

Key Takeaways
- North Korean IT worker fraud exploits gaps across recruiting, onboarding, IT provisioning, payroll, and access management—not just weaknesses in hiring.
- Traditional checks can confirm that an identity exists without proving that the person presenting it is the rightful owner.
- Stronger workforce security connects multiple identity signals across biometrics, documents, devices, and verified data sources.
- Identity assurance shouldn’t end at onboarding; key touchpoints like authenticator enrollment, password resets, account recovery, and privileged access also warrant reverification.
- CLEAR1 helps organizations verify the person beyond the device before access is provisioned and at other critical moments throughout the workforce lifecycle.
Remote hiring relies on several assumptions: that the person applying is the person interviewing, that the person hired is the one doing the work, and that the person granted access is the one who should receive those permissions.
Today, that assumption is becoming harder and harder to validate. We now know that a remote job application can look convincing, a résumé can read as if it was written by a qualified candidate, an interview can go smoothly, and a device can appear to be located in the expected country. Still, the person behind the screen may not be who you think they are.
A Wall Street Journal investigation demonstrated just how sophisticated these operations have become. Reporters examined a North Korean IT worker cell that used stolen American identities and AI tools to pursue remote jobs at U.S. companies. According to the investigation, the cell applied to more than 1,000 companies in just over three months using AI-generated résumés and cover letters, ChatGPT-assisted interview responses, and face-swapping technology.
The operation reportedly extended into the physical world, too. U.S.-based facilitators operated devices, opened bank accounts, cashed checks, and in some cases participated in interviews while North Korean workers performed the actual labor remotely.
While the story focuses on a specific nation-state operation, the broader lesson applies to every organization: credentials, documents, and devices are important signals, but none can confidently prove who is behind the screen on their own. With a multi-layered identity solution like CLEAR1’s, organizations can maximize security and minimize friction—wherever identity matters most.
What the WSJ Investigation Revealed About North Korean IT Workers
The reported operation didn’t rely on one sophisticated attack; it exploited multiple points in the workforce lifecycle, from the initial application through employment.
- Stolen identities: Real American identities gave applications and supporting information a more credible starting point.
- AI-assisted applications: Résumés, cover letters, and interview responses could be produced or refined quickly.
- Presentation-layer impersonation: Face-swapping tools made it harder to determine whether the person on a video call matched the claimed identity.
- U.S.-based facilitation: The Journal described people in the United States operating devices, handling financial accounts, and supporting interviews.
- Remote labor after hiring: The person who obtained the role and the person who performed the work were not necessarily the same individual.
The FBI has separately warned that North Korean IT workers may disguise their identities, use U.S.-based facilitators, and seek fraudulent employment to gain access to U.S. company networks. Its guidance recommends stronger identity controls and vigilance throughout the remote-worker lifecycle.
This makes the security implication clear: hiring fraud can become an access-control problem. Once a false identity is accepted upstream, downstream systems may treat that person as a legitimate employee or contractor—provisioning devices, credentials, payment information, and access to sensitive systems accordingly.
The Problem With Traditional Identity Checks
Background checks, employment verification, sanctions screening, and document checks all serve important purposes. But they don’t necessarily answer a key question: Is the person presenting this identity actually the person it belongs to?
A genuine government-issued ID can be used by an impostor. Legitimate personal information can be stolen. Credentials can be shared or compromised. A device can be operated by a facilitator while someone thousands of miles away performs the work.
This is the central problem in North Korean IT worker fraud. Traditional screening may establish that an identity exists, but there needs to be a trustworthy connection between the identity and the person presenting it. The answer isn’t to discard existing security and hiring controls. It’s to strengthen them with person-based verification at the moments where identity matters most.
The Enterprise Identity Gap
A remote hire often moves through a series of disconnected identity events:
- Recruiting evaluates a résumé and interview.
- Human resources collects identity documents and employment information.
- IT provisions a device, account, and authenticator.
- Finance establishes payment details.
- The employee or contractor requests access, recovery, or privilege later.
Every team can execute its individual responsibility correctly while a larger security gap remains because no single workflow necessarily connects the person, the claimed identity, the document, the device, and the access request. Continuous, multi-layered verification helps close this gap by making trusted identity an explicit control before access is provisioned and throughout the workforce lifecycle.
What Stronger Workforce Identity Verification Looks Like
No single identity signal can eliminate every threat. Stronger assurance comes from connecting complementary signals so that one stolen, compromised, or manipulated artifact doesn’t determine the outcome.
Use multiple layers of identity
Identity is multidimensional, and the security protecting it should be, too. A multi-layered approach combines signals across biometrics, documents, devices, and verified data sources to build a more complete picture of who someone is.
