LightHouse by Silent Harbor

DPRK remote-worker risk / Whitepaper

Deception at the point of hire.

Detecting North Korean and other remote-worker schemes before an applicant becomes an insider.

How technology companies can resolve the person behind a remote application, expose proxy infrastructure and identity reuse, bind onboarding to trusted access, and keep consequential decisions human.

00 / Executive brief

The applicant can pass every check and still be the wrong person.

A remote software engineer submits a polished resume, completes video interviews, passes a background screen, signs employment documents, receives a company laptop, and begins work. Each step appears legitimate. The failure becomes visible only when the evidence is considered as one system: the identity actually belongs to someone else, the person on camera is not the operator behind the keyboard, the equipment is delivered to a facilitator, and the access is exercised from infrastructure the employer never intended to trust.

This is the operating problem behind Democratic People's Republic of Korea (DPRK or North Korea) remote information technology worker schemes. U.S. government reporting describes skilled workers using false, stolen, borrowed, or rented identities; fabricated professional histories; proxy interviewers; artificial intelligence and face-swapping tools; U.S.-based facilitators; false companies; payment accounts; remote access software; and laptop farms to obtain employment and reach company networks.

The objective has often been to generate revenue for the North Korean regime in violation of sanctions and, in turn, to support its nuclear, ballistic-missile, and other weapons-of-mass-destruction programs, as well as leadership spending on luxury goods while much of the population lives in deprivation.

The organizational consequence of these remote-worker schemes can extend much further. The FBI has warned that some workers have exfiltrated proprietary information, copied source-code repositories, harvested credentials and session material, facilitated other cyber activity, and extorted employers after discovery. In April 2026, the Department of Justice reported that North Korean IT workers operating through one facilitation scheme gained access to sensitive employer data and source code, including controlled technical data from a defense contractor.

Technology companies and startups are particularly exposed. They hire globally, move quickly, rely on remote interviews, use contractors and staffing partners, ship equipment, and give small technical teams broad access to code, cloud systems, data, deployment pipelines, credentials, and customer environments. A single fraudulent hire can therefore cross several trust boundaries at once.

How organizations can disrupt and defeat remote-worker schemes

LightHouse is Silent Harbor's Identity Intelligence Engine. It helps authorized teams resolve the candidate across permitted customer, public, commercial, technical, corporate, and threat-intelligence sources; identify evidence that multiple personas or candidates share underlying infrastructure; compare claims with chronology and provenance; bind the verified person to onboarding, device, account, and access records; and preserve an explainable evidence record for designated human reviewers.

LightHouse does not identify a person as North Korean because of appearance, accent, foreign language, name, location, or nationality. It detects characteristics like supported inconsistencies, identity reuse, infrastructure convergence, continuity failures, and material change. DPRK affiliation is an attribution question that requires corroborated evidence and qualified human judgment.

The hiring decision is an access decision. The identity behind it must be genuine and hold.

Resolve the applicant

Test whether the claimed person, history, accounts, identifiers, and professional footprint cohere across time and sources.

Expose the infrastructure

Reveal reused contact points, addresses, devices, payment paths, domains, accounts, and facilitators across apparently separate candidates.

Bind identity to access

Connect the verified person to the interview, onboarding record, equipment destination, enterprise account, device, role, and protected assets.

Preserve human authority

Route evidence and uncertainty to designated reviewers without turning a risk signal into an unsupported indictment, presumption of guilt, or employment decision.

01 / What is being detected

The target is identity deception, not a demographic profile.

The strongest defense begins by separating three questions that are often collapsed.

The first is identity integrity: does the available evidence support the applicant's claimed identity, location, history, and eligibility?

The second is operator continuity: is the person being interviewed, onboarded, paid, equipped, and granted access the same person who will perform the work?

The third is threat attribution: does the supported evidence indicate participation in a DPRK-directed operation, another fraud network, an individual deception, or a benign explanation?

LightHouse can strengthen the first two questions and organize evidence for the third. It should not jump from an inconsistency to a national-security conclusion. A reused phone number, altered image, unusual work hour, shipping change, foreign connection, or virtual private network can have legitimate explanations. The value appears when independent observations resolve to the same person, infrastructure, facilitator, or pattern, and when contradictions remain visible.

