Endorsed CEO: North Korean fraud now 44% of remote IT job applications
A fourfold jump in fake applicants is forcing hiring teams to rethink identity checks as cybersecurity funding cools.

Endorsed CEO David Head shared data showing North Korean-linked fraud patterns in remote IT job applications jumped from 11% to 44% in a year. The surge underscores the need for identity verification beyond resumes as VC funding for cybersecurity tightens.
The number is stark: 44% of remote IT job applications now carry fraud patterns linked to North Korean operatives, up from just 11% a year earlier. That's the finding Endorsed CEO David Head shared exclusively with Fortune, based on an analysis of 175,000 job applications across U.S. companies ranging from three to 25,000+ employees. The data covers all role types, but the concentration is highest in remote software engineering positions - exactly where a fake identity can do the most damage before anyone notices.
The patterns are eerily specific. Fraudulent applicants disproportionately claim to be from Texas (26.5%), California (14.4%), and Florida (7.2%), with Dallas, Austin, and Houston as top cities. They favor universities like the University of North Texas, UT Austin, University of Central Missouri, and UT Dallas. They list past employers including Amazon, Google, Meta, Capital One, CVS Health, Microsoft, and Stripe. They go by names like Sai, Michael, David, and Kevin. More than half even include a LinkedIn profile. As Head put it, the scammers pick familiar details because it offers camouflage - but the pattern itself is the tell.
This isn't just a hiring nuisance. The UN has documented that North Korean IT workers are forced to pose as Americans to funnel earnings into the regime's weapons programs. The threat is real enough that a New Jersey facilitator was sentenced to nine years in prison in April for running a ring that placed operatives inside more than 100 U.S. companies. For executives, the implication is uncomfortable: your remote engineering team may already include someone who isn't who they claim to be, and traditional background checks are not catching them.
The funding environment, meanwhile, is sending mixed signals. PitchBook's Q2 2026 cybersecurity report shows VC funding flat at $8.5 billion for the first half, with deal count down 23.8%. The second quarter's $3.8 billion across 165 transactions was the most tepid since the end of 2024. Security operations led on deal count with 47 transactions worth $1 billion, but identity and access management (IAM) funding shriveled from $0.8 billion in Q1 to $0.3 billion in Q2. PitchBook attributes much of the pullback to fears that AI-native security startups will lose their luster to frontier models like Anthropic's Mythos. Yet PitchBook remains bullish on IAM, noting that nonhuman identities now outnumber humans roughly 45 to 1 in typical enterprises.
Endorsed sits at the intersection of recruiting tech and cybersecurity - what Head calls "an emergent category." Its model deliberately looks past biographical details to examine devices, networks, document signals, and behavior patterns, with a human required to sign off on every decision. The approach is a direct response to the failure of checklist-based screening. When Head's own co-founder and CTO, Kevin Fu, turned out to match several of the fraud patterns - he grew up in a Dallas suburb, went to UT Austin, and spent most of his career at LinkedIn, owned by Microsoft - Head couldn't resist pointing it out. "We've scanned him with Endorsed though," Head joked, "and I can verify that he is legitimate."
The strategic stakes for every CEO and CTO are clear. Remote hiring is not going away, and neither are the fraudsters. The 44% figure is a wake-up call that the old resume-and-interview process is no longer a reliable gatekeeper. Companies that fail to adopt identity verification tools - especially those that combine device, network, and behavioral signals with human judgment - are leaving the door open to state-sponsored infiltration. At the same time, the pullback in IAM funding suggests the market is underestimating the threat. For decision-makers, the message is simple: verify before you trust, and invest in the tools that make verification possible. The cost of a single bad hire in a sensitive IT role can dwarf the price of a robust screening platform.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business
Amazon Prime Air 767 overshoots Miami runway, killing at least 5
The Boeing 767 freighter from San Juan struck vehicles and erupted in flames, prompting a ground stop and a fresh NTSB investigation into Amazon's air cargo network.
Death sentence for TV presenter Sarah Khalifa: Egypt's drug case hits media
The sentencing of Sarah Khalifa and 11 others underscores the severity of Egypt's anti-drug laws and the exposure of public figures to capital punishment.
Tim Cook steps down as Apple CEO, stays on as chair with $45M equity
The 'Trump whisperer' keeps his White House and Beijing access as Apple navigates tariffs and a $4.6 trillion market cap.




