North Korean IT workers use deepfakes to get hired -…
Eleven allied nations have issued a warning regarding North Korean IT operatives using real-time deepfake technology to bypass identity checks during…
- Incident date
- Aug 2026
- Target
- United States technology companies
Eleven allied nations have issued a formal warning regarding a sophisticated campaign where North Korean IT operatives utilize real-time artificial intelligence to bypass identity verification during remote job interviews. This operation, which has funneled an estimated $800 million toward Pyongyang’s weapons programs in 2024, targets freelance and contract roles in software development, database management, and IT support at United States technology companies.
What happened
The operatives employ real-time video inference, where a deepfake model maps a stolen or synthetic face onto the operative's live video feed. This feed is routed through a virtual camera driver, allowing the software to treat the manipulated imagery as a standard webcam input. By utilizing these tools, operatives based in locations such as North Korea, China, Russia, and Southeast Asia can appear as if they are working from a home office in the United States.
Beyond video manipulation, the attackers leverage a suite of deceptive technologies to maintain their cover. This includes the use of voice changers, AI-generated headshots, forged identification documents, and large language models (LLMs) to craft professional communications. Cybersecurity firm CrowdStrike, which tracks the group as FAMOUS CHOLLIMA, reported that these actors were responsible for 47% of all state-sponsored hands-on-keyboard intrusions against U.S. technology firms in the twelve-month period ending March 2026.
In response to the threat, the FBI and 11 allied governments have advised organizations to move beyond standard video interviews. Recommended security measures now include requiring in-person identity verification, implementing liveness detection, and monitoring accounts for location discrepancies or credential-sharing. As of 2026, eight individuals have been sentenced to prison for their roles in these schemes, highlighting the increasing legal and national security implications for organizations that fail to verify the identities of their remote contractors.