Category
Identity & Access Management
Topic
North Korean IT Specialists & Insider Risks
Audience
Companies, HR & IT managers
Reading time
approx. 7 minutes

Anyone hiring freelancers or remote developers these days usually checks their portfolio, references and hourly rate. It is precisely this routine that North Korean IT specialists are exploiting. They apply for jobs under false identities on freelance platforms and within companies, initially delivering solid work and thereby channelling money into North Korea’s arms programmes over a period of months. The Federal Foreign Office, together with ten other countries, has published an official warning about precisely this scam. We explain how the scheme works, how to spot it and what steps you should now take in your settings and access procedures.

What the warning is about

Eleven countries are involved in the joint warning: Germany, Japan, the USA, South Korea, Australia, France, Italy, Canada, New Zealand, the Netherlands and the UK. The crux of the warning is that North Korea is the operator of an organised network of IT specialists who, using forged documents and fabricated identities, pose as legitimate remote workers. The revenue generated in this way is channelled into North Korea’s nuclear weapons and missile programmes.

The original text from the Federal Foreign Office is expressly addressed not only to public authorities, but also to businesses of all sizes, recruitment platforms and private individuals who commission freelancers. You can find the full warning here: Warning from the Federal Foreign Office regarding North Korean IT specialists.

It is important to understand the context: this is not a traditional hacker attack from outside, but rather a person with legitimate access who is deliberately infiltrated into the company. This shifts the problem from the Firewall to the recruitment and onboarding process.

How the scam works

The approach involves a division of labour and is designed to run over a prolonged period. In most cases, the following steps take place:

1

Creating a false identity

Profiles are created on freelance and job platforms using forged or stolen identity documents and fabricated CVs, often with multiple accounts using the same documents.

2

Using front men and intermediaries

Third parties step in for video interviews or face-to-face meetings, embodying the assumed identity. This makes the application appear credible, even though the actual work is being carried out elsewhere.

3

Accepting and delivering the work

The specialists work remotely, often for below-market rates and with unusually long working hours, in order to handle as many projects as possible simultaneously and build trust.

4

Concealing the source of the payment

Payment is preferably made in cryptocurrency or via payees who are not the same as the account holder, so that the flow of money to North Korea cannot be traced.

How to spot suspicious applicants and accounts

The warning notice lists a number of characteristics which may seem harmless individually but, when combined, are a clear warning sign. Pay particular attention to the following points during the application and contract process:

  • Unusual account behaviour: frequent changes to personal details and bank details, multiple accounts linked to the same ID document, logins from varying IP addresses, and unusually long login durations.
  • Discrepancies regarding payment: the account holder and the payee do not match; there is pressure to use cryptocurrency or payment via a third party.
  • Unusual behaviour during the interview: refusal to take part in video conferences, language patterns suggesting machine translation, and a willingness to work for significantly less than the market rate.
  • Document quality: forged or tampered-with identity and supporting documents.

A single characteristic does not in itself prove fraud; many freelancers work legitimately remotely and internationally. The overall picture is what matters. Anyone who consistently avoids video calls, redirects payments and whose details change repeatedly should be scrutinised more closely before being granted access to systems or data.

What risks does this pose to your business?

The problem does not end with the financing of a foreign armaments programme. As soon as such a person has access to your systems, a tangible security risk arises within your own organisation:

📤

data leakage

Source code, customer data and internal documents can be copied and extracted unnoticed, entirely legally via the access granted.

💰

Blackmail & theft

There are documented cases of cryptocurrency theft and blackmail, such as when an individual threatens to publish stolen data following their dismissal.

⚖️

Legal consequences

Under UN Resolution 2397 and national law, simply entering into a contract with and paying such personnel may already constitute a breach of sanctions regulations.

“The most dangerous access is the one you have granted yourself. Security today no longer begins at the Firewall, but with the question of who is really behind a job application.”
Mint Secure GmbH

What companies should do specifically now

The good news is that the same principles that underpin good cybersecurity can help combat this scam – provided they are consistently applied to recruitment and access management.

  • Verify identity reliably: make in-person or video-verified interviews mandatory and check the authenticity of the documents provided.
  • Secure payment channels: make payments only to verified account holders; do not allow spontaneous redirects to third-party accounts or crypto wallets.
  • Minimise access rights: following the principle of least privilege, grant only the rights that are strictly necessary and review them regularly.
  • Detect anomalies: Establish Monitoring for unusual logins, IP changes and data access so that irregularities become apparent at an early stage.

Tip: Treat every external access as potential insider access. Anyone permitted to access systems and data should undergo the same vetting and control procedures as a permanent employee, regardless of whether they are freelancers, service providers or remote workers.

How Mint Secure supports you

We help you set up recruitment, access management and Monitoring in such a way that compromised identities and insider risks are detected early on, without slowing down your operations.

🔑

IAM & Least Privilege

We review and design your access processes so that both external and internal users are granted only the rights they actually need.

🛡️

Security Assessment

Through a structured review, we identify gaps in onboarding, access granting and Monitoring, and prioritise the appropriate measures.

👥

Awareness & Processes

We train HR and IT teams together so that the warning signs highlighted in this article can be recognised in day-to-day operations and escalated correctly.

Ready to get started? We offer a free initial consultation to review your recruitment and access processes together. Get in touch.

Conclusion

The joint warning from eleven countries makes it clear: North Korean IT specialists are not an exotic niche issue, but a real risk for any company that recruits remotely. The attackers do not gain access through a security vulnerability, but through the front door, with a valid contract and legitimate access.

The most effective protection is a combination of reliable identity verification, minimal access rights and Monitoring that flags anomalies at an early stage. The implementation of these fundamentals properly undermines the scam’s foundation.

Mint Secure provides consulting and support every step of the way, from the initial assessment through to day-to-day operations. Talk to us.