In partnership with

Want a freelance gig?

The Vetted Workplace

Real hiring mistakes. Real red flags. Real fixes.

The FBI found a North Korean operative working remotely inside a U.S. federal agency. Their own investigator's reaction, on the record: he's still trying to understand how the hiring process let it through.

The Case

On July 28, 2026, at a security conference in Washington, D.C., an FBI deputy assistant director disclosed something companies have been quietly dealing with for years but rarely see confirmed at this level: a North Korean IT worker had been performing remote contract work inside a U.S. federal agency, undetected, until investigators caught it.

Days later, on July 31, 2026, agencies from 11 countries issued a joint advisory — the US, UK, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, and New Zealand — confirming this wasn't an isolated case. It's a large, organized, state-run operation. North Korea has been placing skilled IT workers into remote jobs at companies worldwide for years, using stolen or synthetic identities, funneling their salaries back to fund the regime — including, per U.S. investigators, its weapons programs.

The scale is not small. Cybersecurity firm CrowdStrike, which tracks the operation under the name FAMOUS CHOLLIMA, found it accounted for 47% of all state-sponsored intrusions into the tech sector between April 2025 and March 2026. The UN has separately estimated the scheme generates between $250 million and $600 million a year for North Korea. In one Justice Department case alone, two U.S. nationals were sentenced in May 2026 for helping run a "laptop farm" — hosting company laptops at their homes so North Korean operatives overseas could appear to be working from a U.S. address — in a scheme that had generated $5 million for the regime.

The Playbook

What makes this different from ordinary resume fraud is the sophistication and the infrastructure behind it, according to legal and threat-intelligence analysis of the scheme:

  • Stolen or synthetic identities, often built from real people's stolen personal information
  • Reused or overlapping resumes across multiple applications and operatives
  • VoIP phone numbers instead of traceable local lines
  • Fabricated portfolio websites to support fake work history
  • Real-time deepfake technology deployed during video interviews to visually impersonate the identity on the application
  • U.S.-based facilitators paid to host company laptops and create the appearance of a domestic worker
  • Mismatches between claimed residence, ID documents, and equipment-shipping addresses — one of the few threads that consistently unravels the whole setup

None of this is subtle once you know to look for it. Almost all of it is invisible if you don't.

The Fix

This scheme doesn't succeed because companies have bad instincts. It succeeds because most hiring processes were never built to check for state-sponsored identity fraud — they were built to check whether a normal candidate is telling the truth about a normal job history.

A few things actually move the needle here: verifying that a candidate's shipping address for company equipment matches their claimed location and ID; watching for inconsistencies in video interviews that suggest deepfake overlay rather than a live face; and treating identity verification as something that continues after hiring, not something that ends the moment someone accepts an offer. This is the same principle that shows up again and again in this newsletter — a background check isn't a single gate you pass through once. For remote roles with real system access, it's a posture, not a checkbox.

The riskiest hire isn't always the one who lies about their degree. Sometimes it's the one who was never the person in the interview at all. Identity is the first thing every background check should confirm — and increasingly, the hardest thing to fake convincingly is turning out to be easier than anyone assumed.

Has your team ever had to double-check whether a remote hire was really who they claimed to be? Reply and tell us.

The Vetted Workplace

The Vetted Workplace

Every Wednesday. One real case. One real fix.

Written by the team at Millow.io — see what a background check catches before you make your next hire.

The 10 Best AI Stocks to Own in 2026

AI is moving from experiment… to essential.

Every major industry is integrating it.
Every major company is investing in it.

By late 2025, AI was already an $800B market — growing at a pace that could push it well beyond $1 trillion in the years ahead.

Cloud infrastructure is scaling fast.
AI-enabled devices are multiplying.
Automation is becoming standard.

But here’s the real question…

When trillions flow into this transformation — which stocks stand to benefit most?

Our new report reveals 10 AI stocks positioned across the backbone of this shift — from the companies powering the infrastructure… to those embedding intelligence into everyday systems.

If you want exposure to one of the defining growth trends of this decade, start here.