Fake North Korean IT workers sneaking into healthcare, finance, and AI
https://www.theregister.com/2025/09/30/north_korean_it_workers_okta/
The North Korean IT worker threat extends well beyond tech companies, with fraudsters interviewing at a "surprising" number of healthcare orgs, according to Okta Threat Intelligence.
In research published Tuesday, the identity services provider said nearly half of the companies (48 percent) targeted by the scam fall outside the IT sector, and fraudsters are increasingly applying for remote jobs in finance, healthcare, public administration and professional services.
These scammers largely originate from North Korea - or at least funnel money back to Pyongyang after fraudulently obtaining a remote worker job, generally in a software development role.
. . .
Unsurprisingly, fraudsters are also interviewing for financial-sector roles, including traditional banks and insurance firms, plus fintech and cryptocurrency organizations.
"The roles targeted have expanded beyond software development to include back-office and financial processing roles in areas like payroll and accounting," Okta says. "This shift indicates an understanding on the part of the DPRK that there are other types of tasks, beyond software engineering, that provide similar opportunities: a targeted entity must be prepared to hire remotely, and a DPRK knowledge worker must be able to demonstrate some level of competency to perform it." ®