Silent Harbor believes a hiring-risk program should distinguish identity assurance from general workforce surveillance. Legitimate and authorized HR missions normally concern the truth of identity claims, continuity of the operator, security of the access path, and material changes relevant to a defined role. They do not authorize an unrestricted inquiry into a candidate's private life.

  • Candidate identity: The person, name, documents, contact points, history, accounts, and representations presented during recruitment.
  • Operator identity: The person who actually attends interviews, completes onboarding, receives payment, controls the device, and performs the work.
  • Access path: The equipment, enterprise accounts, credentials, remote-management tools, networks, addresses, and intermediaries between the operator and company systems.
  • Protected assets: The source code, cloud environments, models, customer data, credentials, funds, infrastructure, technical information, and operations exposed by the role.
  • Evidence standard: The source, date, provenance, confidence, corroboration, contradiction, and alternative explanations required before escalation.
  • Human authority: The people authorized to pause onboarding, narrow access, investigate, contact the candidate, seek counsel, report, close, or take another consequential action.

Detect the deception in the evidence. Do not manufacture certainty from identity, name, origin, appearance, or other identifiers, attributes, or demographics.

02 / Where hiring controls fail

Conventional hiring controls can validate fragments of a constructed identity.

Most companies do not lack controls. They lack continuity between them. Recruiting evaluates the resume and interview. A screening provider checks the identity presented. Human resources owns onboarding. Information technology ships the device. Identity and access management creates accounts. Security begins monitoring after the employee enters the environment. Payroll validates a payment destination. Each function is responsible for different artifacts at different times and stages.

That separation is exploitable.

In a publicly disclosed 2024 incident, KnowBe4, a major cybersecurity company that helps organizations train their employees to spot and avoid online tricks, scams, and cyber threats, reported that a remote engineering candidate completed four video interviews, cleared reference and background checks, and matched the photograph presented during hiring. The identity was real but stolen, and the image had been altered. Suspicious activity began when the company workstation was received and activated. The incident demonstrates a central weakness: a process can successfully verify the identity of the victim whose information was used while failing to verify the operator receiving access.

A real identity can still be used by an impostor

Document and background checks may confirm that the named person exists and that the records associated with that identity are genuine. They may not prove that the person attending the interview, receiving the laptop, and using the company account is the legitimate owner of that identity.

The interview is treated as a moment

A proxy can attend an interview, an image can be altered, or one operator can appear during hiring while another performs the work.

Candidate artifacts remain unconnected

Resume text, portfolio sites, email addresses, phone numbers, code samples, payment accounts, and shipping addresses are checked separately rather than across the applicant population.

Contractors inherit trust indirectly

Staffing firms, employers of record, marketplaces, and subcontractors can place distance between the company granting access and the organization that verified the worker.

Equipment logistics escape security review

A changed delivery address or residential laptop farm can appear to be an administrative exception rather than a change to the access architecture.

Identity assurance ends before privilege begins

The applicant may receive code, cloud, production, model, financial, or customer access after the final identity check, with no continuous test that the operator still matches the hire.

The failure is not one missed red flag. It is the absence of a durable identity thread from application through access.

03 / How the scheme works

The operation converts a false persona into legitimate access.

Official reporting describes an adaptable ecosystem rather than one fixed playbook. Workers, identity brokers, facilitators, front companies, recruiters, and infrastructure providers may perform different parts. Some participants may understand the scheme; others may provide services without knowing the true operator. Not every operation uses every technique.

The sequence below is a composite model drawn from U.S. government enforcement and public threat reporting. It shows where evidence can be captured before the applicant becomes a trusted insider.

