A recruiter had developed a test he ran on candidates he suspected weren’t who they claimed to be. He would ask them, politely, to say out loud that Kim Jong-Un is a fat, ugly pig. Presumably, the real applicants laughed and said it. The North Koreans could not, and the pause that followed told him everything he needed to know.
That such a test exists at all is the strange part. Over the last several years, a wave of seemingly perfect job applicants has flooded American companies, and a meaningful number of them have turned out to be undercover North Korean operatives, dispatched by the regime to use stolen identities and fabricated resumes to land remote software jobs. Once hired, they funnel their paychecks back to Pyongyang, an estimated $800 million a year by recent counts, money that U.S. officials say helps fund the country’s nuclear and missile programs. This is one of the most audacious stories I have come across in a while, and the mechanics of how it works make it hard to look away.
An Industrialized Operation
The thing that surprised me most is that this isn’t a handful of hackers freelancing. It is a factory. For the last year, the Wall Street Journal investigated one small team of these workers from the inside, having obtained a trove of hacked data from their own computers, including browser histories, emails, stolen identities, and screen recordings from their meetings. What the reporters found reads less like a spy novel and more like a staffing agency with a very dark mission statement.
A team leader operating under the codename EagleVision coordinated a group of men posing as tech workers, using a rotating set of fake and stolen names and a private Discord server to assemble resumes and cover letters for each alias. They prepared for interviews using shared Google Docs, and, in a detail that has stuck with me, they even looked up how to pronounce the fake names they were using correctly. The roles were divided the way any company divides labor. Someone specializes in interviews and does fifteen a day. Someone writes the resumes. Someone does the actual coding. In just over three months, this one small team applied to more than a thousand companies. A single week of the leader’s calendar showed 22 job interviews using at least seven different identities, and the team landed at least nine jobs across the U.S. and U.K.
Cheating the Interview in Real Time
Here is where it gets almost comical, if it weren’t so effective. The workers recorded themselves during interviews, probably for training, which means we can watch exactly how they faked technical fluency. Before an interview, an operative would tee up ChatGPT and ask it for help with questions about the software engineering role. Then, when the interviewer asked something like whether he had experience with a particular cloud tool, the worker would copy the question out of a live transcription tool, paste it into ChatGPT, and read the generated answer back word for word. The response comes out polished and confident, and the interviewer, hearing a fluent answer delivered at a natural pace, moves on to the next question. The operative never actually knew the answer; he just read it convincingly enough that no one thought to ask.
The Americans Who Made It Possible
None of this works without help inside the United States, because no company is going to ship a laptop to Pyongyang, as that would set off every alarm a security team has. Shipped to almost anywhere in the U.S., though, it raises no concerns. So the operation recruits Americans to receive the laptops, plug them in, and let the North Koreans log in remotely, a setup investigators call a laptop farm. The biggest one uncovered so far held around a hundred machines in a single home.
One of these facilitators was a man named Derrik Goon, who ran laptops out of his house in rural Ohio. He had dropped out of high school, beaten a heroin addiction, and struggled to find steady work when a contact on Telegram introduced him to a man claiming to be from Brazil. The pitch was simple. Derrik would show up for interviews, sometimes under his own name, land the job, receive the laptop, and sit in meetings while the team behind him did the coding. They split the salary; his cut on one job was 50%. And after he got paid, he in turn sent the rest back to the organizers via cryptocurrency. For a year and a half, it felt like the easiest money he had ever made. Then he discovered that the Brazilian was not Brazilian, that his identity had been used without his permission, and that a tax form was reporting nearly $100,000 in income he had never seen.
Where the Money Goes, and Who Gets Hurt
Some of these workers earn upward of $300,000 a year, and the Treasury Department estimates that in some cases up to 90 percent of it is taken by the regime. The workers themselves are closer to victims than villains. Many were pulled into cyber training as children, are kept working eighteen- and twenty-hour days across multiple jobs, and cannot leave because their families back home would answer for it if they tried. The money makes its way back through a maze of foreign bank accounts, couriers, and crypto transactions designed to shake off anyone trying to follow it.
And then there are the Americans whose names were stolen to make the whole thing run. One of them, a man named Michael Brown in Georgia, learned that his identity had been used to work at nine different companies across eleven states, complete with fraudulent 401(k) accounts opened in his name. He has been effectively blacklisted, unable to open a bank account or rent a place to live, and now has to answer a thousand questions to try to get his identity back. It’s a troubling reminder that when identity theft happens, especially when it goes for so long without being known, the road back is a tough one.
Trust, but Verify
Companies are catching on, and the interviews have started to get interesting. Once a hiring manager gets suspicious, the questions turn away from cloud architecture and toward things ChatGPT cannot answer for someone pretending to sit in an American city. Where are you based? What’s the weather like right now? Is it cold? You can hear the panic set in on the recordings, the operative stalling, then guessing, or answering entirely too slowly after searching for the weather. The catch, though, is that the technology keeps improving. Operatives have begun using AI face-swapping tools to disguise their appearance on camera, and investigators expect that within a year the workers may vanish from video entirely. Some have even started acting as pure middlemen, winning a contract and subcontracting the actual work to a developer elsewhere for a fraction of the pay.
Perhaps the most sobering note comes from the people who study this for a living. Right now it is mostly a revenue scheme, but these workers hold usernames, passwords, and keys to the networks of companies, governments, and defense contractors. What keeps one cybersecurity expert up at night is that they are everywhere, and at a moment’s notice, if the order came, they could try to inflict maximum damage by tearing it all down from the inside. For now, though, the coworker who was never really there just wants the paycheck, and the recruiter on the other side is using the strongest cybersecurity tool ever created; can you say “Kim Jong-Un is a fat, ugly pig”?
***Source: The Wall Street Journal documentary and investigation, “The North Korean Operatives Hiding Inside U.S. Companies.” ***
Markets / Economy
- Markets are back at all-time highs, seemingly shrugging off any negative news with ease. The S&P finished the week up 0.4%, the Nasdaq up 0.1%, and the small-cap Russell 2000 up 1.1%.
- Core CPI in the U.S., which excludes food and energy, rose by 0.2% MoM in July, accelerating from the hold in the previous month, but in line with market expectations.
- Total CPI in the U.S. edged up 0.1% MoM in July as expected, accelerating from a 0.4% decline in June, which had marked the first monthly drop since May 2020 as oil prices fell dramatically.
- US retail sales fell 0.6% month-on-month in July, sharply missing expectations for a 0.1% rise and reversing June’s 0.2% gain. It was the first decline since October 2025 and the biggest since May last year.
Stocks
- U.S. equities were in positive territory. Energy and Utilities were the top performers, while Consumer Discretionary and Materials lagged. Value stocks led growth stocks, and small caps beat large caps.
- International equities closed higher for the week. Emerging markets fared better than developed markets.
Bonds
- The 10-year Treasury bond yield increased three basis points to 4.68% during the week.
- Global bond markets were in negative territory this week.
- High-yield bonds led for the week, followed by government bonds and corporate bonds.

