The Identity-Rental Marketplace Behind 871 Proxy Identities
A man who helped overseas IT workers buy or rent stolen American identities has been sentenced to five years in federal prison.
The scale is what stands out. According to the U.S. Department of Justice, Oleksandr Didenko managed as many as 871 proxy identities, facilitated at least three U.S.-based laptop farms, and enabled North Korean workers to obtain employment at 40 U.S. companies.
Help Net Security also summarized the sentencing and the infrastructure behind the scheme.
Fraud facilitation became a business
The operation was more than one person lending a laptop to one worker. DOJ says a U.S.-based website allowed overseas clients to buy or rent identities. People in the United States received and hosted computers, while the operation helped route employment income through financial services and into foreign accounts.
That is a service layer for fraud:
- identity inventory,
- U.S.-based devices and network presence,
- account and payment access,
- background-check data,
- and a way to scale the same playbook across employers.
When that infrastructure is available for rent, even sophisticated fraud actors do not need to build every component themselves.
Why one-time verification is not enough
A stolen identity can pass because it belongs to a real person. A rented identity can pass because the real person is cooperating. A laptop farm can pass location checks because the device really is in the United States.
The hiring process therefore has to test continuity, not just validity:
- Does the resume align with credible identity history?
- Do application and document signals indicate repeated reuse or manipulation?
- Is the person interviewing the same person represented by the application?
- Do device and behavioral patterns remain consistent after access is issued?
- Can recruiting and security teams revisit the original evidence together?
Protect the legitimate candidates too
The answer cannot be blanket suspicion or extra friction for every remote applicant. That harms genuine candidates and teaches recruiting teams to avoid reviewing inbound applications altogether.
The better obligation is to use evidence proportionately: automate broad screening, escalate only meaningful combinations of signals, preserve an audit trail, and give a candidate a fair opportunity to resolve discrepancies.
The Didenko case shows how industrial the facilitation layer has become. Defending against it requires the same mindset—repeatable controls across the hiring lifecycle, not a single manual checkpoint.