North Korean bots used fake job applicants to target UK bank: Do you really know who has access to your business
More than 700 suspected North Korean bots reportedly tried to secure remote jobs at a major UK bank in June. They didn't need to breach a firewall first. They tried to get invited in through recruitment. For business leaders, the lesson is clear: verifying who you hire is now part of controlling who can access your systems, and preventing cyber attacks.
According to The Times, more than 700 suspected North Korean bots applied for remote-working roles at a large UK bank. The applicants reached initial virtual interviews before being identified as suspicious.
On the surface, they looked credible.
Alfie Whattam, CEO of Alfa AI, told The Times that many of the candidates had polished CVs, gave technically strong answers and presented convincing video interviews. Alfa’s system began finding connections between the applicants, including repeated language, shared device characteristics, manipulated video and discrepancies in location data.
The incident raises a question every business with remote workers should now be asking:
How certain are you that the person receiving access to your systems is actually the person you hired?
The attack starts before the employee does
Cybersecurity controls tend to focus heavily on what happens once somebody has access to a business.
Companies control passwords, devices, permissions and network activity. Yet all of those controls depend on one crucial fact having already been established: the person using those credentials is who the business thinks they are.
That assumption is becoming harder to make.
The UK government has previously warned businesses that North Korean IT workers are fraudulently seeking employment with companies in the UK and elsewhere. Workers may disguise their identity, nationality and location while posing as remote employees based in other countries.
US authorities have issued similar warnings. The FBI has said North Korean IT workers have used fraudulent employment to gain legitimate access to company networks and has documented the use of AI and face-swapping technology during remote interviews.
That changes the nature of the threat.
An attacker does not necessarily need to steal an employee’s credentials when they can attempt to become the employee.
Job application bots make candidate fraud harder to spot
Candidate fraud existed long before generative AI.
People have lied about qualifications, embellished employment histories and used false documents for decades. What has changed is the ability to produce credible applications and identities at scale.
Job application bots can help create CVs, tailor applications to specific vacancies and produce convincing answers to interview questions. AI-generated or manipulated video can also make remote identity checks based purely on visual judgement less reliable.
The UK bank case shows how far this can go. According to The Times, the suspicious candidates initially appeared genuine. It was only when Alfa’s technology identified patterns across their applications, devices, language and location data that the connections became apparent.
For a recruitment team handling hundreds or thousands of applications, spotting those connections manually would be extremely difficult.
And one successful applicant may be enough.
If somebody secures a remote role, the business itself may provide them with a laptop, company credentials and authorised access to internal systems.
At that point, the attacker does not need to break in. The organisation has opened the door for them.

Remote access raises the stakes
Remote hiring gives businesses access to candidates far beyond the commuting distance of an office. It has also removed some of the physical interactions that once made impersonating a candidate considerably harder.
A candidate can apply, interview, sign documents, receive equipment and begin work without ever entering a company building.
That makes identity verification a security control as well as an HR process.
This matters particularly for employees and contractors who will have access to source code, customer information, financial systems or sensitive company data.
An identity check can establish information such as a candidate’s official identity, the validity of their identity document and a biometric match to that document.
Verifying that information before onboarding provides a much stronger foundation than relying on a CV and a convincing video interview.
The principle is simple: sensitive access should follow verified identity.
Identity checks sit at the foundation of effective pre-employment screening.
Veremark’s guide to identity checks explains how identity verification can confirm both attributed details, such as a candidate’s name and date of birth, and biographical information such as their address and country of residence.
This becomes more important when job application bots and AI-assisted impersonation can produce candidates who appear credible during the early stages of recruitment.
A convincing interview tells you somebody interviewed convincingly. It does not prove who was on the other side of the screen.
HR and cybersecurity need to look at the same risk
The North Korean case also exposes a gap in how many businesses think about recruitment.
Recruitment teams decide who enters the organisation. Security teams decide what those people can access. The risk connects the two.
Businesses hiring remotely should establish clear controls for roles that provide access to sensitive systems.
Candidate identity should be verified before onboarding is completed. Relevant employment history and qualifications should be independently checked. Requests to send equipment somewhere other than a verified address should also receive additional scrutiny.
For UK employers, right to work checks provide another formal point at which a candidate’s documentation and eligibility are examined.
Businesses should also consider the level of screening appropriate to the access and responsibilities associated with each position. Veremark offers a wider range of pre-employment background checks that can be selected according to the role, location and risk involved.
Access controls matter too. A new employee should receive the systems and data required to do their job, rather than broad access simply because onboarding is complete.
None of this requires employers to treat every remote candidate with suspicion. It requires businesses to stop treating identity as established simply because someone appeared on a video call.
Ask a different question before granting access
The striking thing about the attempted attack reported by The Times is how ordinary the front door looked.
There was no suspicious email attachment or stolen executive password. There were job applications.
The suspected applicants reportedly had strong CVs. They performed convincingly in interviews. They appeared plausible enough to progress through a recruitment process.
That is exactly why job application bots deserve the attention of business leaders as well as recruitment teams.
For companies with distributed workforces, the question can no longer end with:
“Is this the right person for the job?”
It also needs to include:
“Have we proved this is actually the person we think we are hiring?”
As job application bots become more convincing, finding the answer after somebody has received company credentials is already too late.
.png)
FAQs
This depends on the industry and type of role you are recruiting for. To determine whether you need reference checks, identity checks, bankruptcy checks, civil background checks, credit checks for employment or any of the other background checks we offer, chat to our team of dedicated account managers.
Many industries have compliance-related employment check requirements. And even if your industry doesn’t, remember that your staff have access to assets and data that must be protected. When you employ a new staff member you need to be certain that they have the best interests of your business at heart. Carrying out comprehensive background checking helps mitigate risk and ensures a safer hiring decision.
Again, this depends on the type of checks you need. Simple identity checks can be carried out in as little as a few hours but a worldwide criminal background check for instance might take several weeks. A simple pre-employment check package takes around a week. Our account managers are specialists and can provide detailed information into which checks you need and how long they will take.
All Veremark checks are carried out online and digitally. This eliminates the need to collect, store and manage paper documents and information making the process faster, more efficient and ensures complete safety of candidate data and documents.
In a competitive marketplace, making the right hiring decisions is key to the success of your company. Employment background checks enables you to understand more about your candidates before making crucial decisions which can have either beneficial or catastrophic effects on your business.
Background checks not only provide useful insights into a candidate’s work history, skills and education, but they can also offer richer detail into someone’s personality and character traits. This gives you a huge advantage when considering who to hire. Background checking also ensures that candidates are legally allowed to carry out certain roles, failed criminal and credit checks could prevent them from working with vulnerable people or in a financial function.
Trusted by the world's best workplaces


APPROVED BY INDUSTRY EXPERTS
.png)
.png)




and Loved by reviewers
Transform your hiring process
Request a discovery session with one of our background screening experts today.




.png)

