Somewhere in your hiring pipeline right now, there may be a candidate who checks every box. The resume is clean, the background check comes back clear, and the interview goes well enough to justify an offer.
The catch: the candidate is an adversary operating under a fabricated or stolen identity. And because the role is remote, you may have no idea they’re actually working from an entirely different country than the one they claim to be in.
This is infiltration, and it looks nothing like a conventional compromise. There's no malware to quarantine, session to revoke, or CVE to patch. The adversary applied for a job, made it through interviews and screening, and was onboarded into the HRIS system. They then received a laptop, credentials, and the privileges that come with employment—including access to internal systems and applications. By the time security has something to investigate, the attacker is already inside as an authorized user.
In this article, we'll examine how hiring fraud works, what happens when an operative gets hired, and how organizations can identify the threat before access is granted.
The Hiring Process Is Now an Attack Surface
Traditional insider threats generally involve legitimate employees, contractors, or other trusted users who either intentionally abuse their access or inadvertently create security exposure. Most insider risk controls inherit that model, focusing on suspicious behavior only after access has already been provisioned.
That assumption is exactly what this type of security-related hiring fraud exploits. The operative was never a legitimate insider. They were an adversary from day one, using a fabricated or stolen identity to secure employment under false pretenses. Once hired, however, the malicious insider blends in with trusted users, appearing to the systems around them like any other authorized employee and making them harder for security teams to spot.
This pushes the attack surface upstream into the hiring process: the resume, interview, background check, and onboarding workflow. Those stages span recruiting, HR, IT, and security, with each function responsible for a different part of the hiring lifecycle. Recruiting focuses on identifying and advancing candidates, while HR typically owns the compliance and administrative requirements surrounding employment. The IT and security teams, meanwhile, generally become involved only after someone is hired.
That division of responsibility creates an implicit chain of trust. Security relies on recruiting to adequately vet candidates and HR to complete the appropriate checks before onboarding begins. By the time a new hire comes onto the security team’s radar, there should be little reason to view them differently than any other employee.
But a background check can confirm only that an identity is real—not that it actually belongs to the applicant. A stolen but genuine identity can therefore clear screening while the operator behind it remains hidden. Further, in a remote hiring environment, where every stage may occur without anyone meeting the applicant in person, that lack of visibility can give a fraudulent candidate room to move through the process without attracting security scrutiny.
Infiltration Has Become an Industrialized Threat
This is no longer a niche security story. Last week, the Wall Street Journal shared its investigation illustrating the scale of North Korea's fake-employee operation across the job market. At a July 28 Digital Government Institute event in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, confirmed a DPRK operative had spent months working inside a U.S. federal agency. And last month, eleven governments jointly warned that stolen identities and real-time deepfakes are being used to defeat standard hiring checks.
Behind those headlines is an operation North Korea has industrialized, with thousands of operatives applying for remote engineering roles under stolen and AI-fabricated identities.
Our own threat intelligence team has a direct view into this activity. Over the past 18 months, we've flagged roughly 3,500 fraudulent applicants and conducted deeper intelligence gathering on about 1,000. That includes DPRK operatives as well as candidates tied to Nigerian, Pakistani, and other various threat actors, with direct collaboration observed between some of these groups.
DPRK-linked interview activity is showing up wherever remote hiring happens, across hundreds of organizations—from Fortune 500 enterprises to five-person startups. We've seen these operations target finance, healthcare, defense, crypto, manufacturing, retail, and education. And the activity rarely stops with a single application: the same personas can be used against dozens of companies at once.
What Happens When an Infiltrator Gets Hired
The consequences change dramatically once a fraudulent applicant becomes an employee. By then, the operative has company-issued credentials, equipment, permissions, and the institutional trust that comes with employment. However, the primary goal is not to exfiltrate as much data as possible or cause obvious disruption. It is to stay employed, blend in, and keep collecting a paycheck for as long as possible.
For DPRK operatives, those wages are ultimately a source of revenue for the state. They can be routed through cryptocurrency and mule accounts, contributing to an operation estimated to generate hundreds of millions of dollars a year and help fund sanctioned weapons and ballistic-missile programs.
That incentive creates a challenge for traditional insider risk programs, which generally look for suspicious behavior after someone is already inside. A fraudulent engineering hire may have the same permissions as any legitimate employee in that role, including access to repositories, production systems, customer records, and other sensitive resources. And because remaining employed depends on flying under the radar, the operative may give those controls little reason to flag them early.
Still, the goal can change quickly once the operative believes they have been discovered. With continued employment no longer viable, they may make a final attempt to collect source code, sensitive data, or other information they can use before their access is revoked. At that point, the threat has become an active insider incident.
That makes timing critical. The hiring process is the only opportunity to identify the operative before employment gives them trusted status inside the organization. Once accounts and permissions have been provisioned, the organization must find an adversary already embedded in the workforce.
How Infiltration Operations Work in Practice
The mechanics of infiltration vary, but recurring patterns appear across both our threat intelligence and publicly documented cases. Operators reuse persona components across applications, manipulate the interview process, and rely on domestic infrastructure to make overseas workers appear local. Individually, those signals can be easy to miss. Connected across candidates and organizations, they can reveal a coordinated operation.
One Operator, Many Personas—and Vice Versa
The relationship between operator and persona is not always one-to-one. We’ve seen the same individual interview under multiple identities, as well as multiple individuals use the same identity. Sometimes that reuse becomes obvious in real time.
In one case, a candidate interviewed for a role, was rejected, then reapplied under an entirely different identity and returned for another interview as though they had never spoken with our team before. In another, an applicant joined an interview call under one name, got disconnected, and rejoined under another. We’ve also seen completely different individuals appear in separate interviews using the exact same name and identity.
