all case files

case file 08north korean it scamAugust 2026Australia and the United States

it is not only engineering roles any more

Huntress documented three 2026 cases outside technology: an Australian healthcare company with three fraudulent employees, a finance firm where hardware was wired into a workstation to stream video into Zoom, and a sales hire who had face-swapped himself into a real person's ID documents.

3

documented 2026 cases

13 days

from onboarding to detection, one case

3

fraudulent hires at one healthcare firm

what happened

The assumption that this only targets software engineering jobs is out of date. In February 2026 an Australian healthcare company was found to have three employees posing as Chinese nationals, flagged by repeated Astrill VPN and residential proxy connections and near-identical passport documents.

In August 2026 a financial services firm found a PiKVM, a small device that lets somebody control a computer remotely at the hardware level, attached to an employee's machine, followed by a USB capture card used to stream video into Zoom calls. That is a purpose-built rig for having one person attend meetings while another does the work.

A third case involved a sales and marketing hire, onboarded thirteen days earlier, who had swapped his own face into the identity documents of a real person whose arrest record happened to be posted online.

DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them.

Huntress threat research

how it was caught

By endpoint and network monitoring after the hire, in all three cases. The healthcare company noticed the same VPN and proxy addresses recurring. The finance firm noticed unexpected hardware. The sales case turned on a coincidence: the real identity's arrest record was public.

Every one of these detections happened after the person was employed and had access.

what it cost

Huntress does not publish per-company losses for these cases, but the pattern is consistent: the cost is the remediation, the access review, and the question of what left the building.

The strategic cost is broader. A healthcare company and a sales team do not think of themselves as targets, and so do not look.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • Repeated connections from the same VPN or residential proxy provider across different employees.
  • Passport or ID documents that are near-identical in layout across separate applicants.
  • Unexpected hardware between the keyboard and the machine, or a capture card feeding a video call.
  • An identity whose real owner has a public record that does not match the person you interviewed.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

before the offer, not after

The healthcare company did eventually notice, months into employment. The same conclusion is available before an offer is made when the interview itself is the thing being examined.

NeuralPrint, on the person

A face swapped into ID documents survives a document review. It does not survive matching the live face against the identity throughout a session.

one person, one session

The rigs in these cases exist to put one person on the call and another on the keyboard. NeuralPrint reads whether a single, consistent human being is actually present for the whole interview.

sources

  1. [1]
    North Korean job fraud expands beyond tech into healthcare and sales

    Huntress, via The Hacker News · security research · August 31, 2026

    Three 2026 cases including a PiKVM plus USB capture card used to stream video into Zoom, and a hire who face-swapped himself into a real person's identity documents.

  2. [2]
    Imposter for hire: how fake people can gain very real access

    Microsoft Threat Intelligence · security research · December 11, 2025

    Four cases where KVM-over-IP hardware was attached to employer workstations. Cites Gartner's forecast that one in four candidate profiles will be fake by 2028.

  3. [3]
    i3 threat advisory: inside the DPRK

    DTEX Systems · security research · May 14, 2025

    Catalogues observed risk indicators: KVM-over-IP devices, anti-screen-lock utilities, OBS and ManyCam misuse to inject several workers into one video call, sessions running for days.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes