NewsMacroEndorsed finds half of remote IT job applications show North Korean fraud patterns

Endorsed finds half of remote IT job applications show North Korean fraud patterns

Author: Fortune Crypto·

Key Takeaways

  • Endorsed says it has analyzed more than 11 million job applications for fraud and reviewed 175,000 flagged applications from U.S. companies in 2026.
  • In U.S.-based remote IT roles, applications with patterns linked to North Korean schemes increased from 11% in Q3 2024 to 44% a year later, with Endorsed estimating 47% in the most recent quarter.
  • Texas was the most commonly claimed state among flagged applications, while Dallas, Austin and Houston were the most frequently cited hometowns.
  • The fake applicants most often claimed attendance at the University of North Texas and UT Austin, and frequently listed employers such as Amazon, Google and Meta.
  • Endorsed says its screening relies on multiple signals including devices, networks, documents and behavior, with human review required for decisions.
Endorsed finds half of remote IT job applications show North Korean fraud patterns

David Head is CEO of Endorsed, a San Francisco identity verification startup that uses AI to screen candidates. The company says that work includes spotting signs of imposters and fraudsters, including a torrent of North Korean operatives posing as IT workers who have slipped into hundreds of U.S. companies over the past several years.

Endorsed, which Head co-founded with CTO Kevin Fu, has analyzed more than 11 million job applications for fraud and is backed by Joe Montana’s Liquid 2 Ventures, Pioneer Fund, and angels including Micah Smurthwaite, Head said. The company examined a sample of 175,000 job applications across all role types in 2026 from U.S. companies with between three and more than 25,000 employees, where the applications were flagged as showing mid- to high-risk patterns associated with North Korean IT worker schemes. If you aren’t aware, men from the Democratic People’s Republic of Korea have been forced to pose as workers seeking IT jobs so they can funnel their earnings into authoritarian ruler Kim Jong Un’s nuclear weapons program, according to the UN.

Among U.S.-based remote IT roles, where Head says the fraud is most concentrated, applications carrying those patterns rose from 11% of the total in the third quarter of 2024 to 44% a year later. Endorsed estimates that the rate was 47% in the most recent quarter.

Endorsed, which surfaces risk signals for human review, found that North Koreans likely favor claiming to hail from Texas, which accounted for 26.5% of all flagged applications. California and Florida were also common, accounting for 14.4% and 7.2%, respectively. Among cities, Dallas, Austin, and Houston were the most frequently claimed hometowns.

The company’s research also found that the most common purported alma maters were the University of North Texas and UT Austin, followed by the University of Central Missouri and UT Dallas. For previous employers, the fake applicants were most likely to claim experience at Amazon, Google, and Meta, while Capital One, CVS Health, Microsoft, and Stripe were also popular choices. Among first names, the most common were Sai, Michael, David, and Kevin. More than half of the flagged applications included a LinkedIn profile.

Head said the choices are deliberately ordinary.

“If all of this sounds banal, that’s the point. The scammers pick familiar names, cities, employers and schools because it offers additional camouflage based on real job applicants,” he said.

“One or even several of these traits should never make an applicant seem suspicious on their own,” Head noted. “The risk comes from a broader pattern of inconsistencies and behavior, not someone’s name or background.”

Thousands of North Korean workers have taken jobs at Fortune 500 companies undetected until they are caught, and American accomplices are often part of the conspiracies. A New Jersey facilitator was sentenced to nine years in prison in April for spearheading a ring that placed operatives inside more than 100 U.S. companies. For employers, the challenge is that the fraud can look conventional at first glance, which is why Endorsed says it relies on multiple signals rather than biographical details alone.

Despite the wave of North Korean fraud, venture capitalists are getting pickier and investing in fewer companies. Cybersecurity venture funding was flat at $8.5 billion in the first half of 2026, while deal count fell 23.8%, according to PitchBook’s Q2 2026 cybersecurity report. The second quarter’s $3.8 billion across 165 transactions was the weakest since the end of 2024. Security operations led by deal count with 47 transactions worth $1 billion, accounting for more than a quarter of all VC-backed cybersecurity funding.

Endorsed says it sits at the intersection of recruitment tech and cybersecurity, a category Head calls “an emergent category.” Among identity and access management, funding fell from $0.8 billion in Q1 to $0.3 billion in Q2. PitchBook attributed much of the pullback to concern that some AI-native security startups may lose appeal to frontier models like Anthropic’s Mythos. Even so, PitchBook remains bullish on IAM, noting that nonhuman identities “outnumber humans roughly 45 to 1 in typical enterprises.”

Endorsed says its model goes beyond biographical details and looks at devices and networks, along with document and behavior signals, with a human required to sign off on decisions.

Head even noticed that his own co-founder and CTO, Kevin Fu, matched several of the fraud patterns. Fu grew up in a Dallas suburb, attended the University of Texas at Austin, and spent most of his career at LinkedIn, which is owned by Microsoft.

Those details line up with data Head’s company provided exclusively to Fortune about people pretending to be American software engineers. Head volunteered the coincidence when he sent over the figures.

“We’ve scanned him with Endorsed though,” Head joked, “and I can verify that he is legitimate.”

Amanda Gerut
amanda.gerut@fortune.com

This story was originally featured on Fortune.com