Stopping IT Worker Scams Requires Revamped HR Process

As cybersecurity threats continue to evolve and adapt, one of the most insidious types of attacks is coming from an unexpected source: human resources. Specifically, North Korean operatives have been using fake IT worker job applications to infiltrate companies worldwide, embedding themselves in organizations to provide a stable source of income for the regime. The tactics used by these threat actors are clever and manipulative, relying on AI-powered automation to evade detection.

In June 2025, human-risk management firm Nisos discovered one such operation when a suspected North Korean operative applied for an IT position at the company. Rather than simply reporting the incident to law enforcement, Nisos decided to run its own sting operation, conducting an HR interview and “hiring” the worker before sending them a laptop with surveillance implants. The result was astonishing: the operative’s location was so easily identifiable that the company could see the names of other companies’ computers on screens across the closet where they worked.

This incident is just one example of the widespread problem of IT worker scams, which have been linked to at least 30,000 compromised devices and over 7,000 cryptocurrency wallet breaches in more than 100 countries. The goal of these attacks is not necessarily to steal data or funds directly, but rather to establish a stable source of income for the North Korean regime through long-term access to company resources.

So how can companies prevent such incidents? According to experts, it’s all about training human-resource managers to recognize the warning signs of suspicious applicants. These include unusual communication methods, such as the use of voice-over-IP (VoIP) calls or a lack of digital footprint. Nicholas Kowalczyk, vice president and chief risk officer at Kelly Services, emphasizes that there is no single silver bullet for detecting these threats, but rather a combination of measures that can be taken to make it more difficult for bad actors to infiltrate the company.

To stay ahead of these threats, companies must be proactive in implementing robust HR processes that prioritize security awareness and vigilance. This includes regular training for HR staff on how to identify suspicious applicants and escalating concerns through established channels. Additionally, automated analysis tools can help detect anomalies in applicant behavior and provide an additional layer of protection against these types of attacks.

The stakes are high, as the North Korean regime continues to use these tactics to generate significant revenue. While some companies may view these threats as low-risk, the reality is that even a single compromised device or breached wallet can have devastating consequences for both the company and its customers.

Ultimately, preventing IT worker scams requires a multi-faceted approach that combines human intuition with technological safeguards. By staying informed about these evolving threats and taking proactive steps to protect against them, companies can significantly reduce their risk of falling victim to these insidious attacks.


Source: Dark Reading — 2026-09-25