A year-long investigation by The Wall Street Journal, titled 'Infiltrated: North Korea’s Secret U.S. Workforce', has revealed systematic deception across the US remote labor market. North Korean IT specialists are heavily relying on modern generative AI tools to secure well-paying remote positions at American companies using stolen or fabricated identities. The earned salaries, estimated at up to 800 million US dollars, are mostly funneled directly to the regime in Pyongyang.
Generative AI plays a decisive operational role in this organized infiltration effort. According to the investigation, covert cells use AI tools to mass-produce tailored resumes and application packages. Individual cells have submitted more than 1,000 customized applications in a three-month span, effectively overwhelming automated HR screening pipelines at Western firms.
Language models also give the operatives an illicit edge during subsequent live interviews. Candidates deploy real-time LLM assistants and pre-scripted prompts during technical video calls. These tools feed the candidates instant, accurate coding solutions and technical answers, allowing them to pass complex live coding assessments without raising immediate suspicion.
The revelations carry significant implications for corporate security policies and human resources departments. Following warnings from the FBI and the published findings, American cybersecurity and recruitment firms are tightening candidate verification protocols. Fully automated digital screenings are no longer considered adequate against advanced AI deception.
In response, employers are introducing strict measures, including hardware-backed identity verification and mandatory in-person onboarding steps. These policies aim to neutralize synthetic video feeds and automated prompt assistance. The investigation highlights a sophisticated shift in how state-backed actors exploit generative AI to bypass international sanctions and penetrate corporate infrastructure.

