Fintechs deepfake video — Sep 2026
North Korean operatives are infiltrating fintech and crypto firms by using AI-generated identities and synthetic video conferencing to secure remote.
- Reported date
- Sep 29, 2026
- Target
- fintechs, crypto exchanges, and consumer banks
The exact incident date was not established. This entry is dated by its source report.
North Korean-linked actors are increasingly bypassing traditional cybersecurity defenses by infiltrating organizations through the front door of the hiring process. By posing as remote IT workers, these operatives secure legitimate employment at fintechs, crypto exchanges, and consumer banks to gain access to sensitive internal systems, cloud infrastructure, and financial assets. This trend represents a shift from external malware attacks to human-centric infiltration that exploits the trust inherent in remote work environments.
What happened
The campaign relies on a sophisticated blend of synthetic media and social engineering to deceive hiring managers. Operatives utilize AI-generated résumés, fake documents, and synthetic identities to create convincing professional personas. To bypass remote interview processes, these actors employ synthetic video conferencing environments, allowing them to appear as legitimate candidates during live calls. Once hired, these fake employees leverage their authorized access to steal intellectual property, harvest credentials, and compromise payment systems. In some instances, these actors have been known to extort companies by threatening to leak stolen data after their true identities are discovered. This strategy has proven highly effective for the regime, as it allows for the direct theft of digital assets and the generation of salaries that are funneled back to North Korea. The use of AI to scale these deceptive personas has made it increasingly difficult for organizations to distinguish between genuine remote talent and state-sponsored infiltrators.