You find a great developer. The video interview goes well. The CV looks solid. You make the offer, and the new hire starts on Monday.
Then you discover the person you hired does not exist.
It sounds far fetched, but security researchers say it is happening around the world. North Korea has been sending skilled IT workers into foreign companies under false names. Reports now say South African firms are on the target list too.
Let’s break down what is going on, why it matters and what you can do about it. The steps are simple, and most of them cost almost nothing.
What is the scheme?
At its core, the scheme is simple. Skilled workers from North Korea pretend to be someone else. They use fake names, borrowed identities and polished online profiles. They apply for remote jobs and get hired. Then they collect a salary and send most of it home.
Researchers say much of that money supports the country’s weapons and military programmes. So this is not a case of one person bending the truth on a CV. It is an organised operation with government backing.
It has been running for years. The big jump in remote work after 2020 made it much easier. When nobody meets in person, it is harder to know who is really on the other side of the screen.
How do they get hired?
They are clever, and they plan well.
First, they apply for roles like software developer or engineer. Companies that hire fully remote staff are the favourite targets. Some candidates have used deepfake filters on live video calls to look like another person.
Second, they get help. In the United States, helpers have run what investigators call laptop farms. The company ships a work laptop to a normal looking home. A local person unpacks it and installs remote access software. The real worker then logs in from another country, while the company thinks the employee is next door.
Some helpers even sit in front of the camera when the employer asks for a video check. A US official said the scheme would not work without these local facilitators.
The network is also spread out. One recent report said people linked to laptop farms were mostly in North Korea, China and Russia, with a small number in Africa and south east Asia.
Why this is not just about stolen salaries
At first glance, this looks like a pay scam. A foreign salary is a lot of money. Security firm CrowdStrike pointed out that these jobs pay far more than workers could earn at home.
But the danger goes further. A fake worker who is inside your systems can reach customer data, internal files and source code. Some have used that access to install malware or steal intellectual property.
Others turn to extortion. One security firm said it had seen more extortion attempts tied to these workers. The pattern is easy to follow. A company fires the fake employee. Then the demands start, with a threat to leak data unless money is paid.
The numbers show how big this is
These figures come from public reports. They are global, not South African, but they show how serious the problem is.
| What was reported | The detail |
|---|---|
| Countries affected | A UN sanctions monitoring panel said 40 countries have been hit. |
| Money earned in one US case | Prosecutors said at least $88 million came in over six years. |
| Workers in that case | Two companies allegedly had at least 130 workers. |
| Share of attacks on tech firms | One group was behind 47% of hands on keyboard intrusions in a year long report. |
When a single group is behind nearly half of a certain kind of attack, it is time to pay attention.
A fake job offer can also hurt the worker
The scam also works in reverse. Some groups pretend to be the employer. They post fake jobs for developers and IT professionals. Then they ask applicants to download special software for the interview.
That software is the trap. A group called WaterPlum used this method. Officials say it infected at least 30,000 devices and stole around US$10.71 million in cryptocurrency from 7,000 accounts. Cyber agencies in the US, Japan, Germany and Australia issued a joint warning about it.
So if you are a South African developer hunting for work, stay alert. A recruiter who wants you to install odd software before an interview is a red flag.
Why South African firms should pay attention
Local companies hire remote tech talent all the time. It cuts costs and opens up a bigger pool of people. That is a good thing.
But it also creates a gap. Security analysts say any business that relies heavily on remote IT staff, and does not screen people carefully, could be in scope. Smaller firms are often the most exposed because they have no dedicated security team.
There is a legal side too. If a fake worker gets into your systems and personal information leaks, POPIA applies. You are responsible for protecting the data you hold. A breach could mean fines, lost customers and a damaged name.
Warning signs that are easy to spot
Most red flags are easy to notice once you know them. None of them proves guilt on its own. A weak internet connection is not a crime. But several signs together should make you stop and look closer.
| Warning sign | Why it matters |
|---|---|
| A very long CV but a thin online profile | Real careers usually leave a bigger trail. |
| The candidate keeps dodging the camera | Fake workers often try not to be seen. |
| A last minute change of delivery address for the laptop | The device may be heading to a laptop farm. |
| Video that looks slightly off or glitchy | It could be a deepfake filter. |
| Pressure to rush or skip checks | Genuine candidates rarely mind a proper process. |
Simple steps to protect your business
You do not need a big budget. Good habits go a long way.
Check identity on live video. Ask candidates to show their ID on camera. Compare it with their face. A security reporter noted that staff verification is something many HR teams still need to improve.
Do your own homework. Call past employers using numbers you find yourself. Do not rely only on contacts the candidate gives you.
Watch where laptops go. Send equipment only to a verified address. Be careful if the address changes suddenly.
Give access in stages. A new hire does not need every system on day one. Start small and watch for strange activity.
Train your hiring team. Recruiters see candidates first. A short talk about these warning signs is an easy win.
Plan for the worst. Decide now who you will call and what you will do if you find a fake worker. It is much easier to act calmly when you already have a plan.
What job seekers can do
If you are on the other side of the table, a few simple rules will help.
- Research the company before you apply.
- Never install unknown software just to take an interview.
- Stick to well known video tools that you already trust.
- Be careful when a recruiter’s story keeps changing.
If something feels wrong, pause and check. It takes a few minutes. Losing money or data can take years to fix.
The bottom line
The fake IT worker scheme from North Korea is real, organised and still growing. It began as a way to earn foreign money. It has become a serious cyber security problem that touches cash, data and trust.
South African companies are now part of the story. That is no reason to panic. It is a reason to take remote hiring seriously.
A few easy checks, a careful hiring process and a simple plan for when things go wrong can make a real difference. If your business hires remote tech staff, review your process this week. A little care today costs far less than a data breach tomorrow.
