North Korea's Fake Worker Scheme Now Reaches Into Hospitals and Sales Teams
The DPRK-linked hiring fraud that dogged tech firms is turning up in healthcare and sales roles, widening the insider risk for employers who thought they weren't a target.

Key points
- Investigators have linked suspected North Korean workers to jobs in sales, marketing and healthcare, not just software engineering.
- The scheme, known as the DPRK IT worker fraud, funnels wages back to the sanctioned regime in Pyongyang.
- Employers outside the tech sector are now in scope, including hospitals and clinics that handle sensitive patient data.
- The insider risk covers both stolen data and money leaving the company payroll for a sanctioned government.
- Hiring controls, not firewalls, are the main defence against this specific problem.
For a couple of years, the standard warning went like this: if you hire remote software engineers, some of the CVs in your inbox are fake, and the person on the other end of the video call may be a North Korean operative working from China or Russia. That was the pitch, and most companies outside tech shrugged and moved on.
That shrug is starting to look expensive.
According to reporting by The Hacker News, investigators have now traced suspected North Korean workers into sales and marketing roles, and into the medical profession. The IT worker scheme, as the US Treasury and FBI have called it for years, is no longer just an IT problem.
What is the "IT worker scheme"?
It is a long-running fraud in which people working for the North Korean government pose as freelance or remote employees, get hired by Western companies, and send their salaries back to Pyongyang. The regime uses that money, which is under heavy international sanctions, to fund weapons programmes.
In practice, the workers use stolen or invented identities, western-sounding names, and sometimes a paid accomplice inside the United States who runs a "laptop farm" so the machine appears to be sitting in Dallas or Denver rather than Pyongyang. The hiring manager sees a normal remote hire. Payroll sees a normal direct deposit. Nobody sees the money going to a sanctioned state.
Why are healthcare and sales roles now in the mix?
Because remote hiring exploded across every industry, not just software. A hospital group hiring a remote medical coder, or a SaaS vendor hiring a remote sales development rep, uses the same LinkedIn-plus-Zoom pipeline as a tech startup. The controls are usually weaker.
A sales role is attractive for a different reason than an engineering one. Salespeople get customer lists, pricing, pipeline data, and often CRM access to thousands of contacts. That is useful intelligence. A medical role can mean access to patient records, which are protected under HIPAA in the US and carry real regulatory weight if they leak.
The failure mode here is not a clever exploit. It is a hiring process that never seriously verified who was sitting behind the webcam.
Where the risk shows up
| Sector | What the fake worker gets access to | Main risk |
|---|---|---|
| Software / IT | Source code, cloud consoles, production data | Data theft, later extortion |
| Sales & marketing | CRM, customer lists, pricing | Competitive intel, phishing lures |
| Healthcare | Patient records, billing systems | HIPAA fines, identity fraud |
| Any sector | Payroll | Sanctions violations |
What should ordinary employees and customers watch for?
Honestly, not much on the customer side. This is a hiring and HR problem, not something a patient or a buyer can spot. If you are an employee, the useful signal is a new remote colleague whose camera is always off, whose voice does not match their accent, or who insists on shipping their work laptop to an address that is not theirs. Tell HR, not the internet.
One thing the post-mortem will say, every time: the red flags were in the interview, and nobody was looking.
Operational takeaway: if your company hires remotely and you are not in tech, you are now in scope, and your recruiters are your first line of defence.