The underlying material is often reused as well. In one pattern we observed, two supposedly different senior engineer applicants submitted resumes with a shared verbatim career summary, cloned work history bullets, the same phone number, and the same claimed university, with only the dates changed. The resumes had been created in different tools weeks apart, but the repeated details connected them to the same operation.
Each application was plausible in isolation, making the broader pattern difficult for any one recruiter to see. It emerged only when the applications were compared with one another and with activity observed at other organizations. Traditional background screening evaluates a candidate individually; it does not reveal the same resume structure, contact information, or fabricated employer appearing across multiple applications and companies.
The Interview You Can't Trust
The interview is supposed to provide a layer of human verification that a resume or background check cannot. But these operations are built to manipulate that process, too. Most of these applicants rely on a rotating cast of AI-generated faces—some fabricated entirely, others cloned from real people. They also rely on a familiar set of tactics to reinforce the false identity.
Some candidates avoid live ID checks or use virtual backgrounds to keep interviewers from verifying their identity or surroundings. The same pattern extends to LinkedIn. Some applicants make excuses for why they cannot share a profile at all, while others provide profiles created only days earlier or appropriate an established profile belonging to a real person. Occasionally, the legitimate profile owner has already posted a warning or added a note to the profile itself stating that they are not looking for work and that someone is fraudulently using their identity.
The trap is that the most dangerous operatives are the most skilled. A well-prepared candidate can demonstrate technical competence and provide supporting documentation that appears genuine, all while operating under a stolen identity. Interview performance can demonstrate competence, but it doesn't prove the person being evaluated is who they claim to be.
And operators don't always need a synthetic face. In at least two cases we've observed during live interviews, the person using a DPRK-linked persona was likely a U.S. citizen—able to provide legitimate ID and native fluency, with nothing for a deepfake detector to flag. When someone else can convincingly complete the interview on an operative's behalf, the interview stops being an identity check altogether.
The Laptop Farm
The most industrialized version of this threat depends on a division of labor. An overseas operative sits for the interview behind a deepfaked face and a VPN and, once hired, performs the work. But before they can begin, they need a company-issued device. And because an employer isn’t going to ship a corporate laptop directly to North Korea, the operative also needs a domestic delivery point.
"Laptop farms" serve a role similar to mule accounts in business email compromise: they provide a U.S.-based intermediary that helps conceal the operative’s actual location. A domestic facilitator receives the company-issued laptop, keeps it online with remote access tooling, and enables the operative to control it from abroad. To the employer, the device and network activity appear to originate in the United States.
The 2025 federal prosecution of an Arizona laptop farm operator showed how far this model can scale. A single facilitator hosted more than 90 company-issued laptops tied to the stolen identities of 68 U.S. citizens, enabling North Korean operatives to work at more than 300 companies, including a major television network, an aerospace manufacturer, and a Silicon Valley technology firm. Over roughly three years, the scheme moved more than $17 million to the regime.
The model works because each element can appear legitimate on its own, even when the person performing the work is not the person the company intended to hire. The discrepancy emerges when the claimed identity is examined alongside the behavioral, device, and network signals surrounding the communications between the individual and the employer.
What Infiltration Prevention Detects
The examples above share a common characteristic: each leaves signals before the applicant becomes an employee. The challenge is connecting those signals early enough to expose the operation before damage is done. That is the gap Infiltration Prevention was built to close.
Infiltration Prevention applies behavioral AI to identity and behavior across application identities in the employer’s applicant tracking system (ATS). Critically, it moves the infiltration investigation away from HR workflow and into security workflows. Infiltration Prevention draws on Abnormal's threat intelligence, built from patterns of malicious behavior observed across Abnormal’s customer base, to link the same actors and facilitator networks.
It integrates directly with your ATS—specifically Greenhouse and Workday—through a read-only connection and, outside the ATS, considers every application’s security signals as soon as it enters the pipeline.
The table below shows how common infiltration patterns translate into specific signals and the evidence Infiltration Prevention surfaces for review.
Infiltration Pattern | Trigger Signal | What Abnormal Surfaces |
Reused persona across applications | The same phone, email, resume skeleton, or employer reused across candidates | A cross-candidate correlation cluster—one campaign, not isolated applications |
Fabricated employment history | Name mismatch, recently-registered domain | A sourced evidence brief citing each discrepancy |
Geo/network laundering | VPN egress, geolocation mismatch, threat-infrastructure IP | The identity-and- geolocation signal, with the infrastructure named |
Coordinated campaign | A previously-confirmed threat actor applying across multiple companies or departments at once | Abnormal Threat Intelligence-driven campaign view of coordinated threat actors that no single company could assemble on its own |
Infiltration Prevention does not score candidates or reject them. Rather, it produces a security alert with objective, sourced evidence that an application contains elements consistent with identified threat-actor patterns, then routes the alert to the security team—not HR—for human review. Security teams can see what happened, why it's suspicious, and the evidence behind it in one place.
Treat the Hiring Pipeline as a Security Boundary
Hiring fraud changes where the security problem begins. The critical window is before onboarding, while the operative is still an applicant and the organization can evaluate the identity behind the resume. Once employment begins, that person benefits from the same trust, tools, and permissions as any other employee, and may have every incentive to blend in for as long as possible.
Treating the hiring pipeline as a shared security boundary moves scrutiny to the point where it can have the greatest impact. Infiltration Prevention helps organizations surface threat actors and coordinated malicious identities before they become employees, giving recruiting and security teams the opportunity to act while the adversary is still outside the workforce.
See Infiltration Prevention in action. Schedule your demo.

