In July 2024, the security-awareness company KnowBe4 hired a remote software engineer who turned out to be a North Korean operative running a stolen US identity and an AI-augmented photo. Clearing a background check, reference checks, and four video interviews, the persona was caught only when the company laptop began loading malware. The verification that failed was remote identity screening, part automated and part human, and one operator runs many such personas at once.
What happened at KnowBe4
KnowBe4, a company whose entire product is teaching other organizations to spot social engineering, hired a software engineer for its internal IT team in July 2024. The engineer was a persona operated by a North Korean threat actor, and KnowBe4 published the account itself, in a post detailing exactly how the hire cleared its process.
According to KnowBe4 and to CyberScoop's reporting, the persona used a valid identity stolen from a US-based person, and because the identity was real, it passed the background check and reference checks that identity supported. The photo on the application was a stock image altered with AI to match the stolen identity. Carrying that face, the persona then sat for four video-conference interviews and was hired.
Nothing in the screening caught it. What caught it was the hardware. On July 15, the day the shipped Apple laptop was received, it began loading malware, which KnowBe4's own security operations flagged immediately, and the machine was traced to an IT mule laptop farm, a US address where a facilitator keeps company-issued laptops online so the overseas operator can work through them. KnowBe4 reported no data breach and no exfiltration.
Not one hire, an industry
The KnowBe4 hire is one visible instance of a state-run program. As Dark Reading documents, thousands of North Korean IT workers apply for remote roles at US and European companies using multiple fabricated identities, collect paychecks that fund the regime, and continue until they are discovered and removed. A single operator commonly runs around a dozen personas and applies to hundreds of jobs.
Deepfakes are what make that volume work. With real-time face replacement, one operator can interview for the same role repeatedly behind different synthetic faces, which both multiplies throughput and keeps any single face from being catalogued and circulated in security bulletins. Far from a flourish on the attack, the synthetic identity is the mechanism that lets the attack run at scale.
What actually got bypassed
Separate the two things that failed, because they are different failures. The background check and reference checks are a largely automated control: fed a valid identity, they return a pass, and they returned a pass here because the identity was real, just stolen. The four video interviews are a human control, a person on a call judging whether the face and story hold up, and the people were convinced.
That is the distinction that matters. A human interviewer being convinced is social engineering, and it scales only as fast as you can staff interviews. An automated identity check accepting a synthetic or stolen input is a defeated control, and it scales at the speed of an API, for as many applications as an operator wants to file. The North Korean program exploits both at once: a real stolen identity to clear the machine, an AI-augmented face to clear the human.
The lesson generalizes the way it does across synthetic-media fraud. The question is never whether the face on the interview looks real. It is whether the check reads a property the operator cannot supply, and here the operator supplied everything: a stolen identity for the document, an AI photo and a real-time face-swap for the face. Both are the failure mode our detector benchmark documents, controls that score well on clean inputs collapsing once the input is adversarial.
What this means for hiring platforms
If your platform or your employer relies on remote identity verification and a video interview to establish that a candidate is who they claim, this is your threat model, not a curiosity about one company. Document-plus-selfie identity checks and live-interview liveness (the automated test that a face on camera is a real, present person rather than a replayed or synthetic stream) are precisely the controls this program is built to defeat, and the same face-swap and injection tooling has already opened real bank accounts through the liveness step of remote onboarding.
You cannot tell from a datasheet whether your specific deployment returns a pass on a current-generation face-swap or an injected video stream. Vendor results age and the tooling does not wait, so the only honest answer is a measured one, against your control, with current attacks.
Margen does not sell identity verification or detection. We are an independent third party that red-teams these controls under adversarial, platform-realistic conditions and reports, with a number and a margin of error, where they hold and where they break.
Related reading
- Fraud storiesTwo deepfake CEOs, two executives who did not fall for it.A cloned voice of Ferrari's CEO and a deepfake of WPP's CEO both failed, and neither was stopped by a detector. Each was stopped by a person verifying something the impostor could not supply.
- Fraud storiesThe refund photos that do not fray right.Named retailers from Boll and Branch to Bogg are catching AI-generated damage photos in refund claims. The tell is physical, not pixel-level, and the EU labeling deadline that could have helped passed in August 2026.
- Fraud storiesWhen a 15-dollar AI ID passed a live exchange KYC check.The OnlyFake case is the cleanest documented example of an automated control being beaten by generative AI: a synthetic passport image cleared a crypto exchange's document verification.