case file 08north korean it scamAugust 2026Australia and the United States
it is not only engineering roles any more
Huntress documented three 2026 cases outside technology: an Australian healthcare company with three fraudulent employees, a finance firm where hardware was wired into a workstation to stream video into Zoom, and a sales hire who had face-swapped himself into a real person's ID documents.
3
documented 2026 cases
13 days
from onboarding to detection, one case
3
fraudulent hires at one healthcare firm
what happened
The assumption that this only targets software engineering jobs is out of date. In February 2026 an Australian healthcare company was found to have three employees posing as Chinese nationals, flagged by repeated Astrill VPN and residential proxy connections and near-identical passport documents.
In August 2026 a financial services firm found a PiKVM, a small device that lets somebody control a computer remotely at the hardware level, attached to an employee's machine, followed by a USB capture card used to stream video into Zoom calls. That is a purpose-built rig for having one person attend meetings while another does the work.
A third case involved a sales and marketing hire, onboarded thirteen days earlier, who had swapped his own face into the identity documents of a real person whose arrest record happened to be posted online.
“DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them.”
Huntress threat research
how it was caught
By endpoint and network monitoring after the hire, in all three cases. The healthcare company noticed the same VPN and proxy addresses recurring. The finance firm noticed unexpected hardware. The sales case turned on a coincidence: the real identity's arrest record was public.
Every one of these detections happened after the person was employed and had access.
what it cost
Huntress does not publish per-company losses for these cases, but the pattern is consistent: the cost is the remediation, the access review, and the question of what left the building.
The strategic cost is broader. A healthcare company and a sales team do not think of themselves as targets, and so do not look.
the tells
signals that were visible, in hindsight, before anyone was hired.
- Repeated connections from the same VPN or residential proxy provider across different employees.
- Passport or ID documents that are near-identical in layout across separate applicants.
- Unexpected hardware between the keyboard and the machine, or a capture card feeding a video call.
- An identity whose real owner has a public record that does not match the person you interviewed.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
The healthcare company did eventually notice, months into employment. The same conclusion is available before an offer is made when the interview itself is the thing being examined.
A face swapped into ID documents survives a document review. It does not survive matching the live face against the identity throughout a session.
The rigs in these cases exist to put one person on the call and another on the keyboard. NeuralPrint reads whether a single, consistent human being is actually present for the whole interview.
sources
- [1]North Korean job fraud expands beyond tech into healthcare and sales
Huntress, via The Hacker News · security research · August 31, 2026
Three 2026 cases including a PiKVM plus USB capture card used to stream video into Zoom, and a hire who face-swapped himself into a real person's identity documents.
- [2]Imposter for hire: how fake people can gain very real access
Microsoft Threat Intelligence · security research · December 11, 2025
Four cases where KVM-over-IP hardware was attached to employer workstations. Cites Gartner's forecast that one in four candidate profiles will be fake by 2028.
- [3]i3 threat advisory: inside the DPRK
DTEX Systems · security research · May 14, 2025
Catalogues observed risk indicators: KVM-over-IP devices, anti-screen-lock utilities, OBS and ManyCam misuse to inject several workers into one video call, sessions running for days.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
north korean it scam · June 2025
29 laptop farms, 16 states, one week
In June 2025 the Justice Department searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and charged the American facilitators making the whole thing possible.