Detect Deepfakesby Resemble AI
Deepfake case study · Multi-modal

Companies are unknowingly hiring North Korean operatives…

CISA warns of North Korean operatives infiltrating companies as remote IT workers by using AI-generated identity documents and deepfakes to gain system access

Incident date
Jul 2024
Target
unknown
Updated Aug 12, 2026 · 1 min read

On July 31, 2024, CISA issued a joint alert regarding North Korean IT workers who are infiltrating companies by securing legitimate remote positions using fabricated identities. These operatives gain access to internal systems, source code, and company resources through standard hiring processes, making their presence appear entirely normal.

What happened

Researchers documented three specific cases where operatives applied for remote IT roles using sophisticated deceptive tactics. The first applicant, claiming to be based in Texas, submitted a California driver's license that contained a Google Gemini SynthID watermark, revealing it had been processed with AI tools. The second applicant provided inconsistent documentation, including a Texas driver's license, a Social Security number, and a Kansas City bank account, showing a lack of geographic cohesion. The third operative submitted a stolen New York license alongside an iPhone 15 photograph that had its GPS metadata stripped before submission.

These operatives have been observed utilizing real-time deepfake technology during video calls to bypass standard identity verification. Because many hiring pipelines prioritize skill and culture fit over forensic document analysis, these individuals successfully obtain legitimate employee credentials. Once hired, the operatives gain authorized access to sensitive infrastructure, bypassing traditional external hacking attempts by becoming trusted insiders. To mitigate this threat, experts recommend checking image metadata for AI watermarks, cross-referencing geographic data across documents, performing unscheduled video identity verifications, and enforcing strict limitations on system access during initial probationary periods.

Sources