North Korean Hiring Fraud Moves Into Healthcare, Sales Beyond IT Roles

Organizations worldwide are facing a growing threat from a scheme in which operatives linked to North Korea don real job roles—not just in IT but now in healthcare, sales, and marketing. The undercover campaign relies on forged documents, stolen identities, VPNs and proxy services to conceal origins. It also taps remote hardware tools and increasingly, AI, to help operatives win trust and access.

From Fortune 500 Tech Gigs to Everyday Healthcare Positions

The operation, tracked by researchers under names like Famous Chollima, PurpleDelta (formerly TAG-121), Jasper Sleet, and others, long targeted tech companies. But recent investigations show the fraud has widened. Remote workers pretending to be medical staff or sales professionals have emerged, sometimes completing legitimate work remotely for global firms—while funneling their salaries back to sanctioned entities in North Korea. In one case from February 2026, three staff members at an Australian healthcare firm posed as Chinese nationals, used falsified identity documents, and repeatedly routed internet traffic through VPNs and commercial proxy services. Suspicious details—passport similarities and odd wording in residence proof—finally raised alarms.

Tradecraft, Tools, and Government Targets

Investigators have documented more cases this year in which these masked employees joined organizations through standard hiring procedures. At a financial services firm, a worker was caught using a Raspberry Pi-based remote KVM tool to control a company laptop from afar. Meanwhile, AI-driven methods are entering the mix—things like doctored profile photos, real-time AI transcriptions in interviews, and even custom assistants during onboarding.

The reach has also extended into government: the FBI is probing at least one instance where a North Korean remote worker held a contract role with an unnamed U.S. federal agency. These operatives are opening payroll accounts through front companies—some already sanctioned—and using identity fraud to pass checks. Between December 2025 and February 2026 alone, nearly $2 million was paid via one such channel tied to the sanctioned Ryongbong General Corporation.

Past Cases, Legal Fallout, and Evolving Scale

Earlier prosecutions show how these networks operate. Two U.S. individuals were sentenced earlier this year for managing “laptop farms” that enabled North Korean operatives to work remotely for dozens of American firms. One facility involved over 100 U.S. companies, pocketing about $5 million in illicit revenue while causing more than $3 million in losses to victims.

Researchers uncovered another sting involving a fake cryptocurrency startup where three individuals believed to be part of the North Korean network passed interviews, shared credentials, and performed tasks—all under assumed identities. This operation exposed identity document forgeries, suspicious metadata in images, and unusual internet behavior. Key techniques included using well-known video tools for interviews, fake bank accounts, and fraudulent state IDs.

Cybersecurity firms such as Huntress warn that this pattern is likely to become more sophisticated. As this threat enters non-technical job categories, defenders must look for identity inconsistencies, odd onboarding documentation, and unverified remote access setups. The increased integration of AI into operations—from altering profile photos to assisting with interviews—lowers the barrier for deception.

What this means is simple: this isn’t just a narrow cybersecurity problem anymore. It’s a global hiring crisis. Companies in all sectors—not just IT—must strengthen identity verification, vetting, and due diligence. Remote hiring will remain essential, and the borderless economy is here to stay. But organizations that ignore these rising risks may find themselves compromised not by a breach, but by a bona fide employee.