The answer lives in this podcast
North Korea orchestrated a large-scale operation in which fraudulent software engineers applied to legitimate jobs at banks, insurance companies, and tech firms using AI-mediated hiring systems, conducted fake video interviews, accepted positions, performed some coding work while collecting salaries, and funneled all earnings back to the North Korean government. This scheme exploited the speed and automation of AI recruiting tools, exposing a critical security and identity verification gap in modern hiring processes.
According to reporting covered in The Josh Bersin Company podcast, the Wall Street Journal revealed this operation after investigating hiring anomalies at several major organizations. The fraudsters were not American citizens and did not match the identities they claimed, yet they successfully passed initial AI screenings and automated resume filters that typically reject candidates at scale.
The vulnerability lies in how AI hiring systems prioritize volume and speed over identity authentication. As Josh Bersin explains in the episode, employers have built massive recruiting infrastructure to handle 20 to 30% of Americans changing jobs annually—a high-volume churn that forces companies to automate screening and initial selection. Video interviews, which many organizations use as a first-pass human touchpoint, proved insufficient to catch the deception.
This case also intersects with a broader problem discussed in this podcast analysis of AI recruiting: recruiters report being flooded with AI-generated and fraudulent resumes. When legitimate candidates use ChatGPT to write resumes and fraudsters use the same tools to craft fake profiles, AI systems struggle to distinguish real from fake at scale.
The cost of hiring has risen dramatically—$5,000 to $10,000 or more for skilled roles, and up to one-third of first-year salary for senior engineers—yet companies rushed to automate the process without reinforcing identity verification. The North Korean operation succeeded precisely because AI hiring tools were designed to move candidates quickly through funnels, not to authenticate who they really are.
Traditional resume screening—parsing job titles, skills, experience dates—works on the assumption that the resume belongs to the person submitting it. AI tools trained on legitimate job applications have no pattern to flag a coordinated state-sponsored fraud ring impersonating engineers.
Video interviews added a layer of apparent human verification, but without background checks, reference verification, or rigorous identity confirmation before onboarding, the system remained porous. Companies prioritized speed and candidate experience over friction, creating an opening fraudsters exploited.
"We have AI creating resumes and producing and sending them out and AI consuming them — slop talking to slop — and the recruiters constantly tell us they're getting so flooded with fraudulent resumes that they really can't sort through it all."
Josh Bersin — Global Industry Analyst & CEO, The Josh Bersin Company. A leading expert in talent acquisition, HR technology, and enterprise workforce strategy, Bersin has advised Fortune 500 companies and conducted extensive benchmarking on recruiting costs, AI adoption, and hiring process design across industries.
Research by computer scientists examining hundreds of resumes found that AI recruiting tools using ChatGPT are significantly more likely to accept resumes also written with ChatGPT compared to those written by hand or with Claude or Gemini.
After ChatGPT emerged, hundreds of tools and startups began offering AI-based recruiting and matching systems, making previously expensive proprietary capabilities accessible and commoditized across the industry.
New York State, Illinois, and several other jurisdictions passed laws requiring companies to prove that their AI scoring or inference technology does not exhibit bias or discrimination in hiring decisions.