CLEAR1 analyzes hundreds of real-time signals across these layers. A selfie connects the live person to the portrait on a government-issued ID. Document checks assess whether the government-issued ID itself is authentic. Source validation can corroborate identity details against credible and authoritative sources. Device signals can help identify anomalous patterns.
Each layer answers a different question, and together, they provide stronger identity assurance than any single check can provide on its own.
Trusted, reusable identity
More than 43 million people in the CLEAR network can verify with a selfie, while new users establish their reusable identity after a quick, one-time setup. This makes it seamless for users to verify throughout the entire employee lifecycle, not just at a single touchpoint.
Continuous verification
Onboarding is only one moment in the workforce lifecycle. Verifying identity also matters when an employee enrolls or changes an authenticator, requests a password reset, recovers an account, asks for privileged access, or takes another action involving sensitive systems or data.
Organizations can define step-up events based on their risk model. Examples include first login, device shipment or receipt, authenticator enrollment, privileged access, unusual device or location signals, and account recovery.
Complement the existing security stack
Employee verification is most effective when it fits into the systems and workflows organizations already use to manage hiring, access, and risk. By integrating with existing infrastructure, organizations can introduce stronger identity assurance at critical moments without replacing established processes or creating disconnected workflows.
Person-based verification plays a specific role within that broader security ecosystem: confirming that the individual presenting an identity is its rightful owner. It complements—but does not replace—IAM, endpoint security, least-privilege access, background checks, sanctions screening, and ongoing workforce monitoring.
CLEAR1 adds this person-based identity signal to existing workflows through out-of-the-box integrations with leading IAM platforms such as Okta, Ping, and Microsoft Entra, as well as other enterprise systems, along with flexible APIs for custom experiences.
A Practical Playbook for Security and People Leaders
A workforce identity program should combine identity controls with operational, legal, and security processes:
- Verify before provisioning access. Add person-based identity verification before issuing devices, creating accounts, or granting access to sensitive environments.
- Connect the hiring and access records. Compare identity, contact, payment, device, and shipping information for reuse or inconsistency across candidates, contractors, and vendors.
- Screen against applicable sanctions lists. Use current OFAC sanctions resources and counsel-approved procedures, including OFAC’s SDN List, when applicable to the organization and workflow.
- Reverify at high-risk events. Consider authenticator enrollment, password resets, account recovery, privileged access, and unusual device or location signals.
- Extend controls to third parties. Make staffing firms, recruiting partners, payroll providers, and IT vendors part of the identity-assurance conversation.
- Separate verification from hiring decisions. Identity verification should help establish that a person is who they claim to be. It should not make unsupported judgments about qualifications, intent, nationality, ethnicity, accent, or other protected characteristics.
- Prepare an escalation path. Establish who reviews a failed or inconclusive verification, how legitimate users can resolve issues, and when suspected activity should be reported to the FBI, IC3, or other appropriate authorities.
This playbook is not a substitute for legal advice or a complete insider-risk program. It is a set of identity controls that can strengthen the front end of workforce security.
A More Resilient Model for Workforce Trust with CLEAR1
The Journal’s investigation is a reminder that workforce identity is not only an HR concern or an access-management checkbox; it is part of the organization’s security perimeter. The right response is to verify the person before access is provisioned, connect identity signals across the workforce lifecycle, and reverify when the risk or requested action changes.
Because a document is not an identity, a credential is not a person, and a device is not proof of who is behind the screen.
{{cta-block}}
Frequently Asked Questions
What is workforce identity verification?
Workforce identity verification is the process of confirming that a job applicant, employee, contractor, vendor, or other workforce user is the person they claim to be. It can combine biometric identity verification, liveness detection, government-issued ID authentication, source validation, and device signals before access is provisioned or during a high-risk workflow.
Why is identity verification important for remote hiring?
Remote hiring can make it difficult to confirm that the person who applies is the person who interviews, accepts the job, receives the device, and performs the work. Remote employee identity verification adds a person-based control to hiring and onboarding, helping organizations reduce the gap between an identity record and the human being presenting it.
How can companies prevent remote hiring fraud?
Companies can reduce remote hiring fraud by combining identity proofing with background checks, sanctions screening, device and access controls, third-party oversight, and clear escalation procedures. Person-based verification should happen before sensitive access is provisioned and may be repeated during account recovery, authenticator enrollment, or privileged access.
What is identity proofing?
Identity proofing is the process of establishing that an individual is connected to a claimed identity using evidence such as a government-issued ID, biometric matching, liveness detection, and authoritative or verified data sources. Strong identity proofing uses multiple signals rather than relying on a single document or credential.
What is biometric identity verification?
Biometric identity verification compares a person’s biometric characteristics—such as their face—with an identity claim or previously established identity. Liveness detection helps assess whether a real person is present and can help detect presentation attacks. Biometric verification should be used as part of a broader, risk-based identity decision.
