Site navigation

North Korea’s Fake Worker Scheme Spreading to New Industries

Tom Quinn

,

North Korean fake workers
A new report warns that North Korea’s fake IT worker scheme is shifting beyond tech, infiltrating industries from finance to healthcare through remote job applications.

The fake IT worker scheme out of North Korea is spreading to nearly every industry that hires remote talent, according to new threat intelligence reports, posing a real threat to a wide range of industries.

According to the latest research from Okta Threat Intelligence, DPRK nationals are not only targeting software development roles at tech firms, but jobs across industries, including finance, healthcare, public administration, and professional services.

While the most targeted positions remain in remote software development, Okta’s analysis of thousands of examples of DPRK IT worker activity found that Information and Technology organisations represent only half of the targeted entities.

Tracking over 130 false identities used by the North Koreans, Okta observed the threat actors apply to over 6,500 jobs across more than 5,000 distinct companies up until mid-2025, which the company said likely reflects only a small sample of total active DPRK activity.

As well as roles at software firms, these fake workers have been found targeting jobs at traditional banking institutions and insurance firms, fintech companies, medtech providers, and even AI-focused organisations.

That bolsters earlier findings from Google, which found in a separate report that DPRK IT workers were taking part in web, bot, and blockchain technology development projects, industries of some interest to the North Korean regime.

According to Okta, these positions are valued by DPRK nationals because they offer relatively high wages, as well as access to high-value codebases and infrastructure, and, most importantly, can be performed remotely. 

Remote jobs of every kind are being hit, exposing the opportunistic nature of the threat, which Okta said shows that the attackers care little about the nature of any business itself, only that it pays a decent salary for positions that can be easily exploited.

This ‘scatter-gun’ approach indicates a far-reaching and evolving effort to infiltrate businesses of all types in developed countries.

Although the vast majority (73%) of jobs targeted by DPRK nationals were advertised by US-based firms, Okta found a significant expansion of operations into other countries.

The UK, Canada, and Germany each account for over 2% of total observations, somewhere between 150 to 250 roles, and were often attributed to the same DPRK actors typically moving on similar roles in the US.


Recommended reading


“Years of sustained activity against a broad range of US industries have allowed DPRK-aligned facilitators and workers to refine their infiltration methods,” warns the study.

“Consequently, they are entering new markets with a mature, well-adapted workforce capable of bypassing basic screening controls and exploiting hiring pipelines more effectively.” 

Since these ‘new markets’ are unlikely to have invested the same time or resources into rooting out DPRK fake workers, Okta said it was important for all firms to become more aware of insider threats and introduce mitigation measures.

Those measures should include strengthening identity verification, such as requiring ID checks at multiple stages of recruitment, as well as a tightening of screening processes, more training for HR and recruiters, and closer monitoring of contractors and service providers. 

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data