Fake Hires, Real Threats: When Background Checks Aren't Enough
Mabel Soe
BSidesSF 2025 — Here Be Dragons · Day 1 · Main
Overview
North Korean IT workers have been systematically infiltrating tech companies — including small startups — by constructing elaborate fake identities, passing background checks with stolen U.S. citizen credentials, and funneling salaries back to fund weapons programs. Mabel Soe drew on her experience at Clockwise to walk through real detection patterns, the hiring biases that let these candidates through, and a layered set of mitigations that teams can implement without waiting for a security budget approval. ---

Key moments
- 2:33 FBI/Treasury advisory: North Korean IT workers infiltrating US companies since 2022
- 3:22 Attack method: fake candidates use stolen US citizen identities to pass background checks
- 4:05 Network revelation: entire ecosystem of fake identities giving each other references
- 5:20 Motive: hired fake employees funnel salaries to fund North Korean weapons program
- 6:50 Clockwise case: engineering manager detects suspicious interview behavior
- 7:52 Investigation: Zoom logs reveal candidates joining from Russian and Pakistan IPs
- 8:21 Response: Zoom geo-blocking and removing specific sourcing integration stopped flow
- 9:08 Red flags walkthrough: fake resume patterns including 404 GitHub and front companies
Fake Hires, Real Threats: When Background Checks Aren't Enough
Speaker: Mabel Soe
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch the full talk
Reading time: 8 minutes
TL;DR
North Korean IT workers have been systematically infiltrating tech companies — including small startups — by constructing elaborate fake identities, passing background checks with stolen U.S. citizen credentials, and funneling salaries back to fund weapons programs. Mabel Soe drew on her experience at Clockwise to walk through real detection patterns, the hiring biases that let these candidates through, and a layered set of mitigations that teams can implement without waiting for a security budget approval.
Introduction
The phrase "fake it till you make it" has a particular resonance in the tech industry. What Mabel Soe explored at BSidesSF 2025 is what happens when that ethos is industrialized as an intelligence operation: an organized network of fraudulent candidates, complete with fabricated identities, stolen credentials, front companies, and mutual cross-references, all designed to place operatives inside target organizations and extract both money and data.
The scale of the problem became publicly visible in May 2022, when the U.S. Departments of State and Treasury and the FBI issued a joint advisory warning about North Korean IT workers systematically targeting cryptocurrency companies. Subsequent advisories broadened the scope — effectively any company is now a potential target. The KnowBe4 incident of July 2024, in which a threat actor passed multiple interview rounds, a background check using a stolen U.S. citizen's identity, and reference checks before being hired, served as the case study that crystallized how far the technique had advanced.
Soe, who works in GRC and has held roles spanning internal audit, engineering, and legal teams, framed her talk around a central misconception: "There is a common misconception that this is only impacting Fortune 500 companies, really large organizations where you can really get lost in the numbers. No. This is happening even with two-person companies."
How the Operation Works
▶ Watch: The mechanics of fake candidate campaigns (05:30)
The attack pattern has several phases, each of which exploits a different gap in the standard hiring process. The first step is identity construction. Fraudulent candidates may use entirely fabricated names and profiles, stolen U.S. citizen information, or a hybrid approach in which a legitimate developer handles the technical interview rounds — video calls where the real skill is assessed — before being switched out once an offer is extended. This explains how candidates who appear technically competent in interviews can underperform once on the job.
Once inside, the personas operate as a coordinated network. They give each other references, register front companies that appear in work histories, and apply to roles automatically using bots that submit applications as soon as positions are posted. AI has made the application phase nearly frictionless.
Once hired, the activity follows a predictable pattern: downloading remote administration tools, VPN-ing into company environments to appear U.S.-based, working night shifts to simulate U.S. business hours, and exfiltrating company data. Paychecks are funneled back to the North Korean government. "Your organization is paying them to exfiltrate company data," Soe summarized.
What Clockwise Actually Encountered
▶ Watch: The Clockwise case study (10:15)
Soe shared specific incidents from her time at Clockwise, a company of around 50 people at the time — small enough that each hiring decision was visible and unusual enough to raise flags when something was wrong.
The first signal came from an engineering manager who flagged a call as "really off." Multiple people seemed to be present in the background, video latency was excessive, and the candidate asked pointed questions about where employees lived — framed not as a curiosity about remote work culture but as a request for specific geographic information. When the security team pulled Zoom logs for that interview, the call had originated from a Russian-based IP address. Expanding the analysis to other interviews flagged by engineering managers revealed additional calls originating from Pakistan and Spain.
Two mitigations followed immediately: Zoom geo-blocking to prevent calls from unexpected regions, and the removal of a third-party sourcing integration in Greenhouse — specifically Wellfound (formerly AngelList) — which turned out to be the primary channel through which fake candidates were arriving. "That actually brought down a lot of the fake hiring candidates," Soe confirmed.
