The Employee Who Doesn’t Exist: North Korea’s Deepfake Workforce Inside Western Companies

by Warrier | Jun 27, 2026 | Dossiers

They don't breach your network. They get hired onto it — pass the video interview with a real-time deepfake face, collect a salary, and send it to Pyongyang's weapons program. Over 3,000 of them may already be inside Western companies. Inside the Dossier: how a person who doesn't exist gets onboarded, why Europe is now the target, the extortion twist, and the checks that actually catch them. Members only.

Key Judgement

We assess with high confidence that North Korea operates a large, state-directed program to place its IT operatives inside Western companies under stolen and AI-fabricated identities — a scheme that has reached, by Mandiant's 2026 estimate, more than 3,000 suspected operatives embedded in Western firms, generating in excess of US$600 million annually for the regime. We assess that the operation is run not by freelance criminals but by a North Korean state entity tied to its weapons apparatus, with the proceeds funding sanctions-evaded foreign currency and, ultimately, ballistic-missile and weapons-of-mass-destruction programs. We judge generative AI — real-time deepfake interviews, synthetic résumés and personas, AI coding assistants — to be the accelerant that has turned a long-running infiltration scheme into a scalable industry, and we assess the threat as actively expanding from the United States into Europe.

Why This Dossier Matters

Every other threat in the warrier landscape attacks a company from the outside. This one walks in through the front door, badge in hand, and collects a salary. The deepfake here is not used to defraud a victim in a single transaction — it is used to become an employee, with legitimate credentials, network access, and time. That inverts the entire security model: the perimeter is irrelevant when the threat is on the payroll. Understanding how a synthetic person gets hired is now a core security competency, not an HR footnote.

Source Notes

This Dossier draws on US Department of Justice announcements and the prosecuted cases of Christina Chapman, Oleksandr Didenko, and the New Jersey facilitators; the January 2026 FBI/CISA/Treasury joint advisory attributing the operation to the DPRK Munitions Industry Department; Mandiant / Google Threat Intelligence Group reporting on scale and the European expansion; Palo Alto Networks Unit 42 on real-time deepfake interview tradecraft; and disclosures by Amazon and KnowBe4 regarding their own encounters. Scale estimates (the 3,000-operative and US$600 million annual figures, the per-worker earnings, the 300-plus and 479 corporate-victim counts) are attributed to their originating bodies and presented as estimates, not precise tallies. Defensive guidance synthesises advisories from the FBI, NCSC, BSI, and named identity-security vendors. DPRK attribution reflects the consensus of US government and major threat-intelligence sources.

MEMBERS ONLY — THE FULL DOSSIER FILE CONTINUES BELOW

🔒 This analysis is for warrier.ai Intelligence members only. → Become a Member

Already a member? Log in here

"

advertising

Buy the world How hungry are you? Which country do you want to buy? Become a part of net art history.