We found North Korean engineers in our application pile
cinder.co
cinder.co
In both cases, the fraud was easily made plain when I asked details about their work history. In one case, they claimed to live in the same metro area I had previously lived for 18 years, but couldn’t answer any basic questions about the place. In another situation, they claimed a workplace that was in a community I was familiar with and that was far too small to have corporate headquarters of any type I wouldn’t be familiar with.
After 5-10 minutes of probing, both candidates bailed on the interview realizing they were wasting their time.
They also exhibited some of the other signs as described at the link - no employment profiles on LinkedIn or just a basic profile, names that didn’t match their ethnicity, etc.
I have no evidence or intuition to conclude they were North Korean, as employment fraud is certainly not limited to North Korea. I can’t imagine either of the candidates I spoke to surviving even casual scrutiny, so I highly doubt this kind of fraud results in much success.
The people I've known from China and Korea have a tendency to adopt traditional English names (Steve, Joe, Mike, etc) because their native names are hard to pronounce for English speakers.
Further, the 2nd generation Asian Americans I've met do often have traditional English names.
But someone of obvious Asian descent and accent who introduces themselves as “Simon Cartwright” and has vague tales of growing up in London… again, it’s possible, and we should treat each individual with respect and assumption of good intent, but that might make me dig a little deeper.
But it might be worth paying extra attention to any clues that they might not have lived in that place and have a falsified history.
As he said, "we should treat each individual with respect and assumption of good intent." But a decent proportion of people showing this particular characteristic will be engaging in employment fraud, and we shouldn't be blind to that signal.
There are people with issues like dyslexia and people who don't fit the education system and perform poorly.
I've met non-native speakers who have far better spelling, grammar and an enlarged vocabulary than people who have lived in my English-speaking country for their whole lives.
From https://www.eeoc.gov/prohibited-employment-policiespractices:
> An employer may not base hiring decisions on stereotypes and assumptions about a person's race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability or genetic information.
You are the only person trying to turn this into a racial issue.
One of the first things we ask from both employees and freelancers is a copy of their passport/ID. Would they also have a fake ID with the name they give you (much easier to fake a PDF than a real passport) or just a story, passing you through a legit company? Or is it common to hire people without really knowing who they are?
But someone named Sam Smith who supposedly grew up in an English speaking country, but barely speaks English is something that might trigger you to look further.
I agree wholeheartedly that you can’t/shouldn’t be suspicious just because someone has an “English” name and looks East Asian, but that together with the other signs is just a bit much.
So maybe you could suggest a better answer instead of asking boring questions.
I’d guess that there’s a chance that they specifically targeted this company
There's even a chance this never actually happened as presented.
> Christina Marie CHAPMAN, a U.S. national, conspired with certain overseas IT workers to affect a scheme to defraud the United States and its agencies. Specifically, CHAPMAN: (i) assisted the overseas IT workers in validating stolen identity information of U.S. citizens so the overseas IT workers could pose as U.S. citizens; (ii) received and hosted laptops issued by U.S. companies to the overseas IT workers in her U.S. residences (a “laptop farm”), so that the companies believed the workers to be located in the United States.
I think if the US govt makes such cases public, puts a few news stories out in popular media, indicating the harsh sentences and such, it might make US citizens think twice about helping NK hackers set up their base here.
Actually suspected? There's nothing in the article that shows they were from North Korea.
> Actually suspected
I actually suspected my grand kid ate my icecream. The icecream was in the fridge, grandkids use the fridge. The icecream was not in the fridge, grandkids take things out of the fridge. The icecream was likely eaten. Grandkids eat icecream. I actually suspect the grandkids ate the icecream. (Turns out grandma ate it with her friends on top of some apple pie.)
(English is weird language. :D )
> Turns out grandma ate it with her friends on top of some apple pie.
"That's now how I expected to see grandma go, but hopefully she was doing what she loved."
A few years ago I was getting scammer calls at the same time every day. I started answering as "Fraud desk, Agent Scully". They would hang up instantly and the calls soon stopped altogether.
Sadly, the examples in the article are as good as, or better, than letters I've received from US-based devs.
My money's on "both".
If you’ve got to churn out as many job applications as possible just to get an interview with a real company, you’ll go insane if you try to make them all thoughtful, beautiful, and crafted to the specific job posting. Worse: you’ll churn out fewer applications. The job application with a cover letter like weak tea is infinitely better than the job application that you never submit because you’re paralyzed by the need to write something perfect. I had a standard template that I modified slightly for each application, but I kept the time customizing it very low: swapping out a list of skills to highlight, etc.
