A man wearing a baseball cap undergoing facial recognition scanning with a digital mesh overlay, representing identity verification controls in remote hiring.
Back to all articles

The Interview Is No Longer Proof of Identity: How Do You Vet Remote Engineers in the Deepfake Era?

North Korean operatives are using AI and fabricated identities to bypass remote technical interviews. Learn how engineering leaders can verify identity and prevent hiring fraud

Cybersecurity

One cluster of a North Korean hiring fraud operation tracked by Recorded Future targeted more than 1,100 companies, using fabricated personas, AI-generated profile photos, and custom ChatGPT assistants. Researchers assess that the operation was highly likely to be employed at ten or more organizations. If your remote hiring process treats a good video interview as proof that a person is who they say they are, it is checking for the wrong thing.

In late July 2026, an FBI Deputy Assistant Director, Todd Hemmen, told a government conference in Washington: "Without getting into ongoing investigations, we identified just this past week a [Democratic People's Republic of Korea] remote IT worker that was working for the federal government." Federal News Network reported the remarks on August 10, and experts it spoke with understood him to mean a remote employee doing contract work for an agency.

If a North Korean operative can reach a federal agency through a contracting chain, the question for a private company is whether its hiring process would notice.

We should be upfront about where we sit. Golabs places remote engineers with US companies. This is our business, and a post about the risks of remote hiring from a remote staffing firm deserves a skeptical read. Our argument is not that remote hiring is dangerous. It is that identity verification has quietly become part of the engineering hiring process, and many companies have not staffed it that way.

What Is Actually Happening in Remote Technical Hiring?

North Korean state-backed operatives are applying for remote engineering jobs using fabricated identities, AI-generated photos, and real-time AI help in interviews. Once hired, they earn salaries for the regime and hold insider access to code, credentials, and data. In one tracked operation, IT and software services firms were the top target, followed by staffing and consulting firms.

The August 2026 research from Recorded Future's Insikt Group puts the numbers in perspective. Between late 2024 and early 2025, one cluster of the operation, called PurpleDelta, applied to jobs at over 1,100 companies. Operators applied to at least 60 positions per day across multiple job platforms, maintained at least 22 fabricated personas, and, in the researchers' assessment, were highly likely to have been actively employed at 10 or more organizations. Roughly 41% of the targeted companies were in IT and software services, 26% in staffing and consulting, and about 80% were based in North America.

That staffing figure matters. The research does not say why, but our read is straightforward: one successful placement through an intermediary can open doors at the intermediary's clients, the same pattern the FBI described at the federal level.

In February 2026, a Ukrainian national was sentenced to 60 months in prison for a scheme in which he managed as many as 871 proxy identities, used to get North Korean workers hired at 40 US companies. In May 2026, two US nationals were each sentenced to 18 months for running facilitation schemes that together affected nearly 70 US companies and generated more than $1.2 million for North Korea. In early September, a federal judge in Washington ordered cryptocurrency tied to North Korean IT worker payment addresses forfeited, in a partial win for a Justice Department bid to seize nearly $8 million.

On July 31, 2026, the United States and ten partner governments issued a joint alert on the threat. According to Yonhap's report on the alert, the alert warned that these workers "employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally."

How Do Fake Engineers Get Through a Video Interview?

With the same tools your own engineers use every day. Recorded Future documented operators using AI-generated profile photos sourced from a face-swapping service, custom ChatGPT assistants configured for each persona, and real-time AI transcription tools during interviews, sometimes repeating AI-generated responses verbatim. The researchers also found face-swapping tools used to obscure identities during video calls.

The interview loop most companies run was built to answer one question: can this person do the job? It was never designed to answer a second one: is this the person we think it is? A strong candidate with a clean résumé, fluent answers, and a working camera passes both checks in most interviewers' minds, even though only the first was actually tested.

It is also not only a North Korea problem. Gartner predicted in July 2025 that by 2028, one in four candidate profiles worldwide will be fake. In the same release, a Gartner survey of 3,000 job candidates in the second quarter of 2025 found that 6% admitted to interview fraud, either posing as someone else or having someone else pose as them. Much of that is likely ordinary misrepresentation rather than espionage, and many of the same controls help address it.

Why Should Engineering Leaders, Not Just HR, Own This?

Because the damage occurs within the engineering environment, the signals appear there first.

Huntress, a managed security firm, published an investigation in August 2026 describing five likely North Korean workers it identified inside partner organizations so far this year. One had been onboarded just 13 days before detection. For three of those workers, less than 50 percent of activity occurred during expected business hours, with a peak at exactly midnight UTC. Huntress recommends alerting when hardware remote-control devices such as PiKVM connect to a company laptop, and monitoring authentication through Astrill VPN and similar anonymizing services.

None of that is visible to a recruiter. All of it is visible to whoever owns endpoint and identity telemetry. Detection is a shared job between talent acquisition and security, and in our experience it is often unassigned. We made a related argument about non-human access in what securing the MCP layer buys you: identity is now the control plane, whether the identity belongs to an agent or to a contractor you have never met in person.