  1. Acquire the identity: Obtain a stolen, borrowed, rented, fabricated, or facilitator-provided identity with documents and personal data that can survive basic screening.
  2. Construct the professional surface: Create resumes, portfolio sites, developer profiles, social accounts, references, businesses, and employment histories that support the claimed persona.
  3. Enter the hiring pipeline: Apply directly or through staffing firms, freelance platforms, recruiters, contractors, or front companies for remote technical work.
  4. Pass human verification: Use proxy interviewers, altered images, face-swapping, voice manipulation, rehearsed answers, or a facilitator to satisfy remote interview and onboarding checks.
  5. Redirect the physical path: Send company equipment to a U.S.-based facilitator, alternate address, or laptop farm that preserves the appearance of domestic work.
  6. Establish remote control: Install or connect remote desktop software, keyboard-video-mouse equipment, virtual private networks, proxy services, or other access infrastructure.
  7. Accumulate legitimate trust: Perform assigned work, receive salary, enter meetings, gain team confidence, and obtain access to the repositories, cloud roles, systems, credentials, and data required by the job.
  8. Generate or exploit value: Remit earnings, work several jobs, preserve access, steal data or virtual assets, enable other activity, or use proprietary information for extortion.

The point of hire is the conversion point. Before it, the organization faces a deceptive applicant. After it, the organization has created an authorized insider, issued credentials, and supplied the infrastructure through which the operator can act.

The adversary does not have to break through the perimeter when the hiring process creates an account and ships to the endpoint.

04 / Resolving the applicant

LightHouse resolves the person behind the application.

Stronger document verification and better video interviewing are often viewed as the answer to remote-worker schemes. Both can help. Neither answers the whole identity question.

LightHouse treats the applicant as a time-aware identity graph. It resolves names, identifiers, accounts, entities, professional history, technical artifacts, devices, addresses, payment interfaces, infrastructure, relationships, and access records from the digital universe into one evidence environment. It retains which facts were claimed, which were independently observed, which were supplied by the customer, which were corroborated, which conflict, and which remain unresolved.

  • Names and documents
  • Contacts and accounts
  • Employment and education
  • Developer and portfolio history
  • Device, location, and shipping
  • Payment, entity, and access

Time is essential. A portfolio created shortly before an application is different from a developer history accumulated over years. An address changed before hiring is different from a shipping destination changed after the laptop is issued. A phone number reused across candidates is different from one consistently associated with the same person. A company incorporated recently may be legitimate, a disposable front, or unrelated. LightHouse preserves the chronology needed to tell those possibilities apart.

The graph also makes cross-candidate analysis possible. One application may appear ordinary in isolation. Ten applicants that reuse the same phone number, portfolio language, mailing address, payment destination, domain registration, facilitator, or infrastructure create a different evidentiary picture.

LightHouse does not replace every control in the hiring and security stack. Document authentication, employment eligibility, liveness checks, background screening, endpoint security, identity and access management, human resources systems, payroll, and shipping controls retain their own roles. LightHouse connects the outputs to the same resolved identity so a contradiction discovered in one stage can inform the others.

The candidate, the identity, the device, and the operator should resolve, historically and contemporaneously, to the same person.

05 / Signals of deception

Deception appears in relationships, reuse, and change.

Government advisories provide useful red flags, but a checklist alone can create false confidence. Sophisticated applicants can avoid obvious anomalies, while legitimate remote candidates can trigger several benign ones. LightHouse increases decision value by resolving signals together, comparing them with prior applicants and employees, and preserving the evidence behind each relationship.

These patterns are illustrative. Availability and handling depend on customer authority, source rights, integrations, geography, and policy. No single pattern proves DPRK affiliation or malicious intent.

Claims that do not cohere across sources

Names, spellings, locations, work hours, education, employment, dates, photos, contact details, and portfolio claims may conflict across the resume, screening record, professional sites, developer accounts, payment platforms, and customer records.

Identity components reused across applicants

Distinct candidates may share a phone number, Voice over Internet Protocol service, email address, resume passage, code sample, profile image, domain, wallet, bank details, mailing address, reference, or account-recovery path.

Professional history without durable chronology

A technically credible portfolio may rely on recently created developer accounts, copied software projects, fabricated testimonials, recycled work samples, or a code-contribution history that does not support the applicant's claimed experience.

For example, an applicant may claim a decade of software-development experience while the professional accounts and visible code history presented as evidence were created only months before the application. That inconsistency warrants further verification; it is not proof of deception by itself.

Interview and operator continuity failures

The person appearing during one interview may differ from later meetings or work sessions. Camera avoidance, altered backgrounds, concurrent call software, image manipulation, inconsistent voice or behavior, and unexplained handoffs can warrant additional verification when supported by other evidence.

