Telling the Players Without a Scorecard:

North Korea’s Fraudulent Remote Worker Scheme.

  • The North Korean regime has been using the fraudulent remote worker scheme to fund its weapons program for years. Advancements and access to artificial intelligence (AI) models, like large language models (LLMs), are allowing it to expand and improve operations, making detection more challenging.
  • This represents a significant threat to the lucrative Canadian technology sector, which needs to take steps to defend itself against North Korean and other threat actors.

Background

North Korea routinely uses cyber operations to pursue and fund its national interests and is one of the main threats confronting Canada. In an evolving tactic, threat actors linked to North Korea are posing as non-North Koreans to exploit international remote work opportunities, creating fraudulent candidate profiles and applying to IT, software engineering, and other remote positions. Since 2018, the UN reports that the North Korean remote worker scheme has generated between $250 million and 600 million annually. 

Google’s Threat Intelligence Group has found that while the threat actors previously used the employment to raise funds for the North Korean government through the high paying tech salaries, they are increasingly applying more aggressive tactics and extorting employers. This scheme is a significant financial and operational security threat to companies that may unwittingly hire individuals linked to the North Korean regime.

The Operation

Hackers based in North Korea are using AI and other digital editing tools to create fake profiles on LinkedIn, either by impersonating actual tech workers or by creating entirely spurious identities.  

If selected for virtual interviews, threat actors are using AI tools, like deepfake technology, to alter their audio and visuals to impersonate the created identities. Threat actors are also leveraging LLMs for social engineering, and for assistance with English language, writing tasks, resumes, responding to application questions, and coding.

OpenAI (ChatGPT) recently released a report claiming it has deleted several accounts associated with “suspected deceptive employment campaigns.” OpenAI found that accounts were being used to generate content to support applications for IT, software, and other remote jobs internationally. Based on the observed patterns, OpenAI has linked the activity to North Korea’s IT worker scheme. This represents a shift from manual generation of false personas to the use of automation to generate false identities. 

Once hired, the threat actors are using stolen Social Insurance Numbers (SINs) and falsified or stolen credentials to pass through the on-boarding process. They then have their employers ship their work laptops to an address which operates as a “laptop farm,” where a local person is paid to keep dozens of laptops running. Adam Moyers, the senior vice president of counter-adversary operations at CrowdStrike, stated that some North Korean laptop farms operate over 90 computers. 


Threat intelligence indicates that fraudulent workers are sending their salaries back to North Korea, which uses the revenue to advance its interests and fund its weapons programs. More recently, threat actors have been acting more aggressively, using their insider positions to carry out cyberattacks and extortion schemes.

The Threat

The North Korean remote workers scheme affects both financial and operational security and the corporate bottom line. The cyber threat intelligence community is warning that the number of organizations being targeted by this scheme is much higher than initially believed. The Chief Technology Officer at Google’s Mandiant, Charles Carmakal, recently stated, “I’ve talked to a lot of CISOs at Fortune 500 companies, and nearly everyone that I’ve spoken to about the North Korean IT worker problem has admitted they’ve hired at least one North Korean IT worker, if not a dozen or a few dozen.” 


Executives at cybersecurity firm SentinelOne have spoken publicly about having fallen victim to the scheme, in an attempt to break the stigma and encourage other companies to come forward.   The more cases reported, the more effective tactics and behaviours can be tracked and addressed through robust security measures.

The Threat to Canadian Businesses

On July 16, 2025, the Royal Canadian Mounted Police, Public Safety Canada, Global Affairs Canada, the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), and the Canadian Centre for Cyber Security issued a joint alert warning Canadian businesses of the threat from the North Korean operation. Companies operating in Canada’s digital and technology sectors pose lucrative opportunities for North Korean threat actors. While the United States had been a primary target of the remote workers scheme, threat intelligence has indicated that operations have been growing and targeting sectors across North America and in Europe. 

Organizations in Canada should be aware of this threat, and ensure they are taking the necessary precautions to protect their organizations.

Mitigation Strategies

The sophistication of the scheme is making it increasingly difficult for employers to identify fraudulent applications. Google's Threat Intelligence Group recommends companies take the following steps to help protect themselves:

  • Develop robust internal insider risk management programs.
  • Monitor suspicious activities by ensuring security teams have proper visibility and logging capabilities. 
  • Ensure the hiring process prioritizes security. 
  • Take steps to ensure that remote work is secure. 
  • Take technical measures to ensure early indicators of compromise are captured.