Eleven governments named the same failure mode on the same day: the video interview is no longer proof of identity. On July 31, the US, Japan, and South Korea were joined for the first time by France, Germany, Italy, and the Netherlands on a joint advisory saying North Korean IT workers are now passing live job interviews with real-time deepfake video, not the pre-recorded loops or static photo swaps that liveness detection was actually built to catch.

The mechanism is worth sitting with, because it’s not the crude version most people picture when they hear “deepfake.” CrowdStrike, which tracks these operators as FAMOUS CHOLLIMA, describes a live inference model mapping a stolen or synthetic face onto the operative’s real video feed in real time, routed through a virtual camera driver that Zoom or Teams treats as an ordinary webcam. Nothing about the call looks wrong to a hiring manager who isn’t specifically hunting for synthesis artifacts. Standard advice like “ask them to turn their camera on” stopped meaning anything a while ago, and I don’t think most corporate hiring teams have caught up to that yet.

Getting hired is only step one. Once the laptop ships, an IP-KVM device wired into it hands full remote control to the operative abroad while the machine looks, to the company’s network, like a normal US employee logging in from a normal US address. CrowdStrike’s own threat report puts FAMOUS CHOLLIMA at 47% of all state-sponsored hands-on-keyboard intrusions against US tech companies in the year ending in March, which makes North Korea the single largest state actor running this kind of direct-access infiltration, ahead of the states that usually dominate that conversation. The Treasury Department says $800 million flowed to Pyongyang’s weapons programs through this scheme in 2024 alone, on top of a separate crypto theft operation Chainalysis pegged at $2.02 billion in 2025.

What I keep circling back to is the liability question, because it’s unresolved and it’s going to land on some unlucky company’s desk soon. Companies that unknowingly hire these workers are currently treated as victims by DOJ and OFAC, not violators, but a Skadden analysis from June flags that both agencies have signaled firms with weak compliance programs could still face wire fraud, money laundering, or sanctions conspiracy exposure. That’s a real legal risk sitting on top of a hiring problem most HR departments don’t treat as a security function at all, and it rhymes with the posture Washington has taken toward chip exports for two years now, criminalizing the outcome without giving anyone a clean way to verify compliance in advance. I watched that exact gap play out on the chip smuggling side, where federal prosecutors kept making arrests without a specific export law to charge anyone under, and Malaysia’s own chip diversion problem followed the identical shape a year earlier.

Congress noticed, four days before the advisory. Representative Young Kim introduced the North Korean FAKER Act on July 27, which would push the State Department to coordinate detection with employment platforms, payment processors, and identity verification companies directly. One cosponsor so far, and it’s sitting in committee, which tells you where this stands: named, not solved. The bill reads like Congress trying to get ahead of an enforcement trap before the prosecutions pile up first, the same trap that left chip export cases stuck without a matching statute for years.

The part that unsettles me isn’t the fraud itself, states have run worker schemes for money since long before AI got involved. It’s that the interview, the one moment everyone assumed still required a real human face on a real human body, quietly stopped being reliable sometime in 2024, and it took eleven governments this long to say so together. I don’t know how many companies are already compromised and haven’t found out yet. The other time this year a government reached directly into how a frontier AI system gets to operate, it caught the company on the other end by surprise too. I’d bet on the same thing happening here, just with worse quarterly numbers before anyone notices.

Sources