Remote hiring is facing a trust problem that reaches beyond the interview.
- Fabricated identities reported
- At least 22
- Reported applications per day
- Up to 60
- Platforms named in reporting
- LinkedIn and Upwork
The reported operation used volume as cover
ITPro reports that a group called PurpleDelta used at least 22 fabricated identities to apply for technology jobs. Recorded Future linked the activity to North Korean IT workers. Some of the identities were reported to send as many as 60 applications each day through sites including LinkedIn and Upwork.
The reported operation should be kept separate from legitimate international remote work. The evidence describes a specific group, fabricated identities and a high-volume pattern; it does not justify treating a nationality, location or accent as proof of fraud. That distinction is essential when employers respond.
Remote hiring makes the identity question harder
The volume can make employers add more checks to every application. That may stop fraud, but it can also add delay and scrutiny for legitimate workers who apply from another country.
Identity checks can reduce risk, but a check that is added late or applied inconsistently can make a legitimate candidate repeat the same proof several times. The useful standard is a clear, proportionate process that verifies the person and the work without turning remote hiring into a test of where someone lives.
Security checks should protect candidates too
Explain how candidates can protect themselves. Use the employer domain, never pay to apply, verify the interviewer and protect identity documents. Keep the story about the reported operation, not a suspicion of all international workers.
Candidates can also reduce exposure by sharing sensitive documents only through the employer's verified process. Confirm the domain, the interviewer and the contract before sending identity material. Security should make a real opportunity safer, not create a second opportunity for someone to misuse the application.
Primary source
Check the original source
CISA cybersecurity guidance is the source to consult for the underlying data, statement, ruling or live context.