A recent investigation by Huntress revealed that five North Korea-linked IT workers were hired by Western companies in 2026 using fake identities and remote access techniques. These workers managed to infiltrate legitimate positions in various sectors, including IT and healthcare, without exploiting technical vulnerabilities. Instead, they completed the onboarding process, often performing their roles while funneling part of their earnings back to North Korea.
The investigation highlighted challenges in detecting these deceptive hires, noting that traditional security tools are insufficient against such fraudulent activities. Huntress urged companies to implement thorough background checks, scrutinize identity documents closely, and be on guard for specific indicators of potential DPRK worker activity.