The fake IT worker scheme out of North Korea is spreading to nearly every industry that hires remote talent, according to new threat intelligence reports, posing a real threat to a wide range of industries.
According to the latest research from Okta Threat Intelligence, DPRK nationals are not only targeting software development roles at tech firms, but jobs across industries, including finance, healthcare, public administration, and professional services.
While the most targeted positions remain in remote software development, Okta’s analysis of thousands of examples of DPRK IT worker activity found that Information and Technology organisations represent only half of the targeted entities.
Tracking over 130 false identities used by the North Koreans, Okta observed the threat actors apply to over 6,500 jobs across more than 5,000 distinct companies up until mid-2025, which the company said likely reflects only a small sample of total active DPRK activity.
As well as roles at software firms, these fake workers have been found targeting jobs at traditional banking institutions and insurance firms, fintech companies, medtech providers, and even AI-focused organisations.
That bolsters earlier findings from Google, which found in a separate report that DPRK IT workers were taking part in web, bot, and blockchain technology development projects, industries of some interest to the North Korean regime.
According to Okta, these positions are valued by DPRK nationals because they offer relatively high wages, as well as access to high-value codebases and infrastructure, and, most importantly, can be performed remotely.
Remote jobs of every kind are being hit, exposing the opportunistic nature of the threat, which Okta said shows that the attackers care little about the nature of any business itself, only that it pays a decent salary for positions that can be easily exploited.
This ‘scatter-gun’ approach indicates a far-reaching and evolving effort to infiltrate businesses of all types in developed countries.
Although the vast majority (73%) of jobs targeted by DPRK nationals were advertised by US-based firms, Okta found a significant expansion of operations into other countries.
The UK, Canada, and Germany each account for over 2% of total observations, somewhere between 150 to 250 roles, and were often attributed to the same DPRK actors typically moving on similar roles in the US.
Recommended reading
- North Korean Threat Actors Have Infiltrated UK Firms
- OpenAI Reveals Scale of Threat Actors Using AI to Influence Elections
- North Korea Stole $659M in Crypto Last Year, Says US
“Years of sustained activity against a broad range of US industries have allowed DPRK-aligned facilitators and workers to refine their infiltration methods,” warns the study.
“Consequently, they are entering new markets with a mature, well-adapted workforce capable of bypassing basic screening controls and exploiting hiring pipelines more effectively.”
Since these ‘new markets’ are unlikely to have invested the same time or resources into rooting out DPRK fake workers, Okta said it was important for all firms to become more aware of insider threats and introduce mitigation measures.
Those measures should include strengthening identity verification, such as requiring ID checks at multiple stages of recruitment, as well as a tightening of screening processes, more training for HR and recruiters, and closer monitoring of contractors and service providers.





