The Wire
Here is a question I never thought I'd be asking leaders: Are you sure the person you hired is actually the person doing the job?
I mean that literally.
The Justice Department has been prosecuting cases involving North Korean IT workers who used stolen American identities to get remote jobs inside U.S. companies. In one case announced this April, more than 100 companies hired workers using the stolen identities of at least 80 Americans. U.S.-based facilitators ran "laptop farms", company-issued computers physically located in the United States that workers overseas could access remotely, so the badge photo and the timezone both checked out even though the person never did.
These weren't harmless fake employees quietly collecting paychecks. Workers connected to that scheme gained access to sensitive company data and source code, including ITAR-controlled information at a California defense contractor developing AI-powered technologies. The Justice Department says the scheme generated more than $5 million for North Korea and cost victim companies at least $3 million in legal, remediation, and other damages.
Another case: an Arizona woman helped North Korean workers obtain jobs at 309 U.S. companies using 68 stolen identities. Federal agents found more than 90 company laptops in her home. The operation generated more than $17 million before she was caught.
Hiring has become part of your security perimeter. That's the piece I think leaders need to understand.
For years, we've treated recruiting, cybersecurity, IT, and physical security as separate functions. HR verifies the candidate. IT provisions the laptop. Security protects the network. That model assumes the person entering the organization is who they say they are.
We can't make that assumption anymore.
Remote work removed something we took for granted: physical presence. A convincing résumé, LinkedIn profile, background check, and video interview can build extraordinary trust very quickly. The FBI's own guidance to employers now includes checking whether a candidate will point their camera out a window, comparing photos across interactions, and independently calling the schools and employers on a résumé rather than trusting what's written there.
That matters everywhere, but it deserves particular attention from startups and defense-tech companies. Startups hire fast, and people wear multiple hats; a single engineer may have access to source code, customer data, and cloud infrastructure that would be split across several teams in a larger business. Defense companies may be dealing with genuinely sensitive technology. Put speed, remote hiring, and significant system access together, and the hiring decision is suddenly much bigger than HR.
The Save
I'd caution CEOs against just telling Talent Acquisition to "tighten up screening." Recruiting teams do need better tools and training, but this isn't only a recruiting problem. Your hiring team needs to understand the threat. Your IT and security teams need to understand the hiring process. And those groups need to decide together what identity verification looks like before access is granted.
Before an offer goes out, ask:
Are previous employers and education being verified independently, not just resume claims taken at face value?
Does the candidate's identity, location, contact information, and payment information actually make sense together?
Do you require at least one live, unscripted interaction? What happens when a candidate repeatedly avoids video?
Once someone's in the door:
Does IT know where company equipment is actually being shipped?
Are unusual access patterns after hire treated as a security issue, or just an IT ticket?
None of this requires turning every candidate into a criminal suspect. It requires recognizing that the threat has changed.
HR has always been in the trust business; we decide who enters the organization and what they get access to. For most of my career, the question was whether we'd selected the right person. Now there's another question in front of it: do we know who this person is? That sounds like a cybersecurity question. I think it's a leadership question, and if you employ remote technical talent, it deserves a conversation between your CEO, CHRO, CIO, and security leaders before the next suspicious résumé lands in someone's inbox.
One thing to try this week: Ask your recruiting lead one question: How would we actually catch this, today, in our current process? If the honest answer is "we wouldn't," that's the starting point.
Have you run into this, or built a verification step that's actually worked? Reply and tell me. I read every one.
Talk soon,
Anita
Sources: DOJ — Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote IT Worker Scheme (April 15, 2026) · DOJ — Arizona Woman Sentenced for $17M IT Worker Fraud Scheme (July 24, 2025) · FBI — North Korean IT Worker Threats to U.S. Businesses WSJ https://www.wsj.com/business/media/inside-north-koreas-operation-to-conquer-the-american-job-market-93729962
This is Issue 06 of LiveWire, a weekly jolt of candid thinking for CEOs, founders, and people leaders who know culture isn’t a side project; it’s how a business performs. If this landed, forward it to one leader hiring remote technical talent right now.
