Your Next Hire Might Be in Pyongyang: What the North Korean IT Worker Threat Means for UK SME Hiring
North Korean operatives are posing as remote developers to land jobs at Western companies. Here's how UK SMEs and their MSPs can spot the red flags during hiring, vetting and onboarding.
A US company thought it had hired a talented software engineer. It ran a background check, held video interviews, shipped a company laptop to a home address in Arizona, and started paying a salary. Months later the FBI told them their new developer was a front for North Korean operatives working out of an apartment somewhere far from Phoenix. The laptop never left the US — it sat in a garage stuffed with dozens of other company machines, wired into a device that let workers thousands of miles away control them as if they were sitting at the desk.
That garage, run by an American woman later charged for her role, is now one of the best-documented examples of a scheme that has quietly cost Western firms an estimated hundreds of millions of dollars. And while the headlines frame it as a nation-state story about sanctions evasion and weapons funding, that framing lets a lot of UK business owners off the hook. Because the actual problem landing on your desk isn't geopolitics. It's a hiring and contractor vetting problem, and it's very much within your control.
Why this should worry a Nottingham SME, not just the Pentagon
The instinct is to assume this only happens to Silicon Valley giants with thousands of open roles. It doesn't. The whole model depends on volume and low friction, which means smaller companies hiring remote developers, DevOps engineers and IT contractors are exactly the target. You post a role on a job board, you get a flood of well-qualified CVs, you interview over video, you onboard remotely. Every step of that is now normal, and every step of it is exploitable.
North Korean IT workers are skilled. They pass technical tests. They hold down the job and deliver code. Some have collected salaries from multiple Western companies at once, running several full-time roles in parallel. The financial fraud is one thing. The bigger risk for an SME is what a hostile insider does with legitimate access to your codebase, your client data and your systems — including, in a growing number of cases, stealing data and then extorting the employer once the arrangement is discovered.
For an MSP, this matters twice over. You need to protect your own hiring, and you're often the party your clients lean on when they bring a remote technical contractor into an environment you manage. That makes vetting part of the service, whether it's written into the contract or not.
The red flags, grouped by where they show up
No single sign proves anything. The point is to notice clusters. One oddity is life; three together is a pattern worth stopping for.
Interview and behavioural tells
- Camera reluctance. A candidate who keeps their camera off, uses an obviously virtual or blurred background in every call, or whose lip movements don't quite match their speech. Voice-changing and real-time video tools are in play now, so treat persistent AV excuses as a prompt for more scrutiny, not less.
- The answers don't match the person. Strong written English and polished code, paired with spoken answers that lag, sound scripted, or seem to be relayed. Some operations use a fluent front-person for interviews and a different team to do the work.
- Vague, unverifiable history. Impressive CV, but former employers that are hard to confirm, LinkedIn profiles created recently, and referees whose contact details route to webmail addresses or numbers that never quite connect.
- Reluctance to meet in person, ever. A refusal to attend even an occasional in-person session within reasonable travel, or a stream of last-minute reasons why an on-camera ID check can't happen today.
Payment and paperwork anomalies
- Payment routing that doesn't match the person. The candidate claims to be in Manchester, but wants payment to a US-based payroll intermediary, a payment platform account, or asks to be paid in cryptocurrency. Requests to change bank details shortly after onboarding are a classic.
- Address mismatches. The address on the contract, the address the laptop ships to, and the tax or right-to-work documents don't line up. Laptop-forwarding addresses in a different country from the stated home are the tell that cracked several of these cases open.
- Documents that are 'almost right'. ID and right-to-work paperwork that passes a glance but fails a live check — a photo that doesn't quite match the face on camera, or credentials that can't be validated against the issuing source.
Technical and infrastructure indicators
- KVM-over-IP and remote-control hardware. This is the garage trick. A device that lets someone operate a physical company laptop from anywhere. If a managed endpoint is being driven remotely by hardware you didn't provision, your monitoring should catch input and session patterns that don't fit a person sitting at that machine.
- VPN and residential-proxy use. Consistent logins through commercial VPN exit nodes, or residential proxy services designed to make a connection look like a home broadband line in the 'right' country. Look for a mismatch between claimed location and consistent connection origin, and for impossible-travel events across sessions.
- Odd working patterns. Activity clustered in time zones that don't match the stated location, or long stretches of near-continuous work that suggest more than one person on one account.
- Software that shouldn't be there. Remote-access tools, screen-sharing utilities or scripting frameworks installed early in the engagement that weren't part of the role.
What the due diligence actually looks like
Spotting flags is reactive. The stronger position is a hiring and onboarding process that makes infiltration expensive and awkward. For an MSP advising clients, here's what good looks like.
Verify identity live, against a source of truth. Don't rely on a document photo. Use a video ID check where the person holds their ID to camera and answers unscripted questions. Confirm right-to-work through the official channels rather than trusting supplied PDFs.
Cross-check the money against the person. Payroll and finance should flag when a new hire's payment destination doesn't match their stated location, when intermediaries appear, or when bank details change soon after start. Make that a standing control, not a one-off.
Ship hardware and confirm receipt properly. If you send a laptop, verify it arrived at the person, not just an address. A short 'first login' video call where they set the machine up on camera closes the garage loophole cheaply.
Watch the endpoint from day one. Endpoint detection, VPN and geolocation monitoring, and alerts for remote-control tooling should be live before the first commit, not switched on after something goes wrong. Impossible-travel and residential-proxy detection belong in your standard client baseline.
Stage access. New technical contractors don't need production keys and full repository access on day one. Grant privileges gradually as trust is earned, and log everything they touch.
Keep an in-person moment somewhere. Even one required on-camera, unscripted interaction — technical or otherwise — filters out a surprising share of relayed candidates.
The uncomfortable takeaway
Remote hiring gave UK SMEs access to talent they could never have reached otherwise. That's genuinely good, and nobody should abandon it. But the same frictionless process that lets you hire a brilliant developer in another city lets someone hire you under a borrowed identity. The fix isn't paranoia. It's a handful of deliberate checks at the points where fraud has to reveal itself — identity, payment, hardware and access.
If you use remote technical contractors and you're not sure your vetting would catch any of the above, that's the conversation to have with your MSP this month. We'd far rather help you build the process now than pull an unknown operator out of your systems later.
