For two years, "fake employee" has meant one thing: North Korean IT workers using stolen and invented identities to land remote jobs and route salaries back to the regime. The tradecraft is real, and it worked well enough that hiring screening has oriented around exactly that.
So security teams built their defenses around attribution. Watch for the DPRK indicators: the VPN patterns, the laptop farms, the payment routing. Catch the North Korean, close the gap.
The Technique Left the Nation-State
Identity fabrication is no longer specialized tradecraft. A convincing résumé, a matching LinkedIn history, an AI-coached voice on the screening call, a synthetic face on the video interview. Every piece of that is now a commodity. Financially motivated fraud rings use it. So do actors with no nation-state behind them at all. When you tune your defenses to catch North Korea, you catch North Korea, and you wave everyone else through the door.
Stop Asking Who, Start Asking Whether
Attribution is the wrong first question. By the time you've confirmed who is behind a fabricated identity, they already have system access. The question that scales is whether an identity behaves like the real person it claims to be. PeopleBase maintains a behavioral profile for every identity in an organization: how a real person communicates, what they touch, when. A fabricated identity has no such history to imitate. It has to build one, and building one leaves a trail no résumé can fake.
The next fake employee probably won't be North Korean. The behavior is what gives them away either way.
See the latest from Abnormal's product and engineering teams.

