The fake new hire problem: how criminals slip in through remote onboarding

Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
An HR onboarding workflow diagram displayed on a corporate system, showing gaps between background check completion, laptop shipment, and account activation sta
Share

Key points

  • Fraudsters are exploiting the gap between a company running background checks and a real person turning up on day one, according to guidance published by Specops Software.
  • The scam typically involves one candidate passing the interview and a different person receiving the laptop and gaining login and payroll access.
  • North Korean IT worker schemes flagged by the FBI and US Treasury in 2022 and 2023 use this exact pattern to place operatives inside Western firms.
  • Document verification paired with a liveness check, a short selfie video that confirms a real human is present, can close the gap.
  • Employers should tie identity checks to the moment credentials are issued, not just to the offer letter.

Hiring someone you never meet in person sounds ordinary now. It also sounds, to a certain kind of criminal, like an open door.

A new explainer from Specops Software, first flagged by BleepingComputer, walks through a problem that HR and security teams keep bouncing between each other: the fake remote worker. Somebody passes the interviews, clears the background check, signs the contract. Then a different person picks up the company laptop and logs in.

How does the scam actually work?

The impostor exploits handover gaps in remote hiring. A real candidate, or a stolen identity, is used to clear the paperwork stage. Once the job is secured, a different individual takes over and starts drawing a salary or siphoning data.

The applicant looks legitimate on paper. Interviews happen over video, sometimes with a stand-in on camera, sometimes with deepfake filters that swap a face in real time. The background check runs against genuine documents belonging to a real person, just not the one who'll end up doing the job. The laptop ships to an address not listed on the CV. From that point, whoever holds the laptop holds the access.

Who is doing this?

Two groups, mainly: ordinary fraudsters chasing a paycheque and whatever they can steal on the way out, and state-linked operators. The FBI, the US State Department and the US Treasury issued a joint advisory in May 2022 warning that North Korean IT workers were placing themselves inside US and European companies using stolen or borrowed identities, funnelling wages back to the regime. Follow-up advisories in 2023 and 2024 said the pattern was widening.

Our 11 August story, "Researchers Set Up a Fake Crypto Company and Hired Three Suspected North Korean IT Workers", recorded every keystroke on the laptops a fake employer issued and exposed the paper trail of precisely this scheme.

The money matters. So does what these workers can see once they're inside: source code, customer records, internal systems.

Where does the hiring process break?

The checks and the access aren't joined up. Here's where the seams show:

Stage Who is verified Who actually shows up
CV and interview The named candidate Possibly a stand-in on video
Background check The document holder Not necessarily the worker
Laptop delivery Nobody, usually Whoever is at the address
First login The account, not the human Anyone with the laptop

Each stage trusts the previous one. Nobody checks that the face on day one matches the face from the interview.

What actually stops it?

Two controls, used together. Document verification confirms a passport or driving licence is genuine and unaltered. A liveness check is a short selfie video proving a real person is in front of the camera rather than a photo or a deepfake. Bind that check to the moment the account is activated, not just to the offer letter. If the face at credential issue doesn't match the face from the interview, access doesn't turn on.

Specops argues, reasonably, that this is cheap compared with the cost of a state-backed operative sitting on your network for six months.

Should you worry if you're already hiring remotely?

Treat identity as a security control, not an HR formality. Re-verify at the point credentials are issued. Log the video interview and compare it against the person collecting the laptop. Watch for candidates who refuse to turn on their camera, who insist on shipping equipment to a different address, or whose bank details change late in the process. None of these signals is proof alone. Together, they're a pattern worth pausing on.

The uncomfortable truth: most companies that have been caught out by this didn't fail at vetting. They failed at joining their vetting records to their access controls. Those are two different systems owned by two different teams, and that gap is the product.

© 2026 Threat Vectr