case file 07synthetic identityApril 2026GitHub, Upwork, Freelancer
the persona factory
Group-IB traced a reusable-identity ecosystem running since at least 2021: the same GitHub account renamed from one invented engineer to another, AI-generated headshots, and stored logins for every freelance and payment platform that matters.
42
GitHub accounts
79
email addresses
23
fake portfolio domains
2021
active since at least
what happened
A synthetic identity is not a stolen identity. It is a person who never existed: an AI-generated headshot, an invented work history, a GitHub account with real-looking commits, and a portfolio site on free hosting. Group-IB documented an entire industrial pipeline for producing them.
The same GitHub account would be renamed from one invented engineer to another as personas burned out. One account went from Nicolas Sammaritano to Caddo Smith. Researchers also found prompt libraries for generating application answers with ChatGPT, and stored credentials for Payoneer, Wise, PayPal, AnyDesk, LinkedIn, Discord and Telegram, everything a persona needs to look like a working freelancer.
Group-IB's framing is the useful part: this is not a malware intrusion. It is a labour-enabled access model. The company is not broken into. It is persuaded to hire.
“This is not a classic malware intrusion chain; it is a labor-enabled access model built around social engineering, synthetic identity operations, and platform abuse.”
Group-IB threat research
how it was caught
By researchers correlating artefacts across platforms: the same portfolio template on different domains, the same photograph with a different name, the same GitHub account under a new identity.
None of these correlations are visible to a hiring manager looking at one candidate in one applicant tracking system. They are only visible to someone looking across the whole population at once.
what it cost
Group-IB does not attach a single dollar figure, because the cost is spread across every company that interviewed one of these personas without knowing.
The cost that does show up is recruiter time. A synthetic identity is cheap to produce and expensive to evaluate. That asymmetry is the business model.
the tells
signals that were visible, in hindsight, before anyone was hired.
- A profile photo that reverse-image searches to nothing, or that has AI-generation artefacts around the ears and hairline.
- A GitHub account whose history does not match the claimed career length, or whose display name has changed.
- A portfolio site on free hosting with a template shared by other candidates.
- Inconsistent name spelling, location or education across LinkedIn, the resume and the portfolio.
- An impressive resume paired with surface-level knowledge when questioned.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
The identifiers in this research are public. aperture checks applicants against published indicators from work like this, and a match becomes a flag with the source attached rather than a silent rejection.
A synthetic persona has a face that belongs to nobody. Matching the live session against the identity presented is where an invented person stops working.
Prompt libraries generate strong answers to predictable questions. They cannot produce a specific, checkable detail about work that never happened once the follow-up is built from the previous answer.
sources
- [1]DPRK fake remote developers: a reusable-persona ecosystem
Group-IB · security research · April 8, 2026
42 GitHub accounts, 79 email addresses and 23 portfolio domains traced across GitHub, Upwork and Freelancer, active since at least 2021.
- [2]Generative AI services power DPRK IT contracting scams
Okta Threat Intelligence · security research · April 24, 2025
Facilitators use AI to test CVs against applicant tracking systems, rehearse deepfake overlays in mock interviews, and run chatbots that answer technical questions live.
- [3]Nickel Tapestry expands fraudulent worker operations
Sophos Counter Threat Unit · security research · 2025
Cloned resumes, reused VoIP numbers, and shared contact details across supposedly separate applicants.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
deepfake · March 2025
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.