Ukrainian national who operated a service
called Upwork Cell.
Didenko admitted so in false identities
and online accounts and proxy infrastructure.
The service managed as many as 871 proxy identities
and helped facilitate at least three laptop farms
in the United States.
- And then the final thing is malware and ransomware.
Once I'm an IT admin, I can put in all kinds of malware,
all kinds of ransomware.
When they're leaving, they're saying,
unless you give me X million dollars,
I'm going to delete this file system.
The repercussions of having an insider who's North Korean
go long after they've left the organization
and you've thought you've shut out the problem.
You might have paid for the ransomware,
but when you think about your processes,
your organizational processes, they are long-standing.
Sometimes you don't even understand
How's it going?
some of those processes continue to exist two years
because you're not going to wholesale change
every single process that you have
because you've got a North Korean.
And that's the long tail of this issue.
Then in September of 2023,
one company laptop stopped cooperating.
The machine was having difficulty connecting
at a laptop farm in Virginia
and the overseas worker needed it moved immediately.
A new address was supplied nearly 2,000 miles away
in the Lichfield Park, Arizona.
The recipient was Christina Marie Chapman.
By October 6th, the laptop was back online.
And three weeks later,
FBI agents arrived at Chapman's home with a search warrant.
Inside, they found the physical shape of a crime
that had existed mostly on computer screens.
More than 90 laptops.
Photographs released by the Department of Justice
showed computers haphazardly arranged
on shelves and side tables inside the house.
Laptops were stacked together.
Each represented a phony employee working
for a very real American company.
Many of the companies targeted were not unsophisticated.
Had mature security programs dedicated security teams,
but there was blind spot, of course.
What do you think that a lot of these companies
didn't realize then,
but may realize now in hindsight about those blind spots?
If you are giving all of that access to a North Korean,
the Zero Trust does not matter.
They are going to, at every login,
be able to completely demonstrate
in a Zero Trust fashion that it's truly them.
But who is them?
Is it still the same human
that you identified all the way through that showed up?
And is that human originally North Korean?
Zero Trust doesn't address that at all.
You need other things, right?
Like you need one, the ability to identify
when you're truly talking to the right human.
And then you need continuous identity,
the fact that the identity not just at login,
but throughout the session is the same
and is the same across sessions.
We need a higher bar for identity
than we've had traditionally.
And for sure, after generative AI
and agentic AI have come about.
- Prosecutors say Chapman's operation ran
from approximately October 2020
until October 2023, helping overseas workers obtain jobs
at more than 300 companies.
The victims included Fortune 500 corporations
at television network, Silicon Valley Technology Company
and an aerospace manufacturer,
and an American automaker.
Chapman did more than host computers.
Prosecutors say she forged payroll checks
and controlled accounts receiving the wages.
In all, 68 stolen American identities were tied to the scheme.
The operation generated more than $17 million.
Chapman also shipped 49 laptops
and other devices overseas,
including packages sent to a Chinese city
near the North Korean border.
Investigators found stolen identities diverted salaries
and company computers moving towards North Korea.
Chapman was arrested on May 15th, 2024,
but she was only one facilitator in a much larger system.
This is not about authentication anymore.
This is an identity problem.
So how should that change the way CSOs think about trust?
- Establishing that continuous identity
right from the very beginning,
and I truly mean it has to be continuous.
So if we're in a Zoom call,
you need identity all through the Zoom call.
If you're getting close to determining
that this is a person who's going to come work for you,
you need to make sure you have a higher order
of identity for them.
And that could include device characteristics,
behavior characteristics, biometric characteristics.
You only have a few ways in determining identity
in the remote world.
So something you are because you have biometrics,
there's something you have because you have device,
and there's something you do
because you have behavioral characteristics.
So you have to start tracking all of that
and you have to make sure this is completely privacy-preserving.
- In Tennessee, Matthew Isaac Newton
was accused of enabling workers in China
to control company laptops remotely.
Four employers paid more than $250,000 in salaries,
and then reported over half a million dollars
in investigation and remediation costs.
Add that sum to the costs of isolating affected machines,
generating forensic images, password resets,
plus the question waiting beneath all of it.
What did these employees reach?
While we believe they belonged here.
- Once you've created that profile of this person,
that this is the person that you've been interviewing,
you have to maintain that identity token
all through the life of the employee.
At some point in the future,
you'll have to maintain it
even post the life of the employee.
Because then you can start making a mapping
of which identities have only done good things
and which identities have done malicious things.
- Between June 10th and June 17th, 2025,
the FBI searched 21 locations across 14 states,
believed to be hosting known or suspected laptop farms.
On July 24th, Chapman was sentenced
to 102 months in federal prison.
The sentence closed one case.
It not closed the operation.
Chapman's house had not been the laptop farm.
It was simply a laptop farm
and as investigators learned to identify
and locate the machinery behind the Phantom workforce.
The Phantom workforce was continuing to evolve.
Back three faces for phantoms.
- Everyone has the tendency to believe
that they are somehow special
and the barbarians are not at their gate.
There is the notion that there is a perimeter
and that perimeter does not exist.
Anyone who assumes that their perimeter is secure
because of some kind of control is mistaken
because the world is global.
You can have access from all different places.
- By then, investigators were no longer uncovering
isolated crimes.
They were mapping an entire ecosystem.
Laptop farms had been searched.
Computers and accounts seized.
Facilitators arrested and North Korean nationals
and died it.
Every arrest revealed another strand.
But the web remained.
This was not one breach.
It was an entire business model
and the model was still in its infancy.
- For example, you can't just say,
"Hey, because someone showing up with a VPN, that's bad."
Because that's part of how we all show up.
I think the biggest misconception is
because they have some security controls
that they implemented before Generative AI,
before Agentic AI, those controls
are still going to hold post the situation.
You might have all the great security mechanism
once someone is inside.
But if your front door and the way you're letting people in
is wide open, what does it matter?
What security controls you have once you're inside?
- The original deception had to survive contact
with something real.
The stolen name had to match a document,
a resume had to survive an interview,
a face on a video call, had to resemble a photograph.
Each checkpoint introduced friction.
Then, artificial intelligence began sanding away
the imperfections of the con.
Microsoft researchers observed North Korean IT workers
using face swapping tools to alter identity documents
and place ordinary photographs inside
polished professional settings.
Slightly different versions of the same face
appeared across multiple resumes.
One person could begin to look like several candidates.
Large language models tailored resumes,
translated messages, and prepared answers
to likely interview questions.
Researchers also observed workers experimenting
with voice changing software.
And then, real-time AI video deepfakes
made a massive leap forward.
- What used to take, like, for example,
to clone your voice, Jeremy?
I would need you to sit in a beautiful,
hermiatically sealed room and speak for 20 years.
That's how John Legend became the voice of Google Home.
Fast forward to now, there are 900 tools
that can clone your voice and over 100 tools
that can take a single LinkedIn image
and make a video of you.
It used to take 20 hours, now takes three seconds of audio.
You have a North Korean IT worker
who has the access to AI.
Someone is already good with IT, now has AI
that can magnify their capabilities.
AI is already scary, but AI in the hands of an insider
who's from North Korea is truly, truly scary.
Another interview begins.
A recruiter opens a resume on one side of the screen
and a candidate appears on the other.
The name matches the invitation,
the face resembles the photograph,
the answers arrive without any hesitation.
It looks like an ordinary job interview,
but it is all a carefully crafted, deep fake illusion.
The final human checkpoint, the moment someone looks
into a camera and decides, yes,
this is the person in the documents
has become another system that can be hacked.
For Pin drop, that was no longer theoretical.
It was appearing in the applicant data
the company examined.
Approximately one in six applicants
showed clear signs of being fraudulent or fake.
We've done tests with humans on how good they are
at detecting synthetic identities and deepfakes
and humans have a 38% accuracy in detecting a deep fake,
Which is worse off than a monkey with a random mouse.
coin toss. It's just so easy to fool the human brain. But in this world where synthetic
identities are indistinguishable from real ones, I think the organizations that will win
are ones that adopt the notion of continuous identity. That say, hey, I'm going to monitor
the identities that are interacting with my devices, my infrastructure, my servers, my cloud,
inner continuous fashion from the source identity that I've built and monitored and using it
at every point of access. Again, in a zero-trust fashion, I think that's going to be important.
In 2025, approximately one in 343 applicants were linked to infrastructure or behavior associated
with North Korea. Among those DPRK linked applicants, one in four used a deep fake during a live
interview, then an exponential jump in the numbers. During the first three months of 2026,
Pindrop reported that the proportion showing potential DPRK connections had risen from
approximately one in 343 to one in 47. That trajectory is not just shocking. It is alarmingly
dangerous. As you look at the threat intelligence today, how is this operation evolving?
Originally, they were bringing in about $5,000 per IT operator. Now that number has gone up
to $20,000. It's four times most success over the last 12 months. So the scale is going to
for sure change. The second thing that we're seeing is their level of magnitude of operations
is going to change. So we're seeing these North Korean operatives start to recruit other units.
The interview ends. The candidate thanks. The recruiter in the video window disappears.
All that remains is a scorecard asking the interviewer to grade the applicants on their technical
ability, on their communication skills, and of course, on their experience. None of those boxes
asks whether the person who answered the questions existed as presented. At first, the operation
needed to stolen identity than an American address, then proxy infrastructure to make an overseas
worker appear local. Now, artificial intelligence could attack the part that still is protected
by human intuition. When an interviewer looks at a candidate, when an interviewer listens
to the candidate and decides whether that candidate is an actual human being. In April of 2026,
Kijie, Tony Wang, and Zhijing, Danny Wang were sentenced to federal prison for facilitating
another fraudulent remote worker operation. Prosecutors said it used at least 80 stolen American
identities and generated more than $5 million dollars from North Korea. One investigation ended,
but the model continues. Handing it off to candidate farms in Iran, in Pakistan, in India,
indicators have compromised that you had, that were clear, that they were coming from North Korea,
no longer going to be the standard indicators of compromise, because now you're going to have
a global explosion. And so that's going to be another big area. And then just the sophistication,
we're seeing these AI tools be able to do all kinds of wonderful things, but also you can see that
they're able to chain together these two zero days and attack the organization from the inside.
