Hiring

North Korean IT Workers: How to Screen Remote Engineers

Two 2026 government alerts spell out how North Korean IT workers get hired remotely. Here is what they say, what they don't say about Latin America, and a screening process built from their red flags.

RE

Roberto Espinoza

CEO, Ruzora

October 9, 20268 min read

North Korean IT workers are still getting hired by US companies in 2026, and the screening that stops them is boring: check the person, the address and the bank account at three different moments, and don't let any one of them change quietly. Two government alerts this year, on July 31 and September 18, describe the scheme in more detail than ever, and almost every red flag in them is something a hiring manager can see before the laptop ships.

Key Takeaways

  • An 11-country alert dated July 31, 2026 says many North Korean IT workers live in North Korea, China, Russia, Southeast Asia and Africa, and hide it with proxies, VPNs and US "laptop farms."
  • A September 18, 2026 alert adds interview tells: glances at another monitor, background voices, and repeated video or audio freezes.
  • Payment is the strongest tell: the July alert says these workers avoid direct deposit and route pay through a third party's account.
  • Paying them can expose the employer to sanctions risk, so screen before the first invoice.

What the 2026 alerts actually say

The July 31 alert is hosted on the FBI's IC3 site; NK News reported that 11 governments issued it.

It says many "reside in North Korea, China, and Russia, as well as Southeast Asian and African countries," and they "may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools." The facilitators who run laptop farms are named as being in places "such as in the United States."

The red flags it lists for hiring teams:

  • photo ID that doesn't match the person, or "video feeds that appear to be manipulated or artificially generated"
  • refusing video meetings
  • rates below market
  • signs that "multiple people" run the account, where the person you talk to "may change depending on the time of day"
  • requests for crypto payment, and avoiding direct deposit by giving you "a third party's bank account"

The September 18 alert, from Japan's National Police Agency and National Cybersecurity Office, the FBI, the US DoD Cyber Crime Center, Australia's ASD and Germany's BND and BfV, adds what an interviewer sees: "Frequent glances at another monitor, as if reading from the screen," "Occasional background voices," and "Repeated video or audio freezes." Its suggested checks are cheap: confirm the IP matches the claimed residence, call the phone number, probe the resume in depth, and ask about "hometown, weather, or hobbies."

Is Latin America part of the North Korean IT worker problem?

Not in the government documents. The July alert does not mention Latin America. The only reference I found is from DTEX, a private security firm, as paraphrased by NBC News in September 2026: "Nigeria, Pakistan, India and parts of Latin America are also being targeted to assist in the scheme for facilitator recruitment." That's about recruiting facilitators who lend identities or host laptops, not where the workers sit.

I place LATAM engineers with US startups, so weigh my take accordingly. The scheme borrows real identities, so a candidate in Bogota gets the same checks as one in Ohio. A location confirmed at three points is what counts.

Server racks in a data center, the kind of remote access a laptop farm imitates
Server racks in a data center, the kind of remote access a laptop farm imitates

A screening process built from the alerts

StageWhat to checkWhich alert flag it catches
ApplicationSame phone or email reused across resumes; rate far below marketJan 2025 FBI PSA; Jul 2026 alert
Live interviewCamera on, unscripted follow-ups, eyes reading another screen, background voices, freezesSep 2026 alert
IdentityName on ID matches the person on video and the payment accountJul 2026 alert
Before the laptop shipsShipping address matches the ID; no late address change2022 State/Treasury/FBI guidance; May 2024 PSA
First invoicePaid to an account in the worker's own name; no crypto, no third partyJul 2026 alert
First 60 daysRemote desktop tools on company devices; same person on every callMay 2024 PSA

The 2022 guidance says to be "particularly suspicious if a developer claims they cannot receive items at the address on their identification documentation." Most schemes surface at the laptop.

Why this belongs before the contract

First, the damage after hire. The FBI's January 2025 PSA says some workers, once discovered, held "stolen proprietary data and code hostage until the companies meet ransom demands," and copied GitHub repos to personal accounts.