How do companies verify remote employees and contractors?
Organizations can verify remote employees and contractors during onboarding by connecting the live person to an authenticated identity document and relevant source or device signals. They can also use step-up reverification when a user enrolls an authenticator, resets a password, recovers an account, requests privileged access, or presents unusual risk signals.
How do North Korean IT workers use stolen identities?
According to the WSJ investigation and public FBI guidance, North Korean IT workers may use stolen or deceptive identities, AI-assisted application materials, remote interview techniques, and U.S.-based facilitators to pursue jobs. Organizations should address these risks through layered identity verification and security controls, not nationality-based profiling.
What is the best way to detect North Korean IT workers?
The best approach is a layered, lawful process that verifies the live person against the claimed identity, authenticates identity documents, corroborates relevant information, assesses applicable device signals, and reverifies users at high-risk workforce events. These controls should be combined with sanctions screening, third-party oversight, and applicable FBI or IC3 guidance.
How does CLEAR1 help with workforce identity verification?
CLEAR1 helps organizations verify the person behind a workforce identity before access is provisioned and at selected high-risk moments. Its approach can combine biometric verification, PAD2-certified liveness, government-issued ID authentication, source validation, reusable identity, and device signals, while complementing existing IAM and security controls.
How can organizations secure account recovery and password resets?
Organizations can strengthen account recovery and password-reset security by adding person-based step-up verification instead of relying only on knowledge-based questions, email, SMS, or an existing device. Reverification against an established identity can help confirm that the person requesting access is the authorized user.
Is identity verification a replacement for IAM or background checks?
No. Workforce identity verification complements IAM, endpoint security, least-privilege access, background checks, sanctions screening, and workforce monitoring. It addresses a specific question—whether the person presenting an identity matches the claimed identity—while other controls address authorization, device health, behavior, and legal or employment risk.
Remote hiring relies on several assumptions: that the person applying is the person interviewing, that the person hired is the one doing the work, and that the person granted access is the one who should receive those permissions.
Today, that assumption is becoming harder and harder to validate. We now know that a remote job application can look convincing, a résumé can read as if it was written by a qualified candidate, an interview can go smoothly, and a device can appear to be located in the expected country. Still, the person behind the screen may not be who you think they are.
A Wall Street Journal investigation demonstrated just how sophisticated these operations have become. Reporters examined a North Korean IT worker cell that used stolen American identities and AI tools to pursue remote jobs at U.S. companies. According to the investigation, the cell applied to more than 1,000 companies in just over three months using AI-generated résumés and cover letters, ChatGPT-assisted interview responses, and face-swapping technology.
The operation reportedly extended into the physical world, too. U.S.-based facilitators operated devices, opened bank accounts, cashed checks, and in some cases participated in interviews while North Korean workers performed the actual labor remotely.
While the story focuses on a specific nation-state operation, the broader lesson applies to every organization: credentials, documents, and devices are important signals, but none can confidently prove who is behind the screen on their own. With a multi-layered identity solution like CLEAR1’s, organizations can maximize security and minimize friction—wherever identity matters most.
What the WSJ Investigation Revealed About North Korean IT Workers
The reported operation didn’t rely on one sophisticated attack; it exploited multiple points in the workforce lifecycle, from the initial application through employment.
- Stolen identities: Real American identities gave applications and supporting information a more credible starting point.
- AI-assisted applications: Résumés, cover letters, and interview responses could be produced or refined quickly.
- Presentation-layer impersonation: Face-swapping tools made it harder to determine whether the person on a video call matched the claimed identity.
- U.S.-based facilitation: The Journal described people in the United States operating devices, handling financial accounts, and supporting interviews.
- Remote labor after hiring: The person who obtained the role and the person who performed the work were not necessarily the same individual.
The FBI has separately warned that North Korean IT workers may disguise their identities, use U.S.-based facilitators, and seek fraudulent employment to gain access to U.S. company networks. Its guidance recommends stronger identity controls and vigilance throughout the remote-worker lifecycle.
This makes the security implication clear: hiring fraud can become an access-control problem. Once a false identity is accepted upstream, downstream systems may treat that person as a legitimate employee or contractor—provisioning devices, credentials, payment information, and access to sensitive systems accordingly.
The Problem With Traditional Identity Checks
Background checks, employment verification, sanctions screening, and document checks all serve important purposes. But they don’t necessarily answer a key question: Is the person presenting this identity actually the person it belongs to?
A genuine government-issued ID can be used by an impostor. Legitimate personal information can be stolen. Credentials can be shared or compromised. A device can be operated by a facilitator while someone thousands of miles away performs the work.
