{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"},"incident":{"title":"North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs","date":"2025-08","date_precision":"month","victim_org":"US Fortune 500 technology companies employing fraudulent remote workers","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.","outcomes":["Insider Access","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.","how_it_worked":"The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.","lessons":"Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"}}