North Korea Impersonates Candidates on LinkedIn
A new scheme in which North Korea impersonates candidates on LinkedIn threatens to undermine remote hiring security. Analysts say operatives from the Democratic People’s Republic of Korea (DPRK) are now copying real professionals’ profiles rather than creating fake identities. These actors use verified emails and identity badges to pose as genuine applicants, often with the goal of securing IT roles in Western firms.
Security Alliance analysts flagged this tactic on Feb. 10, noting that the fraudsters control communication channels to intercept job-related messages. They exploit LinkedIn’s job application features to appear credible and bypass early screenings. The campaign allows North Korean operatives to funnel wages to the regime or access sensitive systems, raising espionage risks.
Experts advise employers to validate ownership of LinkedIn accounts through direct platform engagement. A pinned alert on a profile may also help deter misuse.
To learn more about how North Korea impersonates candidates, read the full article:
DPRK IT Workers Impersonating Individuals Using Real LinkedIn Accounts to Apply for Remote Roles