Onboarding details that redirect trust

A request to ship equipment somewhere other than the verified address; a request to redirect payroll to a newly introduced bank account, payment platform, company, or intermediary; unusual urgency; or a mismatch between the claimed work location and the equipment destination should trigger additional verification.

Shared facilitation and laptop-farm infrastructure

Multiple workers may converge on the same residence, business, device host, remote-management pattern, internet-connected keyboard-video-mouse equipment, proxy service, financial account, or facilitator. All can raise serious questions about the actual identity of the applicant or employee.

Post-hire divergence

New remote-access software, changing geography, multiple countries accessing one account, personal cloud repositories, copied source code, harvested sessions, unexplained device behavior, or another person attending meetings can challenge the original identity and access assumptions.

The strongest signal is sometimes not an unusual artifact. It is an ordinary artifact that appears in too many identities, at the wrong time, or in conflict with the access path the company believes it created.

06 / From signal to finding

A supported finding should explain the deception without overstating attribution.

A binary result, such as passing or failing a personnel identity check, cannot carry all the uncertainty and nuance of this hiring and workforce mission. LightHouse can maintain separate but connected assessments for identity integrity, operator continuity, infrastructure exposure, and access consequence. Keeping those dimensions visible prevents a weak identity mismatch from being treated like a confirmed national-security risk or attribution, while also preventing a technically urgent access problem from waiting for perfect attribution.

A reviewer may know, for example, that the laptop is controlled through unauthorized remote-management infrastructure before knowing who ultimately operates it. The correct immediate action may be to protect the environment, preserve evidence, and pause access while the attribution question remains open.

  1. Claimed identity: What name, location, history, documents, accounts, references, and representations did the applicant provide?
  2. Resolved identity: Which people, entities, identifiers, accounts, devices, addresses, and records does the evidence support, reject, or leave unresolved?
  3. Operator continuity: Does the person interviewed remain consistent with the person onboarded, paid, equipped, observed in meetings, and operating the account?
  4. Evidence and provenance: Which customer, public, commercial, technical, corporate, or threat sources support each observation, and when were they collected?
  5. Reuse and infrastructure: Which elements overlap with other candidates, employees, facilitators, front businesses, devices, locations, or known patterns?
  6. Access consequence: Which code, cloud roles, systems, data, credentials, funds, customers, or operations can be reached through the candidate's or employee's role-based access?
  7. Confidence and alternatives: What supports the assessment, what contradicts it, what benign explanations remain, and what would change the conclusion?
  8. Required review: Which designated recipients should verify, protect, clarify, investigate, close, escalate, report, or take another authorized action?

Keep the output inspectable

  • Identity graph
  • Claim matrix
  • Shared infrastructure
  • Access map
  • Evidence chronology
  • Review record

Detect deception early. Attribute carefully. Protect access at the speed of the evidence.

07 / Recruiting and security

Identity assurance must cross the recruiting and security boundary.

Recruiters should not be asked to become counterintelligence analysts, and security teams should not enter only after the account is active. A defensible process assigns evidence capture, identity resolution, technical controls, and consequential decisions to the teams equipped to perform them.

The workflow should typically begin when a role creates material access risk. Remote software engineering, cloud administration, security operations, artificial intelligence and machine learning, DevOps, site reliability, cryptocurrency, finance, data, customer support, and outsourced technical roles may warrant additional identity assurance because of what the person can reach rather than because of where the person claims to live.

  1. Capture: Recruiting and HR preserve candidate claims, consent, interview continuity, screening outputs, references, addresses, and exceptions.
  2. Resolve: LightHouse connects the applicant's permitted identity evidence, chronology, reuse, contradictions, infrastructure, and unresolved questions.
  3. Protect: Security, IT, and Identity and Access Management (IAM) bind equipment, accounts, device posture, least privilege, source-code controls, and monitoring to the reviewed identity.
  4. Human review: Designated hiring, security, legal, HR, compliance, or executive owners decide whether to proceed, verify further, restrict, pause, close, or escalate.

