AIPolicyTracker

AI incident ·

Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

41 news reports Snapshot 7 Sep 2026

In brief

An AI system built by Openai, Large Language Model Developers and 1 other and deployed by Yang Di, Waterplum and 31 others allegedly harmed Western Companies, Web3 and 22 others.

Risk domain
Malicious Actors & Misuse Fraud, scams, and targeted manipulation
Occurred
Coverage
41 reportsMay 2022 - Nov 2025

What happened

North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes

Laws that address this harm

Policy angle: Classified under Malicious Actors & Misuse (Fraud, scams, and targeted manipulation) in the MIT AI Risk Repository taxonomy; 5 recorded instruments address this use case.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (41)

Titles link to the original publisher; report text is not reproduced here.

  1. Publication of North Korea Information Technology Workers Advisory
    ofac.treasury.gov · United States Department of the Treasury, Office of Foreign Assets Control
  2. Charges and Seizures Brought in Fraud Scheme Aimed at Denying Revenue for Workers Associated with North Korea
    justice.gov · United States Department of Justice, Office of Public Affairs
  3. Staying a Step Ahead: Mitigating the DPRK IT Worker Threat
    cloud.google.com · Mandiant, Codi Starks, Michael Barnhart
  4. Arizona Woman Pleads Guilty in Fraud Scheme That Illegally Generated $17 Million in Revenue for North Korea
    justice.gov · United States Department of Justice, Office of Public Affairs
  5. Mitigate Rising Candidate Fraud Through Identity Verification
    gartner.com · Emi Chiba, Akif Khan, Hiten Sheth
  6. North Korea Stole Your Job
    wired.com · Bobbie Johnson

Who was involved

Alleged harmed party
Western Companies, Web3, Ssa, Social Security Administration, Recruitment Teams, Oleksandr Didenko, National Security And Intelligence Stakeholders, Macos Users, Jiho Han, Irs, Interviewees, Internal Revenue Service, Human Resources Staff, Hiring Managers, Haoran Xu, Epistemic Integrity, Employers, Developers, Cryptocurrency Platforms, Companies In The United States, Chunji Jin, Blockchain Projects, Andrew M., Targets Of Fraudulent Professional Opportunities

Classification (MIT AI Risk Repository taxonomy)

Causal entity
Human
Intent
Intentional
Timing
Post-deployment
Harm level
—
Sectors
—
Countries
—

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 4.3.

  • Cheating/plagiarism

    "Cheating/plagiarism - Use of another person’s or group’s words or ideas without consent and/or acknowledgement."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • IP/copyright loss

    "IP/copyright loss - Misuse or abuse of an individual or organisation’s intellectual property, including copyright, trademarks, and patents."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Financial and business

    "Financial and Business - Use or misuse of a technology system in a manner that damages the financial interests of an individual or group, or which causes strategic, operational, legal or financial harm to a business or...

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Impersonation/identity theft

    "Impersonation/identity theft - Theft of an individual, group or organisation’s identity by a third-party in order to defraud, mock or otherwise harm them."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Dehumanisation/objectification

    "Dehumanisation/objectification - Use or misuse of a technology system to depict and/or treat people as not human, less than human, or as objects."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Defamation/libel/slander

    "Defamation/libel/slander - Use of a technology system to create, facilitate or amplify false perception(s) about an individual, group, or organisation."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Misinformation and Manipulation

    "Recent studies have demonstrated that LLMs can be exploited to craft deceptive narratives with levels of persuasiveness similar to human-generated content (Pan et al., 2023b; Spitale et al., 2023), to fabri- cate fake n...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Cybersecurity

    "LLMs may exacerbate cybersecurity risks in various ways (Newman, 2024). Firstly, LLMs may significantly amplify the effectiveness of deceptive operations aimed at tricking people into disclosing sensitive information or...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

Incidents in the same risk subdomain

All incidents in this subdomain

Source record: incident #1118 on the AI Incident Database · all 41 reports