In July 2024 a well-known security awareness company disclosed that it had recruited, onboarded and issued a laptop to a North Korean operative posing as an American software engineer. The candidate had passed several video interviews and a background check. He was identified only when monitoring software flagged him installing malware on the machine the company had sent him, days into the job.
The company published the account deliberately, and the decision was a service to everyone else, because the failure was not unusual and the controls involved were not weak.
This is identity fraud, not conduct risk
Most hiring safeguards are built to answer a question about behavior. They look for undisclosed convictions, exaggerated qualifications, gaps in employment and conflicts of interest, all of which assume that the person being examined exists and is the person in the interview.
The scheme described here begins one step earlier. The identity itself is constructed, frequently from a real person’s stolen details, and every document supporting it is internally consistent because it was assembled to be. A check that verifies the coherence of a file will pass it, and the more thorough the check, the more confidence the result carries.
United States prosecutors have pursued the infrastructure that makes this work at scale. One indictment described five defendants who obtained work from at least sixty-four American companies between April 2018 and August 2024, with payments from ten of them alone generating more than $866,000. The laptops issued to those workers sat in domestic residences, so that connections appeared to originate where the employer expected.

The candidate passed several video interviews and a background check. Every document supporting the identity was internally consistent, because it had been assembled to be.
Remote onboarding removed checks nobody had listed
Distributed hiring is settled practice, and the argument here is not against it. What is worth being precise about is exactly which checks were lost when onboarding stopped happening inside a building.
Somebody used to hand over a laptop in person. Somebody witnessed the original documents rather than a scan. New joiners were seen by dozens of colleagues in their first week, in a setting where an inconsistency would have been noticed without anyone being assigned to look for it. None of that was ever written down as a control, which is why none of it appeared on a list when it disappeared.
What verification actually requires
The distinction that matters is between documents the candidate supplies and facts established independently of them. Screening that relies on the former can only confirm that a story is coherent.
- Confirm the employment history with the employer rather than the referee. A supplied reference contact is part of the candidate’s submission, and in constructed identities it is frequently part of the construction.
- Verify credentials at the issuing institution. A certificate is an artefact, and artefacts are straightforward to produce convincingly.
- Establish continuity of the identity over time. A real person leaves a long, untidy trail across many sources; a constructed one tends to be tidy and shallow, and the tidiness is the signal.
- Reconcile the stated location with observable reality. Where equipment ships, where the person banks and where they connect from should agree, and a mismatch is worth a conversation rather than an assumption.
For senior appointments this is the ordinary territory of executive background investigations, where the expectation is already that findings are sourced rather than collected. The change worth making is applying a proportionate version of the same logic further down the organization, because the access granted to a mid-level engineer is frequently broader than that granted to a director.

A real person leaves a long and untidy trail across many independent sources. A constructed identity tends to be tidy and shallow, and the tidiness is the signal worth acting on.
The exposure is access, not payroll
Read as a fraud, the loss is a salary paid to somebody not entitled to it, which for most organizations is an irritation rather than a crisis.
Read as an access problem, it is considerably more serious. The organization has issued credentials, granted network access and admitted somebody to internal systems on the strength of an identity it never confirmed, and the person holding those credentials is inside every perimeter that was built to keep outsiders out. Whatever monitoring exists is watching for an intruder rather than for a colleague.
That is the reason this belongs alongside cybersecurity rather than in a human resources process. The hiring decision is the point at which access is granted, and it is the only point at which the question can be asked cheaply.
The question for a board
Take the last ten fully remote hires and establish, for each, which facts were confirmed with a source the candidate did not nominate. Where the answer is none, the organization has verified a set of documents rather than a person.
The second question is about proportion. Access, rather than seniority, should determine how much verification a role attracts, and most organizations have those two things the wrong way round. Our Book of the Month shelf has How Spies Think, which is useful here for its treatment of how analysts test what they are being told rather than how much of it they collect.
Falcone International
Bring us a question like this one
We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.