Evidence to capture before access

  • Candidate-provided identity and authorization records
  • Interview images and continuity records where lawful and approved
  • Independently verified employment, education, and references
  • Professional, developer, portfolio, and corporate history
  • Phone, email, address, domain, and account relationships
  • Equipment destination and any requested change
  • Payment destination and any requested change
  • Staffing, contractor, employer-of-record, and subcontractor chain
  • Role, initial entitlements, protected assets, and privilege plan
  • Exceptions, reviewer, disposition, and supporting rationale

LightHouse will not automatically reject an applicant. It will make unsupported claims, shared infrastructure, continuity failures, and unresolved access paths visible early enough for qualified people to act before broad trust is granted.

08 / After the hire

The point of hire is the first trust boundary, not the last.

An applicant who clears enhanced review can still be impersonated, compromised, handed off, or connected to new infrastructure later. A legitimate employee can become the victim of credential theft or device compromise. A staffing relationship can change. Access can expand. A laptop can be moved. A payment account can be replaced. Continuous identity assurance should therefore follow the role for as long as the access creates material consequence.

LightHouse can establish the approved hiring record as a baseline, then monitor permitted customer and external sources for changes that challenge the original identity, operator, device, or access assumptions, including relevant changes that emerge later.

Reverify before privilege expands

An identity and operator check can precede production, administrative, financial, code-signing, customer, or other high-impact access rather than relying solely on the original hire date.

Watch the equipment and access path

Approved device, Endpoint Detection and Response (EDR), IAM, shipping, authentication, and network observations can show unauthorized remote-management tools, location changes, new infrastructure, session anomalies, or another operator controlling the account.

Resolve account and payment changes

A new email, phone, address, bank destination, payment platform, business entity, or employment intermediary can be tested against the trusted baseline and cross-candidate graph.

Connect external exposure to internal privilege

Evidence that an employee's accounts were previously compromised, including stolen credentials, browser cookies or session tokens that could allow another person to reuse an authenticated login, can matter immediately when the employee has sensitive access, even if the employee is the victim.

Preserve meeting and work continuity

Changes in who attends calls, communicates with managers, submits work, controls developer accounts, or interacts with company systems can create a reviewable operator-continuity question.

Close the loop on every alert

Validated outcomes should improve identity rules, infrastructure patterns, hiring questions, access policy, contractor requirements, recipient routing, and future evaluations.

Continuous assurance does not mean continuous suspicion. It means the company can detect when the facts supporting trust materially change and can respond before uncertainty becomes unchecked access.

09 / Controls and authority

A high-consequence hiring defense requires a visible boundary.

The hiring mission touches employment, privacy, sanctions, security, identity, and potentially law-enforcement concerns. The controls cannot be implied. They must be defined before collection begins and inspectable when a decision is challenged.

The governing rule is simple: investigate evidence of deception and access risk, not protected identity. Nationality, ethnicity, race, appearance, accent, disability, age, religion, lawful association, and other protected characteristics must not become proxy risk factors. Geographic and language evidence can be relevant only when it directly tests a material claim or technical access path under an approved purpose and applicable law.

An identity inconsistency may indicate applicant fraud, a stolen identity, an innocent data error, a recruiter mistake, a shared household, a legitimate privacy practice, a contractor arrangement, impersonation, compromise, or another explanation. The evidence record should support correction and closure as deliberately as escalation.

Required program controls

  • Written purpose tied to identity integrity, operator continuity, access security, sanctions compliance, or another authorized hiring risk
  • Role-based criteria that define which positions receive enhanced review
  • Approved sources, prohibited sources, consent, notice, and data-minimization requirements
  • Separation of claimed facts, observed facts, assessments, threat attribution, and decisions
  • Need-to-know access to candidate, workforce, security, and investigative information
  • Human review before adverse hiring, employment, referral, or legal action
  • Procedures for clarification, correction, dispute, appeal, retention, deletion, and legal hold
  • Testing for false matches, identity collisions, stale data, source duplication, and disproportionate effects
  • Escalation paths for security containment, counsel, sanctions review, insurer notice, and government reporting
  • Logged collection, resolution, scoring, routing, review, export, disposition, and policy changes

If supported evidence indicates a possible DPRK or other remote hiring scheme, the organization should preserve relevant records, protect systems, coordinate with counsel and authorized internal owners, and consider prompt reporting through the channels identified by the FBI. LightHouse can assemble the evidence environment. It does not determine criminal liability, sanctions exposure, immigration status, nationality, or guilt.

