North Korean-linked fraud targets 1,100 remote jobs
Wed, 19th Aug 2026 (Today)
Recorded Future has identified a North Korean-linked employment fraud operation that applied for remote jobs at more than 1,100 companies. The activity involved at least 22 fabricated personas.
In a report, the researchers said operators in the cluster it tracks as PurpleDelta submitted as many as 60 job applications a day across at least eight recruitment platforms. The campaign targeted roles at software and technology groups, staffing and consulting firms, financial companies, and healthcare and biotechnology businesses.
The false candidates used AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents obtained from an illicit ID-generation service. The operation was designed to place fraudulent workers inside companies through standard hiring processes for remote roles.
The findings suggest PurpleDelta operatives were likely to have been actively employed at 10 or more organisations. Confirmed or probable placements included companies facing what Recorded Future described as an ongoing and material insider threat.
How It Worked
According to the report, the fraudulent workers adapted their methods as employers shifted more interviews online. During video interviews, operators copied transcribed questions into ChatGPT and then read back the generated replies, in some cases word for word.
Alexander Leslie, Senior Advisor at Recorded Future, said this reduced the usual signals available to hiring teams. "The scale of PurpleDelta's operation is easy to miss when a company sees only one application. During interviews, PurpleDelta operators copied transcribed questions into ChatGPT and read the answers back, sometimes word for word, and occasionally repeated incorrect answers. A candidate can sound prepared without fully understanding what they are saying, which makes ordinary interview cues less reliable."
Once hired, some of the workers recorded internal meetings and used screen-recording software during work sessions. Researchers also found pre-written excuses, drafted with Google Translate, to explain the use of personal devices and personal bank accounts.
In some cases, a company laptop was sent to the country where the false employee claimed to live, while the operative connected to that device remotely from another location. This helped the workers maintain the appearance of being based where they said they were.
In one case observed by researchers, a single operative managed at least four identities at the same time. That meant the same individual could hold one or more full-time roles under different names while continuing to submit new applications.
Security Risk
The report linked the employment fraud to broader security and sanctions concerns. A successful placement generated a regular income stream and also gave an impostor employee access to company systems and information.
Leslie said the financial and security implications went beyond recruitment fraud. "A successful job placement provides the PurpleDelta operation with a steady income and places a false employee within a company's normal systems. Wages are often funnelled toward sanctioned North Korean military and nuclear programs, and access may also expose information that was never meant to leave a company."
The findings add to growing concern among employers about identity fraud in remote hiring, particularly in technical roles where interviews, onboarding, and day-to-day work can all take place online. They also point to a more persistent challenge for compliance and security teams, because the same operator can replace an exposed persona and continue applying under a new identity.
Recorded Future urged companies to verify an employee's identity after hiring and confirm where both the worker and the hardware are actually located during onboarding. The report argued that checks at the point of employment are no longer sufficient on their own when false candidates can adapt quickly after detection.
Leslie echoed that point in the report's concluding remarks. "PurpleDelta operators have adjusted to the growing use of video interviews, and they can appear on camera while using artificial intelligence to answer questions in real time. Companies should verify an employee's identity after hiring, including during onboarding, so they can confirm where a worker and the hardware actually are. PurpleDelta can recover quickly when one identity is exposed and a persona can be replaced. The same application machinery can keep running under a new name, and organisations should expect these operatives to adjust their methods as hiring teams become more familiar with them. Continued verification gives companies a better chance of catching changes."