
Make talent quality your leading analytic with skills-based hiring solution.

Nation state hiring fraud is when a government backed operative uses a stolen or fabricated identity to get hired into a normal remote job, most often in IT, so that their wages, and sometimes the access that comes with the role, can be funneled back to a sanctioned regime. The best documented version of this today is North Korea’s remote IT worker scheme, which the FBI and the Department of Justice say has placed operatives inside more than 100 US companies using stolen American identities. This is no longer a rare or theoretical risk. It is an active, growing part of the threat landscape that recruiters, not just security teams, now have to help defend against.
It is bigger, and more official, than most hiring teams realize. A few data points from 2025 and 2026 show the scale.
In June 2025, the Department of Justice announced coordinated nationwide action against the scheme, including new indictments, an arrest, the seizure of 29 financial accounts and 21 fraudulent websites, and raids on 21 so called laptop farms across 16 states that recovered roughly 200 computers. Prosecutors said the operation had placed workers inside over 100 US companies, compromised more than 80 real American identities, and generated at least 5 million dollars in fraudulent revenue in just one of the schemes charged.
The trend has accelerated since. CrowdStrike reported that the number of companies affected by North Korean IT worker infiltration grew 220 percent over a 12 month period, with operatives found inside more than 320 companies and the firm’s threat hunters now investigating roughly one new incident a day. The United Nations estimates the broader scheme has generated between 250 million and 600 million dollars a year for North Korea since 2018. A single Arizona based facilitator, Christina Chapman, ran a laptop farm that helped generate 17.1 million dollars across 309 separate jobs before her conviction.
Then in July 2026, eleven governments issued a joint alert stating plainly that North Korean IT workers are using false identities, third party proxies, location masking tools, and AI to get hired, and that hiring processes themselves need to be treated as a security perimeter. Weeks later, in August 2026, a senior FBI official confirmed that a North Korean national had worked as a remote IT contractor inside a US federal agency, one of the first publicly confirmed cases of the scheme reaching government systems rather than just the private sector. As US law enforcement pressure has increased, CrowdStrike has also observed the laptop farm model expanding into Western Europe, particularly Romania and Poland.
They get hired the same way anyone gets hired, which is exactly the problem. The operatives apply through normal job boards and staffing pipelines using a stolen or synthetic identity, often paired with a real Social Security number obtained through identity theft. A domestic facilitator, sometimes an unwitting participant and sometimes a paid accomplice, receives the company issued laptop at a residential address and keeps it running, effectively hosting the job on the operative’s behalf. This is what investigators call a laptop farm.
During interviews, operatives increasingly lean on generative AI to appear fluent in English, answer technical screening questions, and in some documented cases alter their appearance on camera in real time. Once hired, AI tools also help a single operative juggle several full time jobs at once by automating routine daily tasks, which is part of why the same identity sometimes shows up working for multiple employers simultaneously.
No single signal proves fraud on its own. Investigators and the joint FBI alert consistently describe this as a pattern of small inconsistencies rather than one obvious tell, so recruiters should watch for clusters of these signs together.
Because the interview alone is not a reliable checkpoint anymore, and treating it as the finish line is exactly the gap this scheme exploits. Research cited in the 2026 joint alert found that people can distinguish real video from AI generated video at only about 50 percent accuracy, which is essentially a coin flip. The alert also warns that in some cases a third party proxy, a real person standing in for the actual worker, has shown up to an in person interview, so even meeting “in person” is not an automatic guarantee.
The practical implication is that identity confidence needs to be built up across several independent checkpoints in the hiring process, not decided at any single one. If sourcing, screening, interviewing, and onboarding are handled by different tools and different people who never compare notes, a candidate only has to get past each checkpoint once, in isolation, to slip through.
A workable playbook maps a distinct check to each stage of the hiring funnel, so no single stage is asked to carry all the weight.
Application stage. Cross reference resume history for internal consistency (do the listed employment dates, technologies, and locations line up with a plausible timeline), and require a government ID check before scheduling a live interview. Tools built for this, like identity verification platforms, can validate a document against a live selfie or short video and flag duplicate applicants reusing a different identity elsewhere in the pipeline.
Screening stage. Replace or supplement scripted technical questions with a live, proctored coding exercise. A scripted interview answer can be fed by an off screen helper or an AI tool, but a live coding simulation done in real time under proctoring is much harder to outsource convincingly, since the assessor can watch the work happen rather than just review a finished answer. Remote proctoring, explained in more detail here, closes the gap that an unmonitored take home test leaves wide open.
