8 min read

Remote IT Worker Fraud: How Fake Employees Are Infiltrating Distributed Teams

Abinayasree C

Updated on August 31, 2026

Remote IT Worker Fraud: How Fake Employees Are Infiltrating Distributed Teams

Abinayasree C

Updated on August 31, 2026

In this post

CREATE YOUR ACCOUNT

Accelerate the hiring of top talent

Make talent quality your leading analytic with skills-based hiring solution.

Get started

Remote IT worker fraud is a scheme in which someone other than the person a company believes it hired performs the job, typically using a stolen or fabricated identity, a facilitator based in the country where the job is located, and a “laptop farm” that makes the worker appear to be logging in from inside that country. The best documented version of this scheme is run by North Korea, whose operatives use it to earn hard currency for the state, including funds tied to weapons development, while evading US and international sanctions. It is not a hypothetical risk. In 2026 alone, the FBI has confirmed finding a North Korean IT worker inside a US federal agency contractor role, the Justice Department has continued prosecuting US based facilitators, and multiple law firms have issued client alerts warning that companies can face sanctions and export control exposure even when the hire was entirely unwitting.

This post breaks down how the scheme actually works, what current 2026 enforcement activity shows, the red flags visible at each stage of hiring, and the identity and IT controls that catch it before a fraudulent worker ever gets access to production systems.

How does remote IT worker fraud actually work?

Remote IT worker fraud works by combining a stolen or fabricated American identity with a US based facilitator who makes the arrangement look legitimate from the outside. According to Fortune’s April 2026 reporting, US facilitators create fictitious front companies and bank accounts, forge documents like Social Security cards and driver’s licenses, and in some cases even sit in for video interviews or on site visits to pass identity checks in person. Once a candidate is hired, the facilitator hosts the company issued laptop in their own home or a dedicated “laptop farm,” a location packed with company laptops that let an overseas operative log in remotely while the login traffic appears to originate from a normal US residential address. The actual work is then performed from North Korea, China, or a third country, often by more than one person rotating through a single identity.

The scheme has also picked up new tactics. Multiple 2026 reports, including a joint warning from eleven nations covered by Tech Times in August, describe North Korean operatives using real time deepfake and voice conversion technology during live video interviews, converting an operative’s accent and appearance into a convincing match for the stolen identity’s photo. Security researcher coverage from DeepStrike and DarkReading also documents a shift beyond simple wage theft: once inside, some operatives have extracted source code, harvested credentials, and in a smaller number of cases attempted extortion, including threatening to leak proprietary code.

How big is the problem in 2026?

The scale is large enough that it now touches Fortune 500 companies and at least one US federal agency. Fortune’s reporting puts the scheme’s total revenue at an estimated 250 to 600 million dollars a year across all known operations, spanning roughly 40 countries and more than 100 US companies. Department of Justice court filings in related cases have documented specific operations affecting at least 136 companies and funneling millions of dollars in salary payments to North Korean operatives, with individual operatives in some cases earning close to 300,000 dollars a year in salary from stacked remote jobs. US based facilitators convicted in these schemes have received sentences of up to nine years for running laptop farms that enabled placement at more than 100 companies using dozens of stolen American identities.

The problem is not confined to the private sector. In August 2026, FBI Deputy Assistant Director Todd Hemmen disclosed at a Digital Government Institute conference that the Bureau had identified a North Korean remote IT worker employed inside a US federal agency, most likely through a contractor arrangement that received less rigorous vetting than a security cleared role, as reported by Federal News Network and TechCrunch. The case underscores a point security researchers keep repeating: support and contractor roles, including remote IT positions, often get significantly lighter identity scrutiny than the roles organizations think of as sensitive, which is exactly the gap this scheme is built to exploit.

What are the red flags of remote IT worker fraud?

The clearest red flags of remote IT worker fraud show up in three distinct windows: the application, the interview, and the first weeks after hire, and employers who only check for it once tend to miss it.

During the application:

  • A resume or LinkedIn profile with AI generated formatting, inconsistent history, or an online presence that appears fabricated or minimal for someone with the claimed experience level
  • A phone number that is VoIP based with no location data attached
  • A portfolio site or professional domain that was registered very recently relative to the claimed years of experience
  • Multiple applicants for different roles sharing banking details, addresses, or references, a pattern that points to a single facilitator network

During the interview:

  • Reluctance or refusal to turn on video, show a work environment, or join an unscheduled call
  • Video or audio that shows latency, unnatural facial motion, blurred or virtual backgrounds, or lip sync mismatches, all signs cited by DarkReading and DeepStrike as consistent with real time deepfake or face swap tools
  • Inability to answer basic, specific questions about the address or location the candidate claims to live in
  • Identity documents that were recently issued, show inconsistent details across documents, or contain the same errors researchers have found repeated across unrelated applicants, such as identical mistakes on submitted utility bills

After hire, during onboarding:

  • A shipping address for company equipment that does not match the identity documents on file
  • Remote access or remote desktop software installed on the company laptop almost immediately after delivery
  • Login sessions that last 24 hours or longer, or logins from multiple countries within a short window
  • Resistance to any request for a second identity check, an unscheduled video call, or an in person meeting after the person is already on payroll

No single item on this list proves fraud by itself. What matters is a pattern, and what makes remote IT worker fraud hard to catch with a single background check is that the identity being checked can be real; it is simply not the identity of the person actually doing the work.

How can employers prevent remote IT worker fraud?

Employers prevent remote IT worker fraud most effectively by verifying identity continuously across the hiring lifecycle rather than once at the top of the funnel, since a one time check at application does nothing to confirm who is still behind the keyboard three months later. A background check alone will not catch this, because background checks confirm a person’s history; they do not confirm that the person sitting in the interview or logging in on day one is the same person the history belongs to. Effective prevention combines identity verification, ongoing monitoring, and IT controls.