This is the central problem in North Korean IT worker fraud. Traditional screening may establish that an identity exists, but there needs to be a trustworthy connection between the identity and the person presenting it. The answer isn’t to discard existing security and hiring controls. It’s to strengthen them with person-based verification at the moments where identity matters most.
The Enterprise Identity Gap
A remote hire often moves through a series of disconnected identity events:
- Recruiting evaluates a résumé and interview.
- Human resources collects identity documents and employment information.
- IT provisions a device, account, and authenticator.
- Finance establishes payment details.
- The employee or contractor requests access, recovery, or privilege later.
Every team can execute its individual responsibility correctly while a larger security gap remains because no single workflow necessarily connects the person, the claimed identity, the document, the device, and the access request. Continuous, multi-layered verification helps close this gap by making trusted identity an explicit control before access is provisioned and throughout the workforce lifecycle.
What Stronger Workforce Identity Verification Looks Like
No single identity signal can eliminate every threat. Stronger assurance comes from connecting complementary signals so that one stolen, compromised, or manipulated artifact doesn’t determine the outcome.
Use multiple layers of identity
Identity is multidimensional, and the security protecting it should be, too. A multi-layered approach combines signals across biometrics, documents, devices, and verified data sources to build a more complete picture of who someone is.
CLEAR1 analyzes hundreds of real-time signals across these layers. A selfie connects the live person to the portrait on a government-issued ID. Document checks assess whether the government-issued ID itself is authentic. Source validation can corroborate identity details against credible and authoritative sources. Device signals can help identify anomalous patterns.
Each layer answers a different question, and together, they provide stronger identity assurance than any single check can provide on its own.
Trusted, reusable identity
More than 43 million people in the CLEAR network can verify with a selfie, while new users establish their reusable identity after a quick, one-time setup. This makes it seamless for users to verify throughout the entire employee lifecycle, not just at a single touchpoint.
Continuous verification
Onboarding is only one moment in the workforce lifecycle. Verifying identity also matters when an employee enrolls or changes an authenticator, requests a password reset, recovers an account, asks for privileged access, or takes another action involving sensitive systems or data.
Organizations can define step-up events based on their risk model. Examples include first login, device shipment or receipt, authenticator enrollment, privileged access, unusual device or location signals, and account recovery.
Complement the existing security stack
Employee verification is most effective when it fits into the systems and workflows organizations already use to manage hiring, access, and risk. By integrating with existing infrastructure, organizations can introduce stronger identity assurance at critical moments without replacing established processes or creating disconnected workflows.
Person-based verification plays a specific role within that broader security ecosystem: confirming that the individual presenting an identity is its rightful owner. It complements—but does not replace—IAM, endpoint security, least-privilege access, background checks, sanctions screening, and ongoing workforce monitoring.
CLEAR1 adds this person-based identity signal to existing workflows through out-of-the-box integrations with leading IAM platforms such as Okta, Ping, and Microsoft Entra, as well as other enterprise systems, along with flexible APIs for custom experiences.
A Practical Playbook for Security and People Leaders
A workforce identity program should combine identity controls with operational, legal, and security processes:
- Verify before provisioning access. Add person-based identity verification before issuing devices, creating accounts, or granting access to sensitive environments.
- Connect the hiring and access records. Compare identity, contact, payment, device, and shipping information for reuse or inconsistency across candidates, contractors, and vendors.
- Screen against applicable sanctions lists. Use current OFAC sanctions resources and counsel-approved procedures, including OFAC’s SDN List, when applicable to the organization and workflow.
- Reverify at high-risk events. Consider authenticator enrollment, password resets, account recovery, privileged access, and unusual device or location signals.
- Extend controls to third parties. Make staffing firms, recruiting partners, payroll providers, and IT vendors part of the identity-assurance conversation.
- Separate verification from hiring decisions. Identity verification should help establish that a person is who they claim to be. It should not make unsupported judgments about qualifications, intent, nationality, ethnicity, accent, or other protected characteristics.
- Prepare an escalation path. Establish who reviews a failed or inconclusive verification, how legitimate users can resolve issues, and when suspected activity should be reported to the FBI, IC3, or other appropriate authorities.
This playbook is not a substitute for legal advice or a complete insider-risk program. It is a set of identity controls that can strengthen the front end of workforce security.
A More Resilient Model for Workforce Trust with CLEAR1
The Journal’s investigation is a reminder that workforce identity is not only an HR concern or an access-management checkbox; it is part of the organization’s security perimeter. The right response is to verify the person before access is provisioned, connect identity signals across the workforce lifecycle, and reverify when the risk or requested action changes.
Because a document is not an identity, a credential is not a person, and a device is not proof of who is behind the screen.
{{cta-block}}