There is also a legal dimension engineering leaders tend to underestimate. As Holland & Knight noted in August 2026, OFAC sanctions violations are subject to strict liability, so engaging North Korean workers can result in penalties even if a company did not know. The same firm warns of the opposite error: investigations that disproportionately target employees based on protected characteristics can give rise to discrimination claims, even when the underlying concern about fraud is genuine.

How Do You Vet a Remote Engineer Without Treating Every Candidate Like a Suspect?

Apply the same controls to every comparable role, document them, and place them at the points where fraud is cheapest to catch. Holland & Knight's guidance to screen comparable roles consistently is the right frame: consistency protects you from both the operative and the lawsuit.

Verify identity against a document, live. Do a live, on-camera check against a government-issued photo ID at least once before an offer and again at onboarding. The FBI's January 2025 guidance tells employers to verify identity during interviews, onboarding, and throughout employment, not only at the start. Where feasible, add one in-person or independently proctored verification step for roles with production access.

Design at least one interview segment that AI assistance cannot carry. Live, unscripted problem-solving specific to your stack, where each follow-up builds on the previous answer. Watch for long pauses before fluent answers and for responses that sound read rather than reasoned. The FBI also suggests "soft" questions about a candidate's claimed location and education, which are easy for a real person and awkward for a persona.

Verify history at the source. Confirm prior employment and education directly with the institution rather than through contacts the candidate supplies. The FBI's July 2025 guidance, as summarized by Baker McKenzie in its coverage of the joint alert, recommends exactly this.

Cross-check your own systems. The FBI recommends checking HR systems for other applicants with the same résumé content or contact information, and reviewing whether phone numbers and email accounts recur across candidates. Operators running many personas reuse infrastructure.

Control where equipment and money go. Ship laptops only to the address on the verified ID. Compare payment accounts across employees and contractors, since several workers paid into one account is a strong signal.

Watch the first 30 days deliberately. Apply least privilege from day one. Monitor for unapproved remote desktop software, hardware KVM devices, VPN and proxy authentication, and activity patterns that do not align with the stated location. Huntress notes that timezone anomalies combined with VPN or proxy use are a stronger indicator than either alone.

Do not overcorrect. Holland & Knight cautions employers against demanding more documents than the I-9 process requires or imposing "U.S. citizen only" requirements without a legal basis. The goal is a consistent process, not a suspicious one.

What Should You Ask a Staffing Partner?

Here is the part that applies to us directly. The FBI's guidance tells employers to "verify third-party staffing firms conduct robust hiring practices and routinely audit those practices." We agree, and we think every company looking to buy remote engineering capacity should do so, including with us.

Ask how identity is verified, and when. Once at sourcing is not enough. You want to hear about live document checks, re-verification at onboarding, and what happens if the person on the first day does not match the person in the interview.

Ask who actually conducts the technical interview. A partner that forwards a résumé and lets you interview has outsourced the vetting to you. A partner that runs its own live technical assessment is doing half the work before you ever see a name.

Ask where the engineer's equipment goes and how pay is routed. A partner who cannot answer both questions precisely has not considered this threat.

Ask for the audit. Whether the firm reviews its own placements for these indicators, and how often.

A real advantage of working with an established partner, rather than hiring through open marketplaces, is that vetting can be done by people who do it every week, with accountability attached. That advantage only exists if the partner can show you the process. Our guide on how to choose an AI development partner covers the broader vetting questions, and our nearshore staffing solutions and AI dedicated teams pages describe how our engagements are structured.

Common Questions About Vetting Remote Engineers

How common is fake candidate fraud in tech hiring?

Common enough to plan for. Recorded Future tracked one North Korean operation cluster that applied to over 1,100 companies between late 2024 and early 2025, with roughly 41% of targets in IT and software services. Separately, Gartner predicted in 2025 that by 2028, one in four candidate profiles worldwide will be fake.

Can AI deepfakes pass a live video interview?

They can help. Researchers documented operators using face-swapping tools during video calls, AI-generated profile photos, custom ChatGPT assistants, and real-time transcription that fed answers during interviews. A single video interview should not be treated as identity verification. Pair it with a live government ID check and an unscripted technical segment.

What are the warning signs of a fraudulent remote engineer after hiring?

Activity concentrated outside expected business hours, hardware remote-control devices such as PiKVMs on company laptops, authentication via anonymizing VPNs, several workers paid into a single account, and requests to ship equipment to an address other than the verified one. Huntress found one likely North Korean worker just 13 days after onboarding.

Yes, if the screening is consistent. Apply the same verification steps to every comparable role and document the reasons for decisions. Holland & Knight warns that demanding documents beyond I-9 requirements or targeting people based on protected characteristics can give rise to discrimination claims, while OFAC sanctions violations are subject to strict liability.

If you are adding remote engineers in 2027 and want to see exactly how a partner verifies who shows up, talk to the Golabs team. Ask us how we handle each check in this post.

Tagged in

Cybersecurity

Save this article

Work with Golabs

Turn your next product idea into working software.

Partner with a senior LATAM engineering team focused on delivery, transparency, and long-term outcomes.

Loading related posts...