Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, dprk, north-korea, it-worker-scheme, insider-threat, fraud, huntress, recorded-future] ยท confidence: high ยท severity: medium ยท affected_sectors: [Global, Healthcare, Financial Services] ยท au_impact: true

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Summary

Huntress and Recorded Future's Insikt Group documented North Korea's fraudulent remote-worker scheme broadening beyond the IT sector into sales, marketing and medicine in August 2026.

Details

Huntress flagged three workers at an Australian healthcare company (February 2026) as suspected DPRK workers impersonating Chinese nationals โ€” caught via Astrill VPN and IPRoyal proxy use, fraudulent identity documents and biographical word anomalies, and passport similarities. A second case at a financial-services firm involved a device joined to PiKVM and a Guermok USB capture card for covert webcam input.

Recorded Future's PurpleDelta cluster applied to jobs at more than 1,100 companies between late 2024 and early 2025, maintaining 22 fabricated personas โ€” some AI-generated using the illicit TrustID Card identity service โ€” and applying to 60 positions a day across 10 platforms while using screen-recording software, AI transcription and chatbot tools to answer interviews in real time. The scheme is tracked under many monikers including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267 and Wagemole.

Assessment

Unlike conventional intrusion, DPRK workers trick companies into hiring them and often do the legitimate work โ€” making them a detection challenge that bypasses perimeter tooling. The Australian healthcare instance makes this directly relevant to AU employers: the control is background-check rigour at onboarding, not network defence.