Recorded Future’s PurpleDelta research shows how fabricated identities, AI-assisted interviews and remote-access facilitators can turn recruitment into the route to legitimate internal access. Recruitment intelligence has to move upstream, connecting identity assurance, digital risk intelligence and security controls before access is granted.
Recruitment is usually discussed as the route into employment. A report from Recorded Future shows how it can also become a route into an organisation’s systems.
In its August 2026 report on PurpleDelta, Recorded Future’s Insikt Group describes clusters of North Korean IT workers using fabricated identities to pursue remote technical roles. One cluster applied to more than 1,100 companies. The researchers identified at least 22 false personas, some supported by AI-generated profile images, custom ChatGPT assistants and illicitly sourced identity documents. Operators were applying for at least 60 jobs a day and, Recorded Future assesses, were highly likely to be working at ten or more organisations.
The figures are striking. The route from application to access matters even more.
Once a fabricated candidate was hired, the employer could issue the account, send the laptop and invite the individual into internal meetings. Access did not need to be stolen at the outset. It was granted through a recruitment process that had accepted the wrong person as the right one.
From false candidate to authorised insider
The Recorded Future report documents an operation built to survive the checks employers already use.
Personas were developed across professional and freelance platforms. Some used purchased identities and accounts. The researchers also observed efforts to fake a GitHub contribution history. Custom AI assistants maintained backstories and generated interview answers in character. During video calls, operators could transcribe a question, put it into ChatGPT and repeat the answer. A separate AI workflow tailored CVs to particular jobs.
The deception did not stop when the interview ended. Facilitators in the country where a worker claimed to be based received company equipment, installed remote-access software and maintained the device. This allowed an operator elsewhere to work through a machine whose physical location appeared consistent with the invented story.
Recorded Future says operators recorded internal meetings after gaining employment. In one session, a single operator maintained the email and Slack accounts of one employed persona while interviewing under another identity elsewhere. The report also describes personal devices and accounts, coordination through Telegram and other people helping to complete work.
This is insider risk in a particularly clear form. An organisation has authorised access, but the individual exercising it is not the individual it believes it hired. The resulting exposure can include proprietary code, internal communications, sensitive data and privileged systems.
The report is an intelligence assessment, and its probability language should be read as such. It is also part of a wider body of official warning. In September 2024, the UK’s Office of Financial Sanctions Implementation said it was almost certain that UK firms were being targeted by North Korean IT workers using false personas, proxies and remote-access tools. In January 2025, the FBI said it had observed North Korean IT workers using unlawful company access to exfiltrate sensitive data and, in some cases, extort employers. The FBI also warned that AI and face-swapping technology were being used during video interviews.
The threat is real, adaptive and capable of exploiting the gaps between recruitment, HR and cyber security.
Why familiar checks can miss the pattern
Identity checks, right-to-work checks, employment verification, references and criminal-record checks remain essential. They answer different questions, and no single one resolves the whole risk described in the report.
A document may be forged or may belong to a real person whose identity has been bought, borrowed or stolen. A video interview confirms that someone appeared on screen, but AI tooling and a proxy interviewee can weaken what that proves. A convincing CV may use real employers and plausible projects while the claimed work history remains false. A company laptop may arrive at the declared address, yet be controlled remotely by somebody in another country.
Many of the warning signs are also innocuous when viewed alone. A candidate changes a payment account. A new starter asks to use a personal device. A developer connects through a VPN. An address changes shortly before equipment is dispatched. None of these facts automatically proves wrongdoing.
The pattern becomes visible when the information is joined, which is where organisational design often fails.
Recruitment sees the CV and interview. HR holds the identity documents and address. Finance receives the payment details. IT sees logins, remote-access software and device location. Procurement may hold the contract with a staffing provider. Each team can complete its own task while nobody owns the combined risk.
The weakness sits upstream. By the time a conventional background check begins, a prepared operator may already have built a coherent identity, supporting documents, professional accounts and an AI-assisted interview method.
For roles where access could cause serious harm, recruitment intelligence should start before onboarding. Define the required assurance when the role is designed, check for repeated CV content or contact details during application review, resolve identity at shortlisting, and verify key history independently before final appointment, equipment or credentials. The scrutiny should follow the risk attached to the role, with a clear purpose and a fair process.
How DRS supports upstream recruitment intelligence
Digital Risk Screening, or DRS, can contribute to this upstream assurance at the identity and intelligence layer.
