# OpenAI Bans Accounts in North Korea-Linked Hiring Deception Scheme

> Source: <https://insideai.news/news/ai-safety/openai-bans-accounts-in-north-korea-linked-hiring-deception-scheme/6718/>
> Published: 2026-07-31 17:25:11+00:00

**July 31, 2026**, (Inside AI) — OpenAI has banned dozens of accounts linked to a deceptive employment scheme that used its AI models to fabricate identities, cheat interviews, and infiltrate Western companies. The operation mirrors tactics attributed to North Korean IT worker fraud, though OpenAI cannot confirm the actors' nationalities.

The banned accounts generated fake resumes, cover letters, and online profiles tailored to specific job listings. They also created reference personas to vouch for the fictitious applicants. In parallel, the operators recruited real people to host company laptops or lend their identities for background checks.

During interviews, the actors used OpenAI's models to produce plausible answers to technical and behavioral questions. After gaining employment, they relied on the same tools for coding, troubleshooting, and messaging colleagues. They also crafted cover stories to explain suspicious behavior like avoiding video calls or accessing systems from unauthorized regions.

The activity aligns with publicly reported North Korean state efforts to funnel income through deceptive hiring, a scheme Microsoft and Google have previously linked to Pyongyang. OpenAI shared its findings with industry peers and authorities to bolster collective defenses.

## How the scheme weaponized AI across the hiring lifecycle

The operation exploited AI at every recruitment stage. First, actors used VPNs and VoIP phones appearing U.S.-based to apply for remote tech roles. They generated resumes and LinkedIn profiles precisely matching job descriptions, maximizing their chances.

Second, they built support personas that provided fake references and referrals. Third, they recruited accomplices through social media to receive company laptops or lend identities for background checks. This layered deception made detection difficult.

During interviews, the actors fed questions into OpenAI's models to generate real-time responses. However, they did not use speech-to-speech tools, suggesting a text-based approach. Once hired, they used AI for daily tasks and to explain away red flags, such as working odd hours or refusing video calls.

OpenAI's investigation, originally published in February 2025, noted that the actors' content distribution was partly visible on LinkedIn. The company emphasized that its policies strictly prohibit using its tools for fraud or scams.

## A persistent threat with limited visibility

Assessing the full impact requires input from multiple stakeholders, OpenAI said, as it only observed a fraction of the activity. The scheme reflects a broader trend of nation-state actors exploiting AI to scale fraud. A 2024 Mandiant report detailed how North Korean IT workers use similar tactics to fund weapons programs.

Industry efforts to counter such threats are growing. Microsoft's Digital Crimes Unit and Google's Threat Analysis Group have published indicators of compromise. OpenAI's proactive bans and information sharing represent a new front in this battle, but the decentralized nature of remote hiring makes complete prevention challenging.

For companies, the case underscores the need for robust identity verification and behavioral monitoring. As AI tools become more sophisticated, distinguishing legitimate candidates from deepfakes will require layered defenses and cross-industry collaboration.
