Suspected North Korean frontman hired for years
We suspected the North Koreans had stolen this man's identity and hired a frontman from another country to pose as him at companies for years. They even knew where he lived.
This was one of the more sophisticated IT worker fraud cases we'd seen.
When the man applied to our enterprise customer with 10,000+ employees, Endorsed flagged his application in Workday as Medium Risk. The recruiting team decided to interview him anyway and "had an awesome interview."
At first glance, there was no VOIP number, no suspicious IP, and an address owner whose name matched the applicant's. All strong positive signals.
The insider threat team wasn't convinced, though, and wanted more certainty.
They dug deeper and asked if Endorsed could run its more advanced checks, both for security and compliance and to do right by the candidate if he turned out to be legitimate.
Two LinkedIn profiles were found with overlapping identities: the same unique name, the same education, overlapping work experience, and the same leadership role at the same organization at the same time.
But the people in the photos looked nothing alike. Impossible coincidence.
One appeared to be stealing the other's identity. Which one was it, though? Was it the person who applied or the other guy?
The applicant's LinkedIn was vibrant. The other one was inactive.
Vibrant Profile:
- 500+ connections
- Joined in 2019
- Posting regularly
- Sophisticated profile picture
- Government ID verified in 2025
- Endorsed flagged some abnormal behavior but nothing conclusive
Inactive Profile:
- <250 connections
- Joined in 2013
- Never posted
- Profile picture taken in a parking lot
- No verifications
- No suspicious behavior flagged by Endorsed
The recruiter said the man they interviewed looked like his profile picture.
Looking only at these signals, the applicant seemed legitimate.
Then came the data behind the address on the resume. Again, it matched the applicant's name, but multiple corroborating data points pointed to the man with the Inactive Profile owning that home. Extremely strange.
The OSINT trail showed the Inactive Profile almost certainly belonged to a real person. That person had a variety of associated online accounts, a wedding registry, and other validating records dating back years.
The OSINT trail of the person behind the Vibrant Profile? Despite the rich LinkedIn presence, virtually nothing existed online pointing toward this being a real person.
The evidence now strongly suggested the owner of the Vibrant Profile had stolen the other person's identity. And judging by the divergence of recent employers on each profile, this may have been going on for years.
