Australia joins US and UK in international warning about North Korean workers obtaining employment under false ID
Australian employers have been warned that North Korean IT workers are using false identities, forged documents, proxies and AI to secure remote jobs. The immediate lesson for employers is simple: a CV, video interview and conventional background check may no longer be enough to establish who is actually being hired.
A job application is becoming a route into corporate systems.
On 31 July, Australia joined the US, UK, Japan, Canada and other countries in issuing an international warning about North Korean IT workers obtaining employment under false identities.
The warning describes operatives impersonating people from other countries, forging identification documents, using third-party proxies and concealing their true locations through VPNs and remote access software. AI is making parts of the deception easier to produce and harder to detect.
For Australian employers, this is now a local problem.
On 9 August, The Australian reported that dozens of Australian companies may already have North Korean IT workers on their payroll. Technology, financial services, artificial intelligence and quantum computing were among the sectors identified as targets. The report also pointed to exposure through suppliers and outsourcing arrangements, where the person gaining access to company systems may never have been recruited directly by the company itself.
That should change the way employers think about background screening.
A convincing candidate may still be a false identity
The old assumption was that a fraudulent applicant would eventually give themselves away.
Perhaps the CV would contain obvious inconsistencies. A reference would fail to check out. The candidate might struggle in an interview. Their identity documents might look suspicious.
That assumption is becoming dangerous.
In July, we wrote about more than 700 suspected North Korean bots that reportedly applied for remote roles at a major UK bank. Many reportedly had polished CVs, strong technical answers and convincing video interviews. Some reached initial interviews before connections between the applications were detected.
AI can help applicants create credible professional histories, manipulate video and produce supporting material quickly. A proxy can attend part of the recruitment process. Stolen or synthetic identities can be supported by apparently legitimate documents and online profiles.
The problem, then, is establishing whether the person being interviewed, checked, employed, paid and given system access is genuinely the same person.
Employers need several controls working together.
Identity verification needs to carry more weight
Background screening starts with identity.
If the identity itself is false, subsequent checks can simply verify information about the person whose identity has been stolen.
Australian government guidance already advises businesses to independently verify the identity details and documentation of remote workers. The latest international warning goes further, recommending stronger checks of identity documents and, in some cases, in-person interviews.
That does not mean every remote employee has to travel to an office.
It does mean employers should decide what level of identity assurance is appropriate for the access a role will receive. Someone who can work on production systems, financial infrastructure, proprietary AI models or sensitive customer data deserves greater scrutiny than someone with little access to sensitive information.
Employment verification should test the story behind the CV
A polished employment history should be treated as something to verify rather than accept.
Previous employers, dates, roles and qualifications can help establish whether the candidate's professional history is genuine. Employers should also look for inconsistencies between what a candidate claims during recruitment and what independent checks establish.
This matters because the US has already shown how far these schemes can reach. As we covered previously, more than 300 US companies unknowingly hired people connected to a North Korean IT worker operation.
A successful interview was clearly not sufficient protection.
Sanctions screening belongs in the hiring conversation
The risk extends beyond cyber security.
Australia's Department of Foreign Affairs and Trade warns that payments to North Korean IT workers violate UN Security Council sanctions and Australian autonomous sanctions. Employing one may therefore expose an organisation to serious sanctions and legal risks, as well as intellectual property theft, data loss and reputational damage.
Sanctions screening should therefore be considered alongside identity and employment checks where the role or risk profile warrants it.
The challenge is that screening a name against a sanctions list will have limited value when the person has successfully assumed someone else's identity. Identity assurance has to come first.
Hiring controls cannot stop on the employee's first day
Pre-employment screening captures a person at one point in time.
Access can change afterwards.
An employee may move into a more sensitive role. A contractor can be given access to additional systems. Credentials can be shared. New information can emerge after somebody has joined.
Employers should consider whether higher-risk roles justify ongoing monitoring or periodic rescreening, alongside security controls that identify suspicious access patterns.
Onboarding matters too. Device delivery, account creation, payment details and remote access should all be capable of exposing inconsistencies. A candidate who appeared to be in Sydney throughout recruitment should attract attention if their corporate account immediately begins behaving as though it is being accessed from somewhere else.
As we have argued before, a cyber incident can now begin with a job application. Recruitment and security teams need controls that reflect that fact.
Your suppliers can hire the person you would have rejected
There is another weakness employers should examine.
A company can apply strict screening standards to every permanent employee and still give sensitive access to people who have never passed through those controls.
Contractors, outsourced development teams, consultancies, managed service providers and other suppliers often receive credentials to company systems.
The Australian reported that Australian organisations are being exposed through third-party suppliers and outsourcing arrangements.
That makes this a supply-chain issue as much as a recruitment issue.
Companies should know who has access to sensitive systems, regardless of which organisation technically employs them. Contracts with suppliers should set clear expectations for identity and employment checks where their workers will receive meaningful access.
“Screening our employees” is an increasingly narrow definition of the problem.
The question employers need to be able to answer
North Korean operatives are an extreme example, but they expose a basic weakness in remote hiring.
Employers have become very good at recruiting people they may never meet in person. The systems for proving who those people really are have not always developed at the same pace.
A candidate can have an excellent CV. They can pass a technical assessment. They can perform well on camera. None of those things proves identity.
The useful question for employers is therefore no longer simply, “Did this person pass our background check?”
It is: How certain are we that the person we checked is the person now accessing our systems?
.png)
FAQs
Essentially, a work permit is a term used interchangeably with a work visa: if a foreign national has a valid work visa, it also serves as their work permit. However, the Department of Home Affairs officially uses the term work visa.
Carrying out a background check in Australia and New Zealand can be a complicated and lengthy process, but with Veremark's automated platform this can be achieved quicker, with less risk and is next to no work for your team.
According to the Privacy Act, a person's criminal history is deemed sensitive information. Therefore, firms must get permission from candidates before doing a police criminal record check or gathering information about a candidate’s criminal history.
Trusted by the world's best workplaces


APPROVED BY INDUSTRY EXPERTS
.png)
.png)




and Loved by reviewers
Transform your hiring process
Request a discovery session with one of our background screening experts today.




.png)

.jpg)