Better evidence should narrow the decision, not automate it.

10 / Measuring the change

Measure whether identity assurance changes the risk decision.

Counting screened candidates, collected records, or generated alerts does not establish value. A useful program should show that consequential roles receive stronger identity continuity, deception is surfaced earlier, access is protected faster, and legitimate candidates are not burdened by unexplained or inconsistent review.

Before a pilot begins, record the current process and known failure modes. Evaluate LightHouse against representative benign, deceptive, compromised, ambiguous, historical, contractor, and identity-collision cases. Include cases that should remain unresolved. A system that forces every observation into a conclusion is not ready for this mission.

Coverage

High-impact remote roles with a current identity, operator, device, and access baseline.

Attribution

Signals correctly linked, rejected, corrected, or left unresolved rather than forced.

Detection

Time from an available deception or infrastructure signal to supported review.

Protection

Time to pause, narrow, revoke, isolate, rotate, or otherwise protect consequential access.

Decision quality

Reviews with visible evidence, alternatives, human ownership, consistent disposition, and no protected-characteristic inference.

Useful secondary measures include cross-candidate reuse discovered, contractor coverage, equipment-address exceptions reviewed, access granted before identity review, false escalations avoided, reviewer agreement, disposition completeness, and the time required to clear a legitimate candidate after a false or ambiguous signal.

11 / Where to start

Start with the roles where a false identity creates immediate consequence.

A bounded deployment should focus on the hiring and access path rather than attempting to investigate every applicant. For a technology company, the first population may include new remote software engineers, contractors, cloud administrators, security engineers, artificial intelligence and machine-learning personnel, DevOps and site-reliability engineers, cryptocurrency developers, finance administrators, or others who can reach source code, production, credentials, customer data, funds, or controlled technology.

Customer-operated

01 / Platform

Customer recruiting, security, identity, insider-risk, fraud, legal, compliance, and investigative teams operate LightHouse within their own authorities, sources, policies, review requirements, and hiring workflows.

Forward-Deployed Intelligence Engineering

02 / Embedded

A Forward Deployed Engineer and Intelligence Mission Lead work beside talent, security, IT, IAM, legal, data, and business owners to connect the hiring stack, build identity and risk logic, test the workflow, and transfer tradecraft.

Silent Harbor Intelligence Practice

03 / Managed

Silent Harbor investigators operate LightHouse for customers that need candidate resolution, infrastructure analysis, enhanced review, monitoring, or investigative capacity without creating a permanent internal function.

Begin with one bounded hiring mission

  1. Define: Select the roles, protected assets, authorities, sources, integrations, reviewers, retention, escalation paths, and desired decision record.
  2. Map: Document the current journey from application through screening, interview, offer, equipment, payroll, account creation, privilege, and termination.
  3. Connect: Bring approved ATS, HRIS, screening, identity, corporate, developer, shipping, payroll, IAM, EDR, device, access, and threat-intelligence outputs around one identity anchor.
  4. Evaluate: Test known legitimate, deceptive, compromised, proxy, contractor, shared-infrastructure, stale-data, and identity-collision cases before consequential use.
  5. Operate: Apply the workflow to a bounded population with named recipients, least privilege, mandatory human review, and documented dispositions.
  6. Learn: Update identity rules, source quality, interview controls, infrastructure patterns, access policy, staffing requirements, and reviewer guidance from validated outcomes.

The first objective is to prove that the organization can detect when the applicant, identity, operator, device, and access path do not hold together, then protect the company without abandoning evidence or human judgment.

Know who is behind the access before the access becomes the incident.

12 / Questions to resolve

Questions technology leaders should resolve.

Is LightHouse designed to identify North Korean applicants?

No. LightHouse resolves identity claims, relationships, infrastructure, continuity, and material change. It can help surface evidence patterns associated with publicly reported DPRK remote-worker schemes, but it does not infer affiliation from nationality, ethnicity, appearance, accent, or location. DPRK attribution requires corroborated evidence and qualified human review.

