Case File 002
The vibrant profile had everything. The inactive profile had the real-world history.
Endorsed
Case File 002David Head3 min readJUL 29, 2026
Workday10,000+ Employees

Suspected North Korean frontman hired for years


We suspected the North Koreans had stolen this man's identity and hired a frontman from another country to pose as him at companies for years. They even knew where he lived.

This was one of the more sophisticated IT worker fraud cases we'd seen.

When the man applied to our enterprise customer with 10,000+ employees, Endorsed flagged his application in Workday as Medium Risk. The recruiting team decided to interview him anyway and "had an awesome interview."

At first glance, there was no VOIP number, no suspicious IP, and an address owner whose name matched the applicant's. All strong positive signals.

The insider threat team wasn't convinced, though, and wanted more certainty.

They dug deeper and asked if Endorsed could run its more advanced checks, both for security and compliance and to do right by the candidate if he turned out to be legitimate.

Two LinkedIn profiles were found with overlapping identities: the same unique name, the same education, overlapping work experience, and the same leadership role at the same organization at the same time.

But the people in the photos looked nothing alike. Impossible coincidence.

One appeared to be stealing the other's identity. Which one was it, though? Was it the person who applied or the other guy?

The applicant's LinkedIn was vibrant. The other one was inactive.

Vibrant Profile:

  • 500+ connections
  • Joined in 2019
  • Posting regularly
  • Sophisticated profile picture
  • Government ID verified in 2025
  • Endorsed flagged some abnormal behavior but nothing conclusive

Inactive Profile:

  • <250 connections
  • Joined in 2013
  • Never posted
  • Profile picture taken in a parking lot
  • No verifications
  • No suspicious behavior flagged by Endorsed

The recruiter said the man they interviewed looked like his profile picture.

Looking only at these signals, the applicant seemed legitimate.

Then came the data behind the address on the resume. Again, it matched the applicant's name, but multiple corroborating data points pointed to the man with the Inactive Profile owning that home. Extremely strange.

The OSINT trail showed the Inactive Profile almost certainly belonged to a real person. That person had a variety of associated online accounts, a wedding registry, and other validating records dating back years.

The OSINT trail of the person behind the Vibrant Profile? Despite the rich LinkedIn presence, virtually nothing existed online pointing toward this being a real person.

The evidence now strongly suggested the owner of the Vibrant Profile had stolen the other person's identity. And judging by the divergence of recent employers on each profile, this may have been going on for years.

Redacted correspondence with the insider threat team member about the candidate interview and suspected identity fraud
Share
Learn how Endorsed can protect your hiring pipeline