TLDRocket
Sign in

Half of remote IT job applications now carry North Korean fraud patterns, startup Endorsed finds

Fortune Amanda Gerut

Endorsed says half of remote IT job apps now show North Korea fraud signs. The fake workers keep using the same dull names, schools and cities because it works.

Based on reporting by Fortune, Amanda Gerut — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

A San Francisco startup that screens job candidates says North Korean fraud has gotten a lot harder to miss in remote IT hiring. Endorsed, co-founded by CEO David Head and CTO Kevin Fu, says applications with patterns linked to the scheme rose from 11% of U.S.-based remote IT applications in the third quarter of 2024 to 44% a year later. For the most recent quarter, the company estimates the share hit 47%.

The firm got there by reviewing more than 11 million applications, then digging into a 175,000-application sample from 2026 across U.S. companies with anywhere from three employees to more than 25,000. Endorsed says the flagged applications matched mid- to high-risk patterns tied to North Korean operatives posing as IT workers. The UN has said those workers are forced to send earnings into Kim Jong Un’s nuclear weapons program.

What’s striking is how ordinary the disguises look. Texas was the most common claimed origin among flagged applications at 26.5%, followed by California at 14.4% and Florida at 7.2%. Dallas, Austin and Houston showed up again and again as supposed hometowns. The most common fake schools were the University of North Texas and UT Austin, with the University of Central Missouri and UT Dallas also popular. Amazon, Google and Meta were the top claimed employers, and more than half of the suspicious profiles included a LinkedIn page.

Head’s point is that none of those details is supposed to trigger alarm on its own. The problem is the pattern around them. Endorsed says its system also checks devices, networks, documents and behavior, with a human signing off before a decision is made. That matters because, according to the company, North Korean operatives have already slipped into hundreds of U.S. companies over the past several years, and American facilitators have helped them do it. A New Jersey facilitator was sentenced to nine years in prison in April for a ring that placed operatives inside more than 100 U.S. companies.

The timing is awkward for security startups, because venture money is getting stingier. PitchBook says cybersecurity funding was flat at $8.5 billion in the first half of 2026, while deal count fell 23.8%. In that kind of market, tools that merely spot a checklist of fraud clues may not be enough. Endorsed is betting that deeper screening still has room to sell.

My take — AI-written commentary, not fact-checked reporting

This is the kind of scam that thrives on corporate boredom. If a hiring stack can’t see through a parade of Michaels from Dallas with Stanford energy and LinkedIn polish, the problem isn’t just fraud — it’s lazy trust. The bigger tell is how much modern security still depends on people pretending patterns are personalities.

Read more about this at: Fortune

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.