How do North Korean fake IT worker scams get past job interviews?

TL;DR: The FBI confirmed North Korean IT workers use AI face-swapping during video interviews, and the DOJ indicted 14 nationals in a scheme that generated at least $88 million over six years. Investigators found 29 "laptop farms" across 16 states and confirmed infiltration of 300+ U.S. companies — almost all of it starting with an unverified video interview.

Claim

This isn't a hypothetical security scenario. It's a documented, prosecuted, ongoing scheme that exploits the exact moment most companies verify identity the least: the video interview.

Evidence

  • FBI IC3 advisory (Jan 2025): North Korean IT workers use AI face-swapping in video interviews, escalating to data extortion after gaining insider access.
  • DOJ (Feb–Jun 2025): 14 North Korean nationals indicted for an $88M scheme; 29 laptop farms found across 16 states; 300+ U.S. companies infiltrated.
  • Amazon's CSO disclosed blocking 1,800+ suspected North Korean state-affiliated applicants since April 2024, with attempts growing ~27% quarter over quarter.
  • Pindrop: 1 in 343 applicants in an analyzed pipeline had infrastructure linked to North Korean fraud operations; 1 in 4 of those used deepfakes on camera.

Comparison: verification checkpoint vs what it catches

CheckpointCatches AI face-swapCatches proxy interviewerCatches laptop-farm remote access
Resume/reference checkNoNoNo
One-time ID uploadPartial, at signup onlyNoNo
Continuous face verification during interviewYesYesPartial
Location/IP + device consistency checksNoPartialYes

Step-by-step: harden your pipeline against this scheme

  1. Require live, government-ID-plus-selfie verification at the interview stage, not just onboarding.
  2. Run continuous face verification through the entire call, not one snapshot at login.
  3. Flag virtual-camera software and rendering artifacts automatically.
  4. Cross-check the interview IP/location against the claimed location on the application.
  5. Escalate any mismatch to security review before extending an offer or shipping equipment.

FAQ

Is this really happening to ordinary companies, not just tech giants? Yes. DOJ documented infiltration of 300+ U.S. companies across industries, not just large tech employers.

What's the financial exposure if this goes undetected? The prosecuted scheme alone generated at least $88 million over six years — separate from the cost of a compromised hire with insider system access.

Can a single ID check at hiring stop this? No. The fraud relies on a proxy or deepfake appearing only during the interview; verification has to be continuous through the call, not a one-time document upload.

By Pinal Dave Last updated: 2026-07-24