The fake new hire problem: how criminals slip in through remote onboarding

Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

ThreatVectr Newsdesk· 4 min read
AI agents in a digital network with security icons
Share

Key points

  • Fraudsters are exploiting the gap between a company running background checks and a real person turning up on day one, according to guidance published by Specops Software.
  • The scam typically involves one candidate passing the interview and a different person receiving the laptop, login and payroll access.
  • North Korean IT worker schemes flagged by the FBI and US Treasury in 2022 and 2023 use this exact pattern to place operatives inside Western firms.
  • Document verification paired with a liveness check, a quick selfie video that proves a real human is present, can shut the gap.
  • Affected employers should tie identity checks to the moment credentials are issued, not just to the offer letter.

Hiring someone you never meet in person sounds ordinary now. It also sounds, to a certain kind of criminal, like an open door.

A new explainer from Specops Software, first flagged by BleepingComputer, walks through a problem that HR teams and security teams keep bouncing between each other: the fake remote worker. Somebody passes the interviews, clears the background check, signs the contract. Then a different person picks up the company laptop and logs in.

How does the scam actually work?

The impostor exploits the handover gaps in remote hiring. A real candidate, or a stolen identity, is used to pass the paperwork stage. Once the job is secured, a different individual takes over the account and starts drawing a salary, siphoning data, or both.

It usually plays out like this. The applicant looks legitimate on paper. Interviews happen over video, sometimes with a stand-in on camera, sometimes with deepfake filters that swap a face in real time. The background check runs against genuine documents, because the documents really do belong to a real person, just not the one who will end up doing the job. The laptop ships to an address that is not the address on the CV. From that point, whoever holds the laptop holds the access.

Who is doing this?

Two groups, mainly. Ordinary fraudsters chasing a paycheque and whatever they can steal on the way out, and state-linked operators. The FBI, the US State Department and the US Treasury issued a joint advisory in May 2022 warning that North Korean IT workers were placing themselves inside US and European companies using stolen or borrowed identities, funnelling wages back to the regime. Follow-up advisories in 2023 and 2024 said the pattern was widening.

The money matters. So does what these workers can see once inside: source code, customer records, internal systems.

Where does the hiring process break?

The checks and the access are not joined up. Here is where the seams show:

Stage Who is verified Who actually shows up
CV and interview The named candidate Possibly a stand-in on video
Background check The document holder Not necessarily the worker
Laptop delivery Nobody, usually Whoever is at the address
First login The account, not the human Anyone with the laptop

Each stage trusts the previous one. Nobody checks that the face on day one matches the face from the interview.

What actually stops it?

Two controls, used together. Document verification, which confirms a passport or driving licence is genuine and unaltered, and a liveness check, a short selfie video that proves a real person is in front of the camera and not a photo, a mask, or a deepfake. Bind that check to the moment the account is activated, not just to the offer letter. If the face at credential issue does not match the face from the interview, access does not turn on.

Specops argues, reasonably, that this is cheap compared with the cost of a state-backed operative sitting on your network for six months.

What should employers do now?

Treat identity as a security control, not an HR formality. Re-verify at the point credentials are issued. Log the video interview and compare it against the person collecting the laptop. Watch for candidates who refuse to turn on their camera, who insist on shipping equipment to a different address, or whose bank details change late in the process. None of these are proof on their own. Together, they are a pattern worth pausing on.

© 2026 Threat Vectr