Second, sanctions. The 2022 guidance warns of possible "sanctions designation" for anyone "processing related financial transactions," and says violations of the North Korea Sanctions Regulations can bring civil penalties "up to the greater of the applicable statutory maximum penalty or twice the value of the underlying transaction." The July alert adds that paying these workers "may also violate the domestic laws of many countries, including Japan, the United States, and the Republic of Korea." Enforcement is real, too: in May 2026 the DOJ announced its 7th and 8th laptop-farmer sentences in five months. This is general information, not legal advice; if you think you've paid one, call a sanctions lawyer and report it to the FBI at ic3.gov.

A Concrete Version

Say you're a 30-person Series A hiring a senior backend engineer, fully remote. A contractor applies at $45 an hour when every other senior applicant from the same city and market asks $70 to $90. Strong resume, polished answers. Here's the run, alert flags in brackets:

1. Day 1, interview. Camera on. You ask about a bug they fixed in their last job, then three follow-ups on why. Their eyes drift left every time [Sep 2026: glances at another monitor]. You note it.

2. Day 3, second interviewer. Ask about their city and the weather lately [Sep 2026].

3. Day 5, identity. The ID matches the resume and the person on today's call.

4. Day 8, offer. They ask to be paid through a friend's account "for tax reasons" and to ship the laptop to another city [Jul 2026 + 2022 guidance]. Two independent flags.

You stop. Total time lost: about four hours of interviews, against a contractor with commit access and a payment you may not be allowed to make.

The Honest Counterpoint

These checks create false positives. Honest engineers have bad internet, shared apartments and second monitors with their notes on them. Treat any single flag as proof and you'll reject good people, disproportionately from countries with worse infrastructure. Count flags, don't react to one.

The checks also don't prove much on their own. A facilitator with a real US identity, a real US bank account and a laptop farm passes the address and payment checks by design. That's why the FBI tells companies to verify identity "during hiring, onboarding, and throughout the employment of any remote worker," not once.

And on what Ruzora does: every engineer we place passes an AI-led technical interview and a graded coding assessment; how we vet lists the further steps. Sol, our hiring agent, shows you blind profiles first; names come after the MSA, which is the right moment to run the identity, address and payment checks above. We do not run ID-document or liveness checks today. Proof-of-human interviews are on our roadmap. You should still run your own identity checks on anyone, including people we send. Our post on candidate identity verification covers how, and how to identify fake candidates covers candidate fraud more broadly.

Frequently Asked Questions

How do I know if I hired a North Korean IT worker?

Check payment and access: pay routed through someone else's account, a shipping address changed after the offer, remote desktop software, or a different person on calls at different times. If several appear, involve counsel and the FBI before confronting the worker.

Are North Korean IT workers only a problem for big companies?

No. The DOJ's June 2025 action described jobs at more than 100 US companies, many Fortune 500. Small teams with no security staff are easier to fool.

Does hiring through a staffing provider remove the risk?

It moves some of the work, not the risk. The FBI's May 2024 PSA tells employers to make sure third-party staffing firms run sound hiring practices, routinely audit them, and flag changes in address or payment platforms. Ask any provider which identity checks it runs, and when, in writing.

The Bottom Line

North Korean IT workers depend on nobody checking the person, the address and the bank account against each other. Put a check at each seam the 2026 alerts describe, and keep checking after the start date. To start from engineers who already passed a coding assessment and an AI-led technical interview, browse the vetted bench and run your own checks on top.

Roberto Espinoza is CEO of Ruzora, which helps US startups hire pre-vetted senior LATAM engineers, with a vetted shortlist in 72 hours. See available engineers.

RE

Roberto Espinoza

CEO, Ruzora

Roberto is the founder and CEO of Ruzora. He works directly with US startup founders and CTOs on staff-augmentation and software-factory engagements, and personally reviews senior engineer placements.

AI-vetted engineers, ready now

Your next senior engineer is already vetted and waiting.

It starts with a single call. 72 hours later, you're reviewing scored candidates who already match your stack and culture.