Criminal groups and state-backed operators are using stolen identities, remote-access tools and AI-assisted interviews to gain legitimate employment.

Criminal groups and state-backed operators are using stolen identities, remote-access tools and AI-assisted interviews to gain legitimate employment. The answer is stronger identity assurance, not suspicion of foreign workers.
An investigation highlighted by The Hacker News has offered a rare view inside a fraudulent remote-working operation.
Researchers deliberately hired suspected North Korean developers and placed them inside monitored virtual environments. Their activity exposed forged identities, AI-assisted working methods, remote-access software and infrastructure designed to disguise their true locations.
North Korean operations provide the most documented examples of this tactic, but the wider risk is not tied to a particular nationality. Stolen identities, proxy interviews and concealed subcontracting can be used by organised criminals, intelligence services or individual fraudsters operating from almost anywhere.
Nor does the threat come from foreign or remote workers as a category. Most are legitimate employees. The security issue begins when an organisation cannot establish who is actually carrying out the work, where its devices are located or whether the person using an account is the individual who was hired.
A legitimate account changes the attack
Traditional security controls are designed to stop an outsider from entering the network. Fraudulent workers take another route: they persuade the organisation to create the account for them.
Once hired, an operator may receive a managed laptop, corporate email address and authorised access to source code, cloud services and internal communications. Their activity can initially resemble normal work because the credentials and equipment are genuine.
A US Department of Justice case illustrates how far this deception can extend. Two US-based facilitators sentenced in April operated so-called laptop farms that allowed overseas workers to appear as though they were working domestically. The scheme used at least 80 stolen identities to obtain jobs at more than 100 companies, generating more than $5 million in revenue.
Company laptops were sent to addresses controlled by facilitators and then accessed remotely through hardware devices. Workers employed through the scheme gained access to source code and other sensitive information, including controlled technical data belonging to a defence contractor.
This makes fraudulent employment an insider-risk problem, even when the person was malicious before joining the organisation. The attacker does not need to steal an employee’s access after recruitment because the hiring process has already converted a false identity into a trusted corporate one.
AI is making inconsistencies harder to spot
Generative AI can help fraudulent applicants produce credible CVs, tailor applications and prepare convincing answers to technical questions. Face-swapping, voice modification and live translation tools can also make remote interviews less reliable as identity checks.
However, individual warning signs should be handled carefully. An applicant looking away from the camera, speaking with an unfamiliar accent or using translation software does not indicate malicious intent. Treating such characteristics as evidence would create discrimination without providing meaningful security.
The stronger signals are inconsistencies across several independent sources. Identity documents, employment history, location, contact details, payment information and device activity should describe the same person. Reused telephone numbers, duplicate CV content, unexplained address changes or repeated attempts to redirect company equipment deserve closer examination.
Checks should also continue after recruitment. Microsoft has reported anomalous sign-ins, anonymous proxy use and impossible-travel alerts involving fraudulent workers after onboarding. It recommends combining information from recruitment platforms, identity systems, email, collaboration services and cloud applications rather than treating hiring and security as separate processes.
Hiring has become part of the attack surface
Responsibility for remote-worker verification often sits between HR, security, legal, procurement and the hiring manager. Each team may perform part of the process without anyone examining the complete picture.
Recruitment agencies and outsourcing providers add another layer. An organisation may verify the supplier but have limited visibility into how individual contractors are interviewed, whether work is subcontracted or who ultimately has access to corporate systems.
The FBI recommends that organisations apply identity verification during interviews, onboarding and employment, while also checking whether staffing firms follow equivalent procedures. This does not mean repeatedly subjecting every remote employee to intrusive surveillance. Verification should be proportionate to the access involved.
A developer with access to production infrastructure, a finance worker able to change payment details or an administrator managing customer data warrants more scrutiny than a role with little access to sensitive systems. Privileges can also be introduced gradually, with unusual downloads, new remote-access software and unexpected changes to payroll or location investigated during the early stages of employment.
Organisations should prevent unapproved remote-management tools, monitor for connections that bypass endpoint controls and maintain clear records of where corporate equipment has been delivered. Access to code repositories, cloud administration and sensitive datasets should follow least-privilege principles regardless of how thoroughly an employee was vetted.
Verify behaviour, not background
Fraudulent remote workers expose a gap between recruitment and cyber-security. Hiring processes usually aim to establish whether someone is qualified and legally employable. Security teams need the additional assurance that the same verified individual remains behind the account and device after access is granted.
Closing that gap requires HR and security teams to share relevant signals, review high-risk appointments together and establish a clear response process when identities or locations do not align.
The objective is not to make international recruitment harder. Restricting opportunities based on nationality or geography would punish legitimate candidates while sophisticated operators continue to use stolen domestic identities and local facilitators.
The more useful principle is simpler: trust should follow verified identity, appropriate access and consistent behaviour. In remote work, none of those should be assumed from a successful interview alone.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543