North Korea's IT worker attack had never depended on one worker or one laptop, farmer,
one disguise. And artificial intelligence was making it cheaper, faster and easier to repeat.
What North Korea spent years refining was beginning to look less like an isolated capability,
and more like a preview of what was to come. For years, cybersecurity invested in protecting
networks, and then endpoints, and then identities. Those controls still remain essential, but this
investigation exposed an assumption that came before all of them, before the account was created,
before the laptop was shipped to a new employee, before the first login was authenticated.
Someone had already looked into a camera, and assumed that the employee they were about to hire
was real. VJ, it has been a pleasure having you on the show, looking forward to having you back
again soon. It was an absolute pleasure having this conversation as well. And now, our closing. At
first glance, this looks like an ending. Christina Chapman is in prison laptop farms have been
searched. Computers and accounts have been seized, but an ending requires the story to be over,
and the phantom employees are still applying for jobs. Because the next nation-state intrusion
may not begin with an attack or forcing their way into your organization, it may begin with a
seemingly qualified candidate. Convincing face and someone on human resources,
clicking the send-offer, and so. We must remain forever vigilant, and always listening,
for the CISO signal.
If you enjoyed this episode, please like, share, and subscribe. If you didn't, thanks for listening
this long. We'll see you on the next episode of the CISO signal. All episodes are based on
publicly available reports, post-mortems, and expert analysis. While we've done our best to
ensure accuracy, some cybersecurity incidents evolve over time, and not all details have been
confirmed, our goal is to inform and entertain, not to assign blame. Where facts are unclear,
we've used cautionary language, and we always welcome your corrections. Thanks for listening.
to the CCR signal.
Podcast Summary
Key Points:
North Korean operatives have established an industrial-scale cyber operation by infiltrating U.S. companies through fake employment, using stolen identities, AI-generated faces and voices, and remote laptop farms to gain privileged access.
These "phantom employees" exploit the lack of continuous identity verification, bypassing security checks by passing interviews, receiving salaries, and gaining access to sensitive systems—all while maintaining plausible deniability through AI-enhanced deepfakes and identity spoofing.
The rise of generative AI has dramatically increased the sophistication and scale of these operations, allowing North Korean cyber actors to create multiple personas, apply to countless jobs, and generate over $100 million in illicit revenue, with one-in-4 DPRK-linked applicants using deepfakes in interviews.
Summary:
North Korea has launched a sophisticated, industrial-scale cyber operation targeting Western companies by masquerading as legitimate IT workers. This "phantom workforce" uses stolen American identities, AI-generated faces and voices, and remote laptop farms to infiltrate organizations, gain access to source code, internal systems, and sensitive data, and extort ransomware or steal intellectual property. The operation began with traditional fraud—such as fake resumes and remote work—but has evolved dramatically with the advent of generative AI, which enables near-perfect deepfakes and automated resume and interview preparation.
These actors apply to thousands of jobs, often passing interviews, receiving salaries, and becoming insiders who can exploit organizational trust. Despite FBI raids and arrests, the threat persists, as AI allows one individual to assume infinite personas across multiple companies and geographies. Security gaps stem from the absence of continuous identity verification—no system currently confirms a person’s identity throughout the entire employment lifecycle.
As North Korean operatives now leverage AI to manipulate human intuition, companies face a new frontier where trust is not just in authentication, but in continuous, real-time identity validation. The CISO signal warns that the next major cyberattack may not come from a breach—but from a seemingly legitimate job applicant. To defend against this, organizations must adopt zero-trust frameworks that verify identity across all interactions—using biometrics, device behavior, and behavioral analytics—ensuring that the person behind a screen remains consistent and authentic from application to exit.
As North Korea's operations grow in scale and sophistication, the need for proactive, AI-aware identity protection becomes critical.
FAQs
They create false identities, use AI to generate realistic faces and voices, and apply for jobs as skilled IT workers, gaining legitimate access to company systems through the hiring process.
AI enables face and voice swapping, generates fake resumes and interview answers, and creates deepfakes that make fraudulent applicants appear genuine during video interviews.
Laptop farms are residential locations where stolen American identities are used to host company laptops remotely, allowing North Korean workers to operate from overseas while appearing to be based in the U.S.
Remote hiring eliminates physical verification, allowing fraudsters to pass background checks, fake interviews, and gain access to sensitive systems without detection.
These operations have generated over $88 million in revenue for North Korea, with individual workers earning up to $200,000 per year across multiple jobs, and companies facing massive remediation costs.
Traditional methods are ineffective—humans only detect deepfakes with 38% accuracy—so companies need continuous identity verification using biometrics, device behavior, and behavioral analytics.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.