What a Former North Korean IT Worker Revealed About the Remote-Work Scheme
A former North Korean IT worker described his previous life to The Wall Street Journal: long workdays in an overseas dormitory, strict earning quotas, and American identities used to obtain remote jobs.
The account is important because it makes two things visible at once. The workers may be operating under extreme pressure, and the access they gain can still create serious security risk for an employer.
A system built around quotas and control
The former worker described being selected and trained by North Korean authorities, sent abroad, monitored closely, and expected to generate thousands of dollars per month.
According to the report, workers lived and worked together, had little time off, and sent most of their earnings back to the government. Teams targeted countries and employers where remote technical roles could generate high pay and useful access.
U.S. citizens could be paid to lend identities, complete checks, or attend interviews. The same identity could support more than one overseas worker.
Why a “real identity” does not settle the question
This model explains why document checks and background checks can pass.
The American identity may be genuine. The person may knowingly appear for a verification step. The laptop may sit in the United States. None of that proves the operator writing code and accessing company systems is the same person the employer intended to hire.
Teams need to compare signals across the entire journey: application history, resume evidence, public identity, contact information, document metadata, device behavior, interviews, and post-hire activity.
Treat it as both a hiring and security problem
The workers are reportedly under pressure to keep earning even when an engagement is discovered. That can increase the risk of source-code theft, data exfiltration, extortion, or maintaining access long enough to create leverage.
Recruiting teams see the earliest evidence. Security teams see the consequences after accounts and devices are issued. Keeping those views separate makes both teams weaker.
If an organization is already finding fake applicants, it should consider whether the same campaign could have succeeded earlier. Re-reviewing current employees should be targeted and evidence-based, with appropriate legal and HR oversight—not a dragnet.
The human reality does not remove the obligation to act
It is possible to recognize that some workers are coerced or trapped by the system while also protecting candidates, employees, customers, and sensitive data from the operation.
Good fraud prevention should reduce harm on both sides: identify the small number of high-risk cases, avoid punishing legitimate remote applicants, and stop access before an exploited person becomes the channel for a larger threat.