How is this different from a background check?

A background check evaluates specified records about the identity presented at a point in time. LightHouse tests whether the applicant controls that identity, whether claims cohere across permitted sources, whether components are reused across other identities, whether onboarding and equipment remain bound to the same person, and whether those facts materially change after hiring.

Does LightHouse replace liveness, document verification, EDR, IAM, or an ATS?

No. Those controls retain their specialized functions. LightHouse can connect their approved outputs to a time-aware identity graph so evidence from recruiting, onboarding, device security, access management, and external intelligence informs one reviewable decision record.

What happens when LightHouse detects a serious inconsistency?

The alert reaches recipients designated by policy. Depending on evidence and access consequence, authorized reviewers may verify further, pause onboarding, limit or revoke access, preserve evidence, protect a device or credential, contact the candidate, seek counsel, close the matter, or escalate. Human review is required.

Should monitoring stop once the employee is hired?

Not when the role retains consequential access. The approved hiring identity can become the baseline for continuous monitoring of permitted changes involving the operator, device, accounts, infrastructure, payment path, external exposure, role, and privilege. Continuous assurance should remain bounded by purpose, authority, policy, and retention.

Selected references

Government guidance, enforcement, and observed tradecraft.

  1. 01

    U.S. Department of the Treasury, U.S. Department of State, and Federal Bureau of Investigation, Guidance on the Democratic People's Republic of Korea Information Technology Workers, May 16, 2022.

  2. 02

    Federal Bureau of Investigation, North Korean IT Workers Conducting Data Extortion, Alert I-012325-PSA, January 23, 2025.

  3. 03

    Federal Bureau of Investigation, North Korean IT Worker Threats to U.S. Businesses, Alert I-072325-4-PSA, July 23, 2025.

  4. 04

    U.S. Department of Justice, Nine Charged with Alleged Scheme to Generate Revenue for North Korean Government and Its Weapons of Mass Destruction Program, June 30, 2025.

  5. 05

    U.S. Department of Justice, Arizona Woman Sentenced for $17M Information Technology Worker Fraud Scheme that Generated Revenue for North Korea, July 24, 2025.

  6. 06

    U.S. Department of Justice, Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People's Republic of Korea, April 15, 2026.

  7. 07

    U.S. Department of Justice, Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People's Republic of Korea, May 6, 2026.

  8. 08

    KnowBe4, How a North Korean Fake IT Worker Tried to Infiltrate Us, July 23, 2024, updated October 19, 2024.

  9. 09

    Google Threat Intelligence Group, Staying a Step Ahead: Mitigating the DPRK IT Worker Threat, September 23, 2024.

  10. 10

    Google Threat Intelligence Group, DPRK IT Workers Expanding in Scope and Scale, April 1, 2025.

  11. 11

    Microsoft Threat Intelligence, Jasper Sleet: North Korean Remote IT Workers' Evolving Tactics to Infiltrate Organizations, June 30, 2025.

Scope note: This whitepaper describes a general security and identity-intelligence operating model, not legal, sanctions, employment, immigration, privacy, or investigative advice. Source availability, collection, monitoring, attribution, and response depend on the customer's authority, source rights, deployment, policies, and applicable obligations. An inconsistency is not proof of DPRK or other malicious affiliation, harmful intent, or employee misconduct. LightHouse supports identity resolution, evidence development, prioritization, and human review. It does not infer risk from nationality, ethnicity, appearance, foreign language, accent, or another protected characteristic, and it does not make consequential hiring, employment, legal, or law-enforcement decisions.

Request the PDF

The full document is available as a PDF for reference and circulation. The page above carries the complete text and stays open.

Silent Harbor stores these details as a record of who requested this document and may use them to follow up about it. The address is not verified and no account is created. Details are not sold and are not shared outside the service providers listed in theprivacy policy. A request to stop hearing from Silent Harbor is honoured.

Silent Harbor / LightHouse

Know who is behind the access.

We can help define the hiring population, identity evidence, approved integrations, access controls, review workflow, and evaluation standard for a bounded remote-workforce mission.