process 01Smarter ScreeningRead and score every application, not just the top of the pile. 02Better ShortlistingRank on twenty signals, with the evidence behind each one. 03Faster SchedulingNo calendars, no slots. One link, good for fourteen hours. 04Fairer InterviewsQuestions built from the role, answers scored against a written rubric.
Pricing
use cases 01Resume VerificationEvery claim read in context, not lifted out as a keyword. 02AI Cheating PreventionBuilt for the copilot era: divided attention, novel questions. 03Volume ScreeningThe same rubric for applicant one and applicant a thousand. 04Pre-BGV FilterA consistency check before formal verification spend.
For candidates For investors Candidate login Employer login Get access
our views

The FBI Found a North Korean Operative Inside a US Federal Agency

One cell submitted more than 166,000 job applications and landed 76 offers, using deepfakes good enough to put human detection at roughly a coin toss.

The federal agency case is still under investigation, and the FBI hasn't said which agency, what the worker touched, or how he got the offer. That's not really the point. The point is that six weeks after a foreign government's IT operative was found sitting inside a US government network, the eleven-nation alert that followed didn't describe a hiring loophole specific to one agency's process. It described the standard remote hiring funnel — job posting, resume, video interview, offer, onboarding, laptop shipped, first day — as the thing that failed, working exactly as designed, against an applicant who wasn't who the process assumed he was.

The scale is no longer a rounding error

North Korea has reportedly deployed an estimated 8,400 IT workers globally to obtain remote jobs under false identities, according to U.S. Treasury-linked estimates, and DOJ prosecutions to date have identified 479 companies among the confirmed corporate victims. The UN estimates the scheme generates $250 million to $600 million a year for Pyongyang; the joint alert puts 2024's take at roughly $800 million funneled directly into the country's nuclear weapons and ballistic missile programs. The FBI said eight people were sentenced to prison in the first seven months of 2026 alone for facilitating it from the US side — running the "laptop farms" that let a worker in Pyongyang or Shenyang appear to be typing from a home office in Ohio.

The Nisos number is the one that reframes the problem as a funnel rather than a handful of bad hires. The threat-intelligence firm identified a single North Korean cell that had filed more than 166,000 job applications and converted 76 of them into actual offers — a conversion rate so low it would read as failure in any normal hiring analysis, and so high in absolute terms that it means dozens of companies handed a laptop and system access to an operative in the time it took to run this one investigation. Nisos CTO Jared Hudson, describing the moment his team confirmed they were watching it happen in real time rather than inferring it after the fact, put it simply: "If you can think of a best-case scenario for an analyst that follows these things, this is a dream come true, because you never get this kind of access to what we assume is happening. Now we could actually see it happening in real time."

The interview isn't a check anymore. It's an attack surface.

The mechanism that makes this scalable is the same one that shows up everywhere else AI has touched hiring in the past two years: the cost of producing a convincing signal collapsed, and the cost of verifying it didn't. Researchers have shown it takes about an hour, with no prior experience and consumer-grade hardware, to build a working real-time deepfake face-swap good enough to sit through a live video interview. A joint study out of King's College London and the Center for Strategic and International Studies, published in Communications of the ACM, found that people distinguish AI-generated video from authentic video at roughly 50% accuracy — statistically indistinguishable from guessing. The FBI first flagged deepfakes in remote-work interviews back in June 2022, when lip-sync errors were still a visible tell. The eleven-nation alert four years later describes video feeds that "appear to be manipulated or artificially generated," full stop — the tell is gone, and the recruiter on the other end of the call has no reliable way to know it.

Pindrop, a voice- and video-security firm that reviewed the alert in detail, makes a point worth sitting with: even the alert's own recommendation to fall back on in-person interviews isn't the fix it sounds like, because the same advisory warns that third-party proxies now show up in person too, "to create a false sense of trust." Once you can't trust the video and you can't fully trust the room, the interview stops functioning as a check on identity and starts functioning as a stage the operative has to get through — no different, structurally, from an ATS keyword filter or a resume screen, just with higher stakes on the other side of it.

And the stakes on the other side are severe. A Greek security researcher, Vangelis Stykas, spent 22 months inside North Korean operators' own command-and-control infrastructure after they infected their own machines, and presented the results at Black Hat in August 2026: 1,640 companies breached across 57 countries, 700 to 800 of them suffering what he called "really damaging" intrusions with root-level access to corporate servers and cloud environments. The named victims include Coinbase, Uniswap Labs, Boston Children's Hospital, Oppo, an Al Rajhi Bank affiliate, and Italy's Supreme Judicial Council — a reminder that the person who clears your interview isn't just an unqualified hire if the vetting fails. In a meaningful share of cases, the operative's actual assignment is to get inside, not to do the job.

"We didn't know" is not a defense

The part of this that should worry a general counsel as much as it worries a security team is that ignorance doesn't help. OFAC's North Korea sanctions regime operates on a strict-liability standard: a company that unknowingly pays a sanctioned North Korean worker through a legitimate-looking payroll process can be held civilly liable without any finding that it knew or should have known. Working through a staffing agency or a contracting platform doesn't transfer that liability away — several enforcement actions have specifically targeted companies for failing to monitor vendors who did the actual hiring. The only mitigating factor regulators recognize is a documented, reasonable diligence program applied before the hire, not a good-faith explanation offered after the FBI calls.

That combination — strict liability on one side, a verification method that performs at chance levels on the other — is what makes this different from the run-of-the-mill resume inflation this newsletter has covered before. A padded title or an invented certification costs a company a bad quarter from a weak hire. A successful North Korean placement can cost a company a sanctions investigation, a ransomware event, or a spot on a list of 1,640 breached organizations presented at a security conference.

Same blind spot, higher stakes

Every version of the hiring-fraud problem this newsletter has covered comes down to the same failure: a process built to evaluate a self-reported claim, evaluating a self-reported claim it has no independent way to confirm. A resume claims a job title. A cover letter claims enthusiasm for the role. A video interview, it turns out, claims something even more basic — that the face and voice on the call belong to a specific, real, singular human being who is who they say they are. The eleven-nation alert and the Nisos investigation both land on the same practical advice: no single signal, checked once, is sufficient. Cross-reference identity documents against payment details. Compare behavioral and location signals across multiple sessions, not just the one interview. Treat a below-market rate, a refusal to appear on camera, or a mismatch between the name on the account and the name on the bank transfer as data points to be checked against each other, not dismissed one at a time.

That's a verification problem, not a bigger-interview-panel problem, and it's the same shift this newsletter has argued for on the competence side of hiring: the fix isn't reading the same unverifiable signal more carefully, it's replacing the reliance on that signal with something that has to be independently corroborated before anyone gets a laptop shipped to them. A title on a resume that can't be checked against a real, verifiable employment history is a competence risk. A face on a video call that can't be checked against a real, verifiable, singular identity is a security and sanctions risk. Companies that have spent two years bolting AI detection tools onto the resume stage are, in a meaningful number of cases, still doing nothing to verify the much more basic claim sitting underneath it: that the applicant is one real, consistent person.

AgentR evaluates candidates against a verified trajectory — the specific work, at the specific employer, with a specific measurable outcome — because a self-reported resume or a single video interview was never proof of who someone is or what they've done. The North Korean IT worker scheme is the most extreme version of a problem that runs through every stage of hiring right now: a process asked to trust a claim it has no independent way to check. The companies now showing up in DOJ indictments and Black Hat slide decks didn't skip their interview process. They ran it exactly as designed, against a claim the process was never built to verify. Let's talk.