all case files

case file 07synthetic identityApril 2026GitHub, Upwork, Freelancer

the persona factory

Group-IB traced a reusable-identity ecosystem running since at least 2021: the same GitHub account renamed from one invented engineer to another, AI-generated headshots, and stored logins for every freelance and payment platform that matters.

42

GitHub accounts

79

email addresses

23

fake portfolio domains

2021

active since at least

what happened

A synthetic identity is not a stolen identity. It is a person who never existed: an AI-generated headshot, an invented work history, a GitHub account with real-looking commits, and a portfolio site on free hosting. Group-IB documented an entire industrial pipeline for producing them.

The same GitHub account would be renamed from one invented engineer to another as personas burned out. One account went from Nicolas Sammaritano to Caddo Smith. Researchers also found prompt libraries for generating application answers with ChatGPT, and stored credentials for Payoneer, Wise, PayPal, AnyDesk, LinkedIn, Discord and Telegram, everything a persona needs to look like a working freelancer.

Group-IB's framing is the useful part: this is not a malware intrusion. It is a labour-enabled access model. The company is not broken into. It is persuaded to hire.

This is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse.

Group-IB threat research

how it was caught

By researchers correlating artefacts across platforms: the same portfolio template on different domains, the same photograph with a different name, the same GitHub account under a new identity.

None of these correlations are visible to a hiring manager looking at one candidate in one applicant tracking system. They are only visible to someone looking across the whole population at once.

what it cost

Group-IB does not attach a single dollar figure, because the cost is spread across every company that interviewed one of these personas without knowing.

The cost that does show up is recruiter time. A synthetic identity is cheap to produce and expensive to evaluate. That asymmetry is the business model.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • A profile photo that reverse-image searches to nothing, or that has AI-generation artefacts around the ears and hairline.
  • A GitHub account whose history does not match the claimed career length, or whose display name has changed.
  • A portfolio site on free hosting with a template shared by other candidates.
  • Inconsistent name spelling, location or education across LinkedIn, the resume and the portfolio.
  • An impressive resume paired with surface-level knowledge when questioned.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

open source threat intelligence

The identifiers in this research are public. aperture checks applicants against published indicators from work like this, and a match becomes a flag with the source attached rather than a silent rejection.

NeuralPrint, on the person

A synthetic persona has a face that belongs to nobody. Matching the live session against the identity presented is where an invented person stops working.

adaptive questioning

Prompt libraries generate strong answers to predictable questions. They cannot produce a specific, checkable detail about work that never happened once the follow-up is built from the previous answer.

sources

  1. [1]
    DPRK fake remote developers: a reusable-persona ecosystem

    Group-IB · security research · April 8, 2026

    42 GitHub accounts, 79 email addresses and 23 portfolio domains traced across GitHub, Upwork and Freelancer, active since at least 2021.

  2. [2]
    Generative AI services power DPRK IT contracting scams

    Okta Threat Intelligence · security research · April 24, 2025

    Facilitators use AI to test CVs against applicant tracking systems, rehearse deepfake overlays in mock interviews, and run chatbots that answer technical questions live.

  3. [3]
    Nickel Tapestry expands fraudulent worker operations

    Sophos Counter Threat Unit · security research · 2025

    Cloned resumes, reused VoIP numbers, and shared contact details across supposedly separate applicants.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes