What question should British employers answer?
The useful question is not whether a video applicant looks convincing. It is whether the organisation can establish that the same verified person applied, received the equipment, performs the work and remains where they claim to be. The Times reported on 25 July that more than 700 suspected North Korean applicants had sought remote roles at a large unnamed UK bank in one month. The recruitment company Alfa AI said its screening system linked applications through repeated language, shared device characteristics, manipulated video and inconsistent location data. The bank has not been identified and the attribution has not been confirmed in a public government notice, so those details should be treated as a reported incident rather than an independently established breach.
The underlying UK warning is official
The broader risk does not depend on that single report. The National Cyber Security Centre says British firms are almost certainly being targeted by IT workers from the Democratic People’s Republic of Korea who disguise themselves as third-country freelancers to generate revenue for the regime. HM Treasury’s Office of Financial Sanctions Implementation describes the use of false identities, aliases, proxy infrastructure, remote-desktop tools and helpers who may knowingly or unknowingly support the arrangement. A company can therefore face more than poor recruitment. It may give an untrusted operator access to code, customer data and internal systems while making payments that create sanctions exposure.
AI removes familiar warning signs
Microsoft Threat Intelligence has observed North Korean workers using face-swapping tools to place their images into stolen identity documents and professional profile pictures, and voice-changing software during interviews. Generative tools can also improve CVs, translate answers and help one operator maintain several plausible personas. That does not mean every remote candidate or imperfect video call is suspicious. It means accent, writing style and visual intuition are weak controls. Employers need evidence that connects identity, device, location, payment and work activity without creating blanket discrimination against legitimate overseas applicants.
Build one control chain before day one
OFSI recommends reputable hiring platforms with robust verification, video interviews, checks that equipment can be received at the address on identity documents, monitoring of remote-worker IP addresses and caution around remote collaboration software. Those checks should feed a single risk decision shared by recruitment, security and payroll. Company equipment should be enrolled before use, privileged access should be exceptional, and a new starter should receive only the repositories, environments and customer records required for the role. A local laptop address is not proof of a worker’s location: US prosecutions show how facilitators have operated laptop farms so overseas workers appeared domestic.
Design for detection after hiring
A point-in-time identity check cannot carry the whole burden. Organisations should look for impossible travel, unexpected remote-control software, concurrent logins, unusual code access, payment changes and repeated use of the same device or contact details across candidates. Any concern needs a defined route to security, HR and sanctions specialists before accounts or evidence are removed. The aim is not surveillance of ordinary staff. It is continuity between the person approved, the device trusted and the access actually used. Remote hiring remains valuable; treating it as part of the cyber perimeter makes it safer.
UK TECH TRENDIndependent analysis for the British technology market.
Continue to all articles

