Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Nearly Half of Remote IT Job Applications Now Flagged With North Korean Fraud Patterns, Screening Firm Says

A San Francisco identity verification startup says North Korean fraud patterns are showing up in nearly half of the remote IT job applications it screens for U.S. companies.
Endorsed, founded by CEO David Head and CTO Kevin Fu, told Fortune it analyzed a sample of 175,000 job applications flagged with mid-to-high-risk patterns tied to North Korea's IT worker scheme across U.S. companies ranging from 3 to more than 25,000 employees. Among U.S.-based remote IT roles specifically, the share of applications carrying those patterns went from 11% in the third quarter of 2024 to 44% a year later. Endorsed estimates the rate hit 47% in the most recent quarter.
Endorsed sells fraud-detection software, and the 47% figure describes applications its own system flagged as risky, not applications confirmed to be North Korean operatives after investigation. Head himself said the risk comes from "a broader pattern of inconsistencies and behavior," not any single trait, and that the firm's flags are meant to prompt human review, not serve as a verdict. Treat it as a vendor's estimate of a growing problem, not a government-verified count.
The pattern Endorsed describes matches what independent security researchers are finding in confirmed cases. The scammers favor claiming Texas as their home state, according to Endorsed, accounting for 26.5% of flagged applications, followed by California at 14.4% and Florida at 7.2%. Dallas, Austin and Houston are the most common claimed hometowns. Favorite fake alma maters include the University of North Texas, UT Austin, the University of Central Missouri and UT Dallas. Claimed past employers skew toward Amazon, Google and Meta, with Capital One, CVS Health, Microsoft and Stripe also popular. Common first names include Sai, Michael, David and Kevin, and more than half of flagged applicants included a LinkedIn profile.
Confirmed cases show the tradecraft
Cybersecurity firm Huntress says it has confirmed five North Korea-linked hires in 2026 at companies outside the IT sector, according to reporting from The Hacker News, Security Affairs and Dark Reading. The activity is tracked under multiple names, including Famous Chollima, Jasper Sleet, Nickel Tapestry and Wagemole.
In one case, reported by Security Affairs, three employees at an Australian healthcare company were flagged after Huntress found their identity documents shared "an impossible number of coincidences": identical passport issue cities, issue dates one day apart, matching residential streets, and photo metadata showing the same iPhone model used eight minutes apart. Fake electricity bills submitted by two of the workers even contained the identical typo, rendering "hassle" as "hassic," which Huntress called a translation artifact from a shared document template.
A second case, at an unnamed financial services firm and reported by The Hacker News, found a worker's device connected to a PiKVM, a Raspberry Pi-based device that gives remote hardware-level control of a computer, followed by installation of a USB capture card that let the operative feed a manipulated video stream into Zoom calls as a fake webcam. Security Affairs reported the same device had earlier connected through a GL.iNet travel router and residential WiFi before the PiKVM was installed. Huntress researchers Jai Minton and James Maclachlan, whose findings were covered by Dark Reading, said the operatives "present a unique detection challenge" because they aren't breaking in through technical vulnerabilities. They're getting hired, and often doing the actual job.
The scheme has moved beyond wages
According to identity firm 1kosmos, North Korea places thousands of IT workers in remote jobs using stolen American identities, generating an estimated $250 million to $600 million a year for the regime's weapons programs, with U.S.-based facilitators hosting company laptops in "laptop farms" to make logins look domestic.
1kosmos also points to concrete enforcement and disclosure milestones this year. In April 2026, two New Jersey men received a combined 200 months in federal prison for running laptop farms that placed North Korean operatives at more than 100 U.S. companies, with one operative reaching export-controlled defense data. On July 28, the FBI disclosed it had found a North Korean IT worker doing paid work for a U.S. federal agency, which 1kosmos describes as the first publicly confirmed case inside government. Three days later, eleven governments issued a joint alert warning employers that these operatives now work in teams and rotate who appears on camera during interviews.
The UN has said North Korean IT workers funnel their earnings toward Kim Jong Un's nuclear weapons and ballistic missile programs in violation of Security Council sanctions. No U.S. agency has published its own comprehensive count of how many federal contractors or agencies may currently employ undetected North Korean workers, leaving the scale of the government-side exposure, beyond the single case the FBI disclosed in July, an open question.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.