Interview stage. Ask at least one spontaneous, unscripted question that requires reasoning in the moment rather than a memorized answer, and watch for the deepfake indicators covered above, including lip sync mismatches and unnatural lighting. Insist on at least one unscheduled video call later in the process, since a documented red flag is refusal to join calls that were not arranged in advance.
Offer and onboarding stage. Confirm that the shipping address for company equipment matches the address on file, verify the bank account name on payroll paperwork matches the verified identity, and record the device serial number so it can be checked later if suspicious activity appears.
Post hire monitoring. Watch for login locations that do not match the claimed home address, working hours that don’t fit the claimed time zone, and any sign that the same device or network is being used across what should be unrelated employee accounts.
Move carefully and quietly rather than immediately confronting the worker or cutting off access, since a sudden change can trigger data destruction, extortion attempts, or the operative simply disappearing before you have evidence. Loop in legal, security, and HR together, preserve access logs and equipment shipment records, and report the case to the FBI, either through a local field office or the IC3 portal, since these cases feed active federal investigations.
Companies are currently treated as victims in these schemes, but the DOJ and OFAC have both signaled that they expect employers to run reasonable verification programs, so documenting what checks were in place matters for your own compliance position.
Right now, nearly all documented and prosecuted cases involve North Korea, which uses the wages to help fund its weapons programs under international sanctions. The underlying playbook, stolen identity plus remote work plus a domestic laptop farm, is not unique to any one country, which is why security researchers increasingly use the broader term “nation state hiring fraud” rather than treating this as a single country’s problem.
It has grown quickly. CrowdStrike reported a 220 percent increase in affected companies over a recent 12 month period, with operatives found inside more than 320 organizations, and the firm now investigates roughly one related incident per day. In August 2026, the FBI confirmed the scheme had reached inside a US federal agency for the first time publicly.
Yes. Research referenced in the 2026 joint government alert found that people correctly identify AI generated video versus real video only about 50 percent of the time, no better than guessing. This is why interview performance alone should never be the only verification step in a hiring process.
A laptop farm is a residential location, often run by a paid or unwitting domestic facilitator, where a company issued laptop is received and kept running so that a remote worker overseas can appear to be logging in from a normal US address. DOJ raids in 2025 uncovered laptop farms across 16 states.
Remote IT and software development roles are the primary target, since they offer both a plausible reason for full remote work and, in some cases, access to source code, infrastructure credentials, or sensitive data that can later be used for extortion.
Companies are generally treated as victims when they are deceived, but sanctions and export control exposure can still apply depending on what the worker accessed, and regulators have signaled that they expect employers to maintain reasonable identity verification programs going forward. Legal counsel should be involved as soon as a case is suspected.
Skills based hiring that relies on live, proctored demonstrations of ability, rather than a resume and an unmonitored take home test, removes one of the easiest points for a proxy or AI tool to quietly do the work for someone else. It does not replace identity verification, but it closes a different gap in the same funnel.
Glider AI’s identity verification, live coding simulations, and remote proctoring are built to close exactly the gaps described above, biometric and document checks at the application stage, real time proctored assessments at the screening stage, and continuity checks that confirm the same verified person shows up at every step of the process, rather than relying on a single interview to catch a fraud pattern that is specifically designed to survive one.

Synthetic identity fraud in hiring happens when someone builds a job candidate instead of being one, blending a real Social Security number or stolen document with a fabricated name, a generative AI face, and a scripted background, so the “person” who interviews and gets hired never actually existed as a single, real individual. It is […]

A diploma mill is an unaccredited operation that sells degrees or certificates for a flat fee, little or no coursework, and almost no academic oversight, and the fastest way to catch one is to verify education claims directly with the issuing school rather than trusting the document a candidate submits. Fake degrees are no longer […]

A bad hire typically costs somewhere between 30 percent and over 200 percent of that employee’s first year salary, once you count recruiting, onboarding, lost productivity, and the cost of doing the search again. When the bad hire is the result of candidate fraud (a faked skill set, a proxy interview, a stolen identity, or […]