case file 09resume fraudSeptember 2026United States, remote IT roles
nearly half the applications
A hiring verification company that has screened more than 11 million applications found that the share of U.S. remote IT applications showing North Korean fraud patterns rose from 11 percent in late 2024 to 47 percent in late 2026.
47%
of remote IT applications, Q3 2026
11%
the same measure, Q3 2024
175k
flagged applications analysed
11m+
applications screened
what happened
Endorsed, a hiring verification company, analysed 175,000 flagged applications during 2026 out of more than 11 million it has screened. It found that the proportion of U.S. remote IT applications carrying patterns consistent with North Korean fraud had risen from 11 percent in the third quarter of 2024 to 47 percent in the third quarter of 2026.
The patterns are statistical rather than individually damning: claimed locations clustered in Texas, California and Florida, a repeating set of alma maters, a repeating set of former employers among well-known technology and financial companies, and a small set of recurring first names. More than half include a LinkedIn profile.
The company's own caution matters as much as the number. No single one of these traits should make an applicant look suspicious. It is the combination, at population scale, that shows the shape of the operation.
“One or even several of these traits should never make an applicant seem suspicious on their own.”
David Head, co-founder of Endorsed
how it was caught
By looking across an entire applicant population rather than at one candidate at a time. Clustering only becomes visible above a certain volume.
This is the structural problem for an individual hiring team. Each application looks plausible on its own. The pattern lives at a level no single recruiter can see.
what it cost
If the finding holds for a given remote IT pipeline, roughly half the applications a team reviews are not worth reviewing, and the recruiter time spent on them is spent on nothing.
The second cost is the one nobody measures: real candidates buried underneath, in a pile that is now half noise.
the tells
signals that were visible, in hindsight, before anyone was hired.
- A cluster of applicants claiming the same few metro areas for a fully remote role.
- Repeating alma maters and former employers across otherwise unrelated resumes.
- Resume text that is near-identical between candidates.
- Reused phone numbers or email patterns across supposedly separate applicants.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
λ-CORE evaluates candidates relative to the whole applicant pool, so repetition across supposedly unrelated applicants surfaces as a group signal rather than one candidate at a time.
When the fraud rate is this high, screening resumes harder does not help, because the resume is the artifact being faked. The interview is the step a fabricated application cannot complete on paper.
sources
- [1]47 percent of U.S. remote IT applications now show North Korean fraud patterns
Endorsed, via Fortune · security research · September 1, 2026
Based on 175,000 flagged applications analysed in 2026, up from 11 percent in Q3 2024. Endorsed's David Head cautions that no single trait should make an applicant look suspicious on its own.
- [2]CrowdStrike: 320+ Famous Chollima incidents in 12 months, up 220 percent
CrowdStrike, via CyberScoop · security research · August 4, 2025
Nearly one newly detected fraudulent hire per day in the twelve months to June 30, 2025.
- [3]North Korea's IT workers expand beyond U.S. big tech
Okta Threat Intelligence · security research · September 30, 2025
130+ tracked identities linked to 6,500+ first-round interviews at more than 5,000 companies through mid-2025.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
deepfake · March 2025
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.