Jessica Entwistle
September 1 2026
The Hacker News reports that North Korean threat actors are expanding their fraudulent IT worker schemes beyond traditional software development and IT roles, with recent investigations identifying suspected workers employed in sales, marketing and medical professions. The scheme, which has been widely documented over the past two years, involves North Korean operatives using false identities, stolen credentials and remote work arrangements to secure employment in Western companies, with the aim of earning revenue for the North Korean state and potentially gaining access to corporate networks and sensitive information. The expansion into non-technical roles suggests the scheme is becoming more sophisticated and harder to detect, as organisations may be less vigilant about vetting candidates for sales or healthcare positions than they are for software engineering roles with direct access to code repositories or production systems.
For UK organisations, this development highlights the importance of robust hiring and vetting processes across all roles, not just technical positions. Remote work has made it easier for fraudulent candidates to obscure their true location and identity, and the use of stolen or synthetic identities, remote desktop tools and intermediaries makes detection more difficult. The risk is not limited to espionage or network access; even non-technical roles can provide valuable intelligence about business operations, customer data, financial systems or strategic plans. Sales and marketing roles often have access to customer relationship management systems, pricing information, strategic plans and competitive intelligence. Healthcare roles may have access to patient data, clinical systems or pharmaceutical research. The expansion into these sectors suggests that North Korean operatives are targeting a broader range of information and revenue opportunities. Organisations should consider whether background checks, identity verification and right-to-work processes are consistently applied across all roles, whether remote workers are subject to the same vetting standards as on-site staff, and whether HR and security teams have clear processes for escalating concerns about unusual candidate behaviour or documentation.
UK organisations should review hiring and vetting processes to ensure background checks, identity verification and right-to-work processes are consistently applied across all roles, including remote positions. HR teams should be trained to recognise indicators of fraudulent applications, including inconsistencies in documentation, reluctance to appear on video calls, use of remote desktop tools during interviews, or unusual payment arrangements. Security teams should work with HR to ensure that remote workers are subject to appropriate access controls, monitoring and review, and that onboarding processes include verification of identity documents and right-to-work status. Organisations should also consider whether they have clear escalation routes for reporting concerns about employees who may be using false identities or operating from undisclosed locations. Insider risk is not limited to technical roles, and vetting standards should be consistent across the organisation.
Source: The Hacker News