Skip to content
NetarxImpact Database
Fake IT Worker InfiltrationConfirmed AI-enabledReported

North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs

US Fortune 500 technology companies employing fraudulent remote workers · Technology · United States · August 2025

What happened

In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.

How the deception worked

The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.

AI involvement · Confirmed AI-enabled

Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.

The control that would have caught it· our reading, not a claim from the sources

Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.

Sources (2)

  1. Detecting and countering misuse of AI: August 2025
    Anthropic·anthropic.comOpen ↗
  2. Anthropic threat intelligence report, August 2025 (PDF)
    Anthropic·www-cdn.anthropic.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.