At the point of hire:

  • Verify government issued identification against a live biometric capture, not a static uploaded photo, and confirm the document itself has not been altered
  • Verify employment history directly with the named institutions rather than relying only on contacts the candidate provides
  • Screen for duplicate applicants reusing addresses, bank details, or documents across different job postings
  • Treat contractor and staffing sourced roles with the same identity rigor as direct hires; several 2026 cases specifically exploited lighter vetting on contractor pipelines

On an ongoing basis after hire:

  • Reverify identity at high risk moments such as device replacement, role changes, or account recovery requests, since credentials and device access can transfer to a different operator after the initial check is complete
  • Audit payroll for phantom workers and monitor login geolocation for patterns inconsistent with the employee’s stated location
  • Watch for multiple accounts authenticating from the same IP address or device fingerprint, a signature of laptop farm activity
  • Restrict and monitor the installation of remote access tools and VPN software on company issued equipment

Tools built specifically for this problem help close the gap that manual review leaves open. Glider AI’s ID Verify authenticates government issued IDs from more than 150 countries and matches them against live biometric capture to confirm the applicant is a real, unique person before they ever reach an interview. Real Candidate 360 extends that same identity check across the full hiring journey, pairing document and biometric verification with continuity checks that confirm the same person shows up at every stage, from screening through day one. AI Proctoring adds real time monitoring during live interviews and assessments, flagging the visual impersonation, lip sync mismatches, and deepfake indicators that a manual reviewer is likely to miss on a routine call. Employers can also review Glider AI’s dedicated identity verification platform for a closer look at how document and biometric checks work together across a hiring pipeline.

What should a company do if it suspects it hired a fraudulent remote worker?

A company that suspects it has hired a fraudulent remote worker should involve legal counsel before taking any action that could tip off the individual or destroy evidence, because both the forensic response and the notification obligations carry legal weight. Security researchers and legal advisories converge on a similar sequence. Engage outside counsel early so the investigation is protected by attorney client privilege. Preserve system access logs and audit everything the account touched rather than immediately revoking access, since an abrupt cutoff can trigger data destruction or make it harder to reconstruct what was accessed. Check payroll and access logs for other accounts sharing the same address, bank details, or device fingerprints, since these schemes place multiple fraudulent workers with the same employer or staffing vendor. Loop in HR and employment counsel before any termination decision. Finally, report the case to the nearest FBI field office and to IC3.gov, both of which the Bureau has specifically asked companies to use when this type of fraud is suspected.

Because employing a sanctioned individual can create liability even when the company had no intent to violate sanctions, several 2026 legal advisories, including Skadden’s June client alert, recommend building a documented, repeatable identity verification process now rather than relying on a case by case judgment call after a suspicious hire is already flagged.

FAQs

What is remote IT worker fraud?

Remote IT worker fraud is a scheme where someone other than the person a company believes it hired performs a remote job, using a stolen or fabricated identity along with a facilitator and often a laptop farm to make the login activity appear to come from inside the country where the job is based.


How do North Korean IT workers get hired at US companies?

They typically apply using stolen or fabricated American identities, pass interviews with the help of a US based facilitator or, increasingly, real time deepfake and voice altering technology, and then perform the actual work remotely from North Korea or a third country once hired.

What is a laptop farm?

A laptop farm is a location, often a facilitator’s home, where company issued laptops are physically kept and remotely accessed so that login activity appears to originate from a normal US residential address while the actual work is performed from overseas.

What are the warning signs of a fake remote IT employee?

Warning signs include refusing unscheduled video calls, video or audio inconsistencies suggestive of a deepfake, recently issued or inconsistent identity documents, a shipping address that does not match identity documents, and remote access software appearing on a company laptop shortly after delivery.

Is it illegal for a company to unknowingly hire a North Korean IT worker?

It can create sanctions and export control exposure even without intent, since US sanctions law does not always require proof that a company knew who it was paying. Legal advisories from firms including Skadden Arps recommend documented identity verification processes specifically to reduce this exposure.

How can employers verify a remote employee’s identity?

Employers verify identity most reliably by combining government issued document checks with live biometric matching at hire, then reverifying at high risk moments such as device changes or privilege escalation, rather than relying on a single check completed during the application stage.

What should a company do if it suspects it hired a fraudulent remote worker?

It should involve legal counsel immediately, preserve rather than abruptly cut off system access for forensic purposes, audit what the account accessed, check for related fraudulent accounts, and report the case to the FBI and IC3.gov.

AI Reference Checking: Automating Verification Without Losing the Human Signal

AI reference checking uses software, not a recruiter’s personal phone calls, to reach a candidate’s former managers or colleagues, collect their feedback through a structured digital survey or a conversational voice or chat interface, and analyze the responses for consistency and red flags. Done well, it does not just digitize the old “would rehire, yes […]

Why 38% of Candidates Are Walking Away From AI Interviews

Thirty eight percent of US job candidates say they have already withdrawn from a hiring process specifically because it involved an AI led interview, according to Greenhouse’s 2026 Candidate AI Interview Report, a survey of 2,950 active job seekers across the US, UK, Ireland, Germany, and Australia published in May 2026. Another 12% said they […]

Ghost Jobs in 2026: Why Companies Post Roles They Never Intend to Fill

A ghost job is a job posting for a role that the company is not actively trying to fill, whether because the position is already spoken for internally, the budget has quietly frozen, or the listing was never meant to close. In 2026, a Clarify Capital analysis of more than 175,000 US job listings found […]

chevron-down