In July 2024, the security-awareness company KnowBe4 hired a remote software engineer who turned out to be a North Korean operative running a stolen US identity and an AI-augmented photo. The persona cleared a background check, reference checks, and four video interviews, and was caught only when the company laptop began loading malware. The verification that failed was remote identity screening, part automated, part human, and one operator runs many such synthetic personas at once.
What happened at KnowBe4
KnowBe4, a company whose entire product is teaching other organizations to spot social engineering, hired a software engineer for its internal IT team in July 2024. The engineer was a persona operated by a North Korean threat actor. KnowBe4 published the account itself, in a post detailing exactly how the hire cleared its process.
According to KnowBe4 and to CyberScoop's reporting, the persona used a valid identity stolen from a US-based person, and it passed the background check and reference checks that identity supported. The photo on the application was a stock image altered with AI to match the stolen identity. The persona then sat for four video-conference interviews and was hired.
Nothing in the screening caught it. What caught it was the hardware. On July 15, the day the shipped Apple laptop was received, it began loading malware, which KnowBe4's own security operations flagged immediately. The machine was traced to an IT mule laptop farm, a US address where a facilitator keeps company-issued laptops online so the overseas operator can work through them. KnowBe4 reported no data breach and no exfiltration.
Not one hire, an industry
The KnowBe4 hire is one visible instance of a state-run program. As Dark Reading documents, thousands of North Korean IT workers apply for remote roles at US and European companies using multiple fabricated identities, collect paychecks that fund the regime, and continue until they are discovered and removed. A single operator commonly runs around a dozen personas and applies to hundreds of jobs.
Deepfakes make the volume work. Real-time face replacement lets one operator interview for the same role repeatedly behind different synthetic faces, which both multiplies throughput and keeps any single face from being catalogued and circulated in security bulletins. The synthetic identity is not a flourish on the attack. It is the mechanism that lets the attack run at scale.
What actually got bypassed
Separate the two things that failed, because they are different failures. The background check and reference checks are a largely automated control: feed them a valid identity and they return a pass. They returned a pass, because the identity was real, just stolen. The four video interviews are a human control: a person on a call judging whether the face and story hold up. The people were convinced.
This is the distinction that matters. A human interviewer being convinced is social engineering, and it scales only as fast as you can staff interviews. An automated identity check accepting a synthetic or stolen input is a defeated control, and it scales at the speed of an API, for as many applications as an operator wants to file. The North Korean program exploits both at once: a real stolen identity to clear the machine, an AI-augmented face to clear the human.
The lesson generalizes the way it does across synthetic-media fraud. The question is never whether the face on the interview looks real. It is whether the check reads a property the operator cannot supply. A stolen identity supplies the document. An AI photo and a real-time face-swap supply the face. Both are exactly the failure mode our detector benchmark documents, where controls that score well on clean inputs collapse once the input is adversarial.
What this means for hiring platforms
If your platform or your employer relies on remote identity verification and a video interview to establish that a candidate is who they claim, this is your threat model, not a curiosity about one company. Document-plus-selfie identity checks and live-interview liveness (the automated test that a face on camera is a real, present person rather than a replayed or synthetic stream) are precisely the controls this program is built to defeat.
You cannot tell from a datasheet whether your specific deployment returns a pass on a current-generation face-swap or an injected video stream. Vendor results age; the tooling does not wait. The only honest answer is a measured one, against your control, with current attacks.
Margen does not sell identity verification or detection. We are an independent third party that red-teams these controls under adversarial, platform-realistic conditions and reports, with a number and a margin of error, where they hold and where they break.