Remote hiring is facing a trust problem that reaches beyond the interview.

Fabricated identities reported
At least 22
Reported applications per day
Up to 60
Platforms named in reporting
LinkedIn and Upwork

The reported operation used volume as cover

ITPro reports that a group called PurpleDelta used at least 22 fabricated identities to apply for technology jobs. Recorded Future linked the activity to North Korean IT workers. Some of the identities were reported to send as many as 60 applications each day through sites including LinkedIn and Upwork.

The reported operation should be kept separate from legitimate international remote work. The evidence describes a specific group, fabricated identities and a high-volume pattern; it does not justify treating a nationality, location or accent as proof of fraud. That distinction is essential when employers respond.

Remote hiring makes the identity question harder

The volume can make employers add more checks to every application. That may stop fraud, but it can also add delay and scrutiny for legitimate workers who apply from another country.

Identity checks can reduce risk, but a check that is added late or applied inconsistently can make a legitimate candidate repeat the same proof several times. The useful standard is a clear, proportionate process that verifies the person and the work without turning remote hiring into a test of where someone lives.

Security checks should protect candidates too

Explain how candidates can protect themselves. Use the employer domain, never pay to apply, verify the interviewer and protect identity documents. Keep the story about the reported operation, not a suspicion of all international workers.

Candidates can also reduce exposure by sharing sensitive documents only through the employer's verified process. Confirm the domain, the interviewer and the contract before sending identity material. Security should make a real opportunity safer, not create a second opportunity for someone to misuse the application.

Primary source

Check the original source

CISA cybersecurity guidance is the source to consult for the underlying data, statement, ruling or live context.

Open CISA cybersecurity guidance

Sources and editorial note

This original Hidden Jobs analysis uses the report from ITPro (published August 19, 2026) as a secondary source and points readers to the primary source for verification. Hidden Jobs is not affiliated with the organisations or sources mentioned in this story, and reported conditions, figures and policies can change.

More from the newsroom

Hiring news Netflix Plans 5% Layoffs Ahead of Q3 Earnings Hiring news US freezes PERM green card applications for Microsoft, Adobe and six IT firms Hiring news US tech job postings hit three-year high, but actual hiring fell in September
← Back to Hidden Jobs News Explore remote tech jobs