Key points
- Fresh reporting says third-country workers are being recruited to appear in remote interviews for jobs that North Korean operatives later perform.
- Some alleged interview associates were offered about $500 a month in cryptocurrency, according to NBC reporting cited by Quartz and Cointelegraph.
- A July 31 joint government alert separately warned that DPRK IT workers may seek crypto payment and can create data-theft and insider risks.
A wider network around fraudulent remote hiring
North Korean-linked remote IT operations are increasingly recruiting people in third countries to appear in job interviews for U.S. companies, according to fresh reporting based on cybersecurity investigations and government warnings. The interview stand-ins may help secure contracts before the technical work is taken over by North Korean operatives using false identities.
Quartz reported that workers in Iran, Lebanon, Syria, South Africa and Saudi Arabia had been approached as part of the broader scheme. Citing NBC News, it said some recruits found through LinkedIn were offered about $500 per month in cryptocurrency to work part time as interview associates. Cointelegraph independently highlighted the same recruitment tactic on September 12.
Related reporting: Revolut disclosed Bitcoin records after fake government request
Why cryptocurrency appears in the scheme
Cryptocurrency is not the only payment rail involved, and the available reporting does not identify a token, wallet or exchange used for the alleged $500 offers. Its relevance is more practical: digital assets can let participants receive cross-border compensation outside a normal employer payroll process. That does not make cryptocurrency itself the cause of the fraud.
A July 31 alert issued jointly by the United States and partner governments said North Korean IT workers may avoid direct deposit, request payment through money-transfer services or cryptocurrency, and route funds through third-party accounts. The alert also said workers may seek blockchain-development contracts and can pose insider risks involving data exfiltration, cryptocurrency theft and sensitive information.
Official guidance supports the broader warning
The government alert did not name the individuals described in the latest media reports, but it documented the underlying method. It said third-party proxies are increasingly used to create online accounts, participate in interviews and establish in-person contact. Other techniques include forged identification, virtual private networks, remote-desktop software and U.S.-based laptop farms that conceal the worker's true location.
The advisory links the activity to revenue generation for North Korea's nuclear and ballistic-missile programs. It also warns companies that paying a North Korean IT worker may breach sanctions or domestic law. These are government assessments, not court findings against every remote applicant associated with the indicators.
Security research shows the scale of the problem
Nisos, a U.S. cybersecurity company, said one cell it investigated submitted more than 170,000 applications across 22 operatives between December 2024 and September 2025, producing 76 job offers. Its research described stolen or purchased identities, coordinated references, AI-assisted interviews and American facilitators operating laptop farms. Those figures describe one investigated network rather than the entire global operation.
The latest reporting suggests a further adaptation: recruiters can use real people in additional countries to pass live interviews when employers become more alert to deepfakes or inconsistent video appearances. A successful identity check at the hiring stage therefore may not prove that the same person later accesses company systems or performs the work.
What U.S. companies should watch
The joint alert recommends stronger document review, in-person interviews where practical and systems that flag unusual account behavior. Warning signs can include mismatched payment names, repeated changes to account details, multiple logins from different locations, manipulated video feeds, unusually long working hours and requests for crypto payment. None is conclusive alone. For technology, blockchain and financial companies, the central risk is unauthorized access by a hidden operator after an apparently ordinary remote hire.
Sources
- Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers
- North Korea's remote job scheme now recruiting workers abroad
- North Korea using foreign IT workers to pass job interviews
- Inside a DPRK Employment Fraud Operation
AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.
