Threat actors linked to North Korea have expanded their job fraud schemes beyond the information technology (IT) sector, targeting roles in sales, marketing, and healthcare. This ongoing insider threat is part of a broader strategy where North Korea utilizes skilled IT workers to secure remote positions in Fortune 500 companies, generating income to support its illicit nuclear and missile programs. These operations often involve the use of stolen or forged identity documents, VPNs, and proxy services to conceal the workers’ true identities and locations. This campaign is tracked under various names, including PurpleDelta and Jasper Sleet.
According to reporting by The Hacker News, investigations have revealed multiple instances of North Korean workers impersonating individuals from other countries. For example, in February 2026, three employees at an Australian healthcare firm were flagged for using fraudulent identity documents and connecting through suspicious VPN services.
In another case, a financial services firm discovered the presence of PiKVM technology on a device used by a suspected North Korean worker, which is often associated with remote access schemes. This worker also accessed a file-sharing service to download a modified GitHub profile, likely to use as their own.
The threat actors are believed to maintain numerous fabricated identities, some generated using artificial intelligence, and have applied to over 1,100 companies across various sectors. They utilize sophisticated methods during job interviews, including screen recording software and AI transcription tools, to create the illusion of legitimacy.
As these schemes continue to evolve, cybersecurity experts emphasize the importance of rigorous background checks during the hiring process to mitigate the risk of employing fraudulent workers. The U.S. Federal Bureau of Investigation (FBI) is currently investigating how a North Korean IT worker managed to gain employment at a federal agency, highlighting the ongoing challenges posed by these deceptive practices.
Governments worldwide have issued joint alerts urging organizations to enhance their identity verification processes and remain vigilant against these sophisticated fraud schemes.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



