AI-Coached Fake Hires Slip Past Remote Vetting

Remote hiring checks now have to beat a live operator, not a paper resume. In this case, the fraud worked because an AI fed answers in real time while the worker hid behind U.S.-based hardware, so the employer saw a plausible remote hire even though both the person and the machine were elsewhere. Nisos said it infiltrated an active North Korean remote-IT fraud cell and found stolen identities, a U.S. laptop farm, PiKVM remote control, Tailscale, and roughly 40 devices supporting multiple personas across companies. The setup let one operator pass interviews, look local, and route wages through American accounts before the money reached North Korea. The practical risk is broader than one bad applicant. A single actor can gain employee access, payroll diversion, and repeated placement at multiple employers using the same identity-and-device stack.

Part of the PlainSec briefing for 2026-06-17

Sources