At Safehire.ai, DRS starts with a small set of declared identifiers, such as a name, email address, telephone number and address. Identity resolution can connect those details to possible usernames, aliases, other contact details and associated accounts. Relevant information from lawful public, commercial, surface, deep and dark-web sources can then be assessed against a defined risk purpose. A human analyst reviews potential findings before they are reported.
Applied to a high-trust remote hire, this approach may help surface matters that deserve closer examination:
- the same contact detail or username appearing across apparently different identities;
- a declared identity that does not fit the wider digital footprint;
- links to exposed credentials, illicit identity or account-brokering activity;
- associations with hacking or criminal crypto activity; and
- relevant links to a known threat actor or infrastructure, where appropriate threat-intelligence data is within the service’s scope.
The value lies in turning disconnected identifiers into evidence a trained person can examine. A plausible application may look less coherent once its contact details, usernames, accounts and history are considered together.
DRS still has firm boundaries. It does not authenticate a government document, establish a right to work, verify a qualification directly with an institution or detect unauthorised remote-control software on a company laptop. It cannot guarantee that a candidate is safe. A search with no relevant finding means only that no relevant signal was identified within the sources, categories and time covered.
A potential finding should start a review, not decide its outcome. The employer may need authoritative evidence, a repeated identity check, direct verification of history or input from HR, security and legal colleagues. The individual should have a fair route to correct mistaken identity or inaccurate information, subject to any lawful investigation requirements.
Used in this way, DRS does not replace established checks. It gives them a broader intelligence context and can help an organisation spot contradictions before trust is converted into privileged access.
Build a connected chain of controls
PurpleDelta crosses several organisational boundaries, so the response must do the same. Five disciplines would materially improve the position.
1. Apply enhanced assurance where access creates serious consequence
Start with the role, avoiding nationality or a crude candidate profile. Remote developers, system administrators, finance staff, data specialists and contractors may receive access to sensitive data, code, payments or operational systems. Define the roles that justify enhanced identity and digital due diligence, and document why.
This keeps the process proportionate. It also avoids turning a genuine security threat into discriminatory suspicion of candidates who have overseas backgrounds, accents or remote-working needs.
2. Verify independently
Verify employment and education directly with the organisation concerned. Use accredited routes for right-to-work checks. Examine identity documents for authenticity and confirm that bank, contact and delivery information belongs to the same person. The candidate’s story should not rest entirely on candidate-supplied evidence.
The FBI recommends checking internal recruitment records for repeated CV content and reused contact details. This is a basic control with real value when one operator may be managing several personas.
3. Join recruitment data to security data
Decide in advance which changes or technical events require a joined review. Examples include an unexplained address change before equipment delivery, a request to use a personal device, a payment account in another name, geographically inconsistent logins, prohibited remote-access software or contact details shared with another applicant.
Security should not have to infer the recruitment story from an IP alert. HR should not assess a changed address without knowing that the device is connecting through an unexpected remote-control tool.
4. Control the device and the access
Send equipment to the verified individual at a corroborated address, with appropriate confirmation of receipt. Restrict unauthorised remote-management tools and investigate unexpected connections. Apply least privilege from the first day, then review access as responsibilities develop.
These controls limit the damage even when recruitment assurance fails. They also help distinguish a malicious operator from an employee whose account or device has been compromised.
5. Give the pattern an owner
A named risk owner should bring together recruitment, HR, IT, finance, procurement and relevant threat intelligence. The operating plan should state who can pause onboarding, protect evidence, review access and escalate a concern.
Screening must be lawful, transparent and proportionate. Sources and risk categories should be defined before a search begins, sensitive or irrelevant material should be filtered, and employment decisions should remain with accountable people. For higher-risk processing, data protection and equality impacts need proper assessment.
Test whether you know who has access
PurpleDelta is an unusually organised and state-directed example, but the control failure is easy to recognise. An organisation accepted a candidate’s presented identity, then built trusted access on top of it.
Take one remote employee or contractor with privileged access and reconstruct the evidence behind four statements:
- the person who attended the interview is the person named in the identity record;
- their employment and education history was verified independently;
- the company device was received and is controlled by that person; and
- their account activity is consistent with the expected person, device and location.
Record which team owns the response if one statement can no longer be supported. Then check whether your screening provider, staffing partner and internal controls are designed for fabricated personas, reused identifiers and remote-access facilitation, rather than yesterday’s simpler form of CV fraud.
The practical control point sits upstream. Before a high-consequence candidate reaches final appointment, equipment dispatch or account creation, recruitment, identity and security evidence should have been considered together by a named owner.

-2025.png)
.png)
.png)
.png)




.png)
.png)