Soe also walked through two illustrative resume profiles. "Hannah" had a GitHub URL that returned a 404 and a listed employer whose website looked legitimate at first glance — testimonials, polished design — but was registered with a non-U.S. address and had only two employees on LinkedIn. "Sophia" had minor discrepancies between the email on her resume and the one used for scheduling, and after geo-blocking was implemented, simply failed to join her interview and sent a suspicious follow-up email. "That was only proof that this person was fake," Soe noted.
Red Flags and Hiring Biases
▶ Watch: Patterns and bias considerations (17:00)
Soe catalogued the signals that appear across fraudulent candidate profiles, covering the full arc from application through onboarding:
- LinkedIn profiles that are new (joined within the past five days or month), look generic, or disappear when the candidate is challenged
- VoIP phone numbers (though Soe was careful to note these are not reliable indicators on their own)
- Resume batches with overlapping universities, locations, and employer names
- During interviews: resistance to appearing on camera, excessive lag, background filters, background noise, difficulty with casual conversation, and AI-assisted pauses before giving scripted answers
- Post-hire: laptops being shipped to addresses that don't match stated location, requests to redirect hardware to "emergency" addresses, and remote admin tools appearing in activity logs
She also devoted significant time to the risk of over-correction. The advisories from Mandiant and government agencies note that signals like Americanized names with unexpected accents can be indicators — but Soe was direct: "Race or accent is not an indicator of a threat." The U.S. Civil Rights Act prohibits hiring discrimination based on nationality or race, and the legitimate signals (behavioral inconsistencies, technical anomalies, documentation discrepancies) need to be disentangled from demographic features that say nothing about intent.
"It's easier to almost like spot anomalies in a log," Soe observed. "People are complex. They're nuanced. People are shy, awkward."
Mitigation Tactics
▶ Watch: Layered mitigations across the hiring funnel (21:45)
Soe organized her mitigations by stage in the hiring process. At the pre-screening and application phase: long-form questions requiring specific, personalized answers; checking GitHub contribution activity for developer roles; phone carrier lookup tools to screen for VoIP or stolen numbers; and hidden instruction fields — some smaller organizations embed instructions like "include the word 'pineapple' in your application" to identify bots or AI-generated submissions.
During interviews: starting with video, not phone screens; asking location-specific casual questions ("what's your favorite coffee shop?"); empowering interviewers to end calls without confrontation using soft scripts like "I need to follow up with my recruiting team" rather than directly accusing anyone.
For onboarding: in-person laptop pickup, or shipping to a local delivery service for identity verification at pickup; reconciling submitted personal information with payroll and HR records; and enhanced monitoring for new joiners with a defined baseline of expected first-week activity.
Soe also recommended working with talent and recruiting teams before implementing changes. Recruiters are under pressure to fill roles quickly and may not be aware of the security context for each check. "You need to understand the trade-offs and the constraints. It is a very big waste of time, energy, and budget."
During the Q&A, she confirmed that the Wellfound integration removal produced a significant reduction in fake candidate volume — enough that the team was no longer on edge during every interview. Most remaining fake candidates were caught at the pre-screening stage.
Notable Quotes
"These folks are exfiltrating company data and your organization is paying them to do it."
— Mabel Soe
"There is a common misconception that this is only impacting Fortune 500 companies. No. This is happening even with two-person companies."
— Mabel Soe
"Race or accent is not an indicator of a threat, and we should really be careful of that."
— Mabel Soe, on the risk of hiring bias in the detection process
Key Takeaways
- Small companies are not exempt. The North Korean IT worker program targets any organization, including 50-person startups. Soe confirmed encounters at Clockwise and noted that attendees with a 1,600-person company had already found three fraudulent hires — including one who committed code.
- Third-party sourcing integrations are a high-risk channel. Removing a single sourcing integration from their ATS (Wellfound/AngelList) dramatically reduced fake candidate volume at Clockwise. Review which integrations feed your pipeline.
- Technical signals exist at every stage. From 404 GitHub links and mismatched email addresses to Zoom IP mismatches and remote admin tool downloads, the indicators are present — but they require someone to look.
- Empower interviewers without putting them on the spot. Providing soft exit scripts ("I need to follow up with my recruiting team") lets interviewers end suspicious calls without direct confrontation, reducing hesitation.
- Hiring processes must evolve continuously. The tactics used by fraudulent candidates adapt — AI-assisted interviews, different routing channels, persona variations. No single fix is permanent; the controls need to evolve alongside the threat.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Soe came with real incidents, real red flags from real candidates, and the institutional courage to say out loud that race and accent are not indicators. The Wellfound integration removal reducing fake candidate volume dramatically is the most operationally valuable single data point in the talk. Small companies think they're immune. They aren't.
Heather Calloway (CISO) — STRONG ACCEPT
North Korean IT worker infiltration is happening at two-person companies, not just Fortune 500 organizations. Soe's documentation of what it actually looked like at Clockwise — specific red flags, specific detections, specific mitigations that worked — is more valuable than the advisory documents because it tells you what to look for in practice. The bias warning is the part that makes this responsible rather than reckless.