That being said: after talking to my boss recently, apparently my cover letter helped when I was applying to this job (I’m enthusiastic about this area, so I put in some extra time and let my water nerd show). I think what I said is still probably valid for most junior developer positions, but your mileage may vary.
That might very well be the case for a big company that receives a ton of applications but the numbers game works both ways: as the person looking to hire somebody, I find it well worth the time to weed out people based on poor spelling, grammar, etc. It only takes a few seconds to spot the bad ones, and it ensures I don't have to waste my time with somebody who has poor communication skills to begin with.
You're potentially getting into dicy employment law waters with questions like these.
Dealing with both aspects is the joy of cross-cultural communication :)
I'm assuming everybody who's been a witness (or god forbid a party) to a protected-class employment lawsuit had their eyebrows shoot up all the way off their head at the premise of this article, which is "rooting out secret North Koreans from an incoming flow of candidates, in part using forensic interview questions".
I see how ex-CIA guys would expect to get a profile on everyone and know what color toothbrush they use.
I am lucky that I can refer to media publications citing my name in a professional context. But it's a creepy world where the employers' expectation is that all your personal information is public.
The article makes it sound like these guys are none too bright and not especially well trained. Are companies just that desperate?
My company is pretty small, so we caught it within an hour of getting him onboarded. But I can see this being trickier in bigger companies, where the hiring process is more disconnected from the team they get assigned to.
So fascinating as well having a person that was paid to do the interview. I guess there is a secret web site where people are waiting to do this as a service?
It seems unlikely that someone living in the US would take the test for someone else, since the risk is just too high. I'm pretty sure this is just straight up fraud you can get in trouble for. My bet is that this was a scam setup outside of the country, and they used a stolen identity to get the paperwork cleared.
When you apply for jobs nonstop and can multiply your efforts by applying under a multitude of different names and resumes, eventually you get bites. Push long enough and you might catch a desperate hiring manager who doesn't know how to interview people but is under pressure to fill headcount immediately to hit their KPIs or whatever.
They play it like a numbers game. They also get better by constantly A/B testing their process and practicing interviews over and over again.
Yes. Not too long ago I saw so-so engineer get hired and his manager was desperate enough to overlook some troubling knowledge gaps and the guy's inability to actually do what he was told.
IANAL, but this sounds 100% illegal to me. From https://www.eeoc.gov/prohibited-employment-policiespractices:
> An employer may not base hiring decisions on stereotypes and assumptions about a person's race, color, religion, sex (including gender identity, sexual orientation, and pregnancy), national origin, age (40 or older), disability or genetic information.
If the based their decisions on the 2nd half of that, it could be fine.
Many times the signs are rather obvious, the keywords are right but everything about the profile is just off and doesn't stand to even a bit of scrutiny. I suspect it's done on purpose, just like Nigerian scams, to optimize for gullible or inattentive companies.
Sauce?
Second, you did not find any confirmed North Koreans at all! Come on, now. How trustworthy are you with such a clickbait title?
I wonder how they would screen for new graduates, which might not have much professional work history?
Communication skills are at least as importing as programming skills, and I’ve never worked at a place where someone like this would have passed an FTE interview.
Unless you're working on some national security s/w, or finding that backdoors are being installed in your source, why not let North Korean engineers work?
> What tipped us off
> 5. Background noise during their interview that indicated other people speaking in an interview-like setting
The rest maybe false flags, but this really seals the deal. (or... maybe it's just a recent day in Starbucks. But I don't take the risk)Also, how dare those people apply jobs for an US based cybersecurity firm? Don't they know what cybersecurity firms do? Go apply a Web3 companies, they also uses Vue/React all front-end kids stuff and some of them still got deep pockets.
Not because I somehow vehemently disagree, but because I think this just lazy writing, and confusing general trends with a boogie man, just because the boogie man follows the general trends.
BLUF: Yes, North Korean (and other nation state, organized crime group) spies apply to jobs to gain access. None of your indicators of value even cumulatively. Do better.
> No online presence outside of professional networking websites
I do not, and there is whole group of young people do not have an (reasonably traceable) online presence. I have better things to do in my off time than prattle about my bowel movement online for some validation of my existence.
> Completely fabricated job history including office locations that don’t actually exist.
I will give the author this. This is a red flag pointing to someone who is unethical, not that they are NorKs.
> Unable to find these applicants online outside of the standard ...
This is the same as the first one.
> Inability to answer basic questions about the cities in which they allegedly worked
Eh.. I do not remember what I ate for breakfast. That that make me a NorK? I used to commute in a big city for a year. No idea what stop I would have gotten off, or even what line it was that I used. Such things become almost autonomous and forgotten as extraneous information.
> Background noise during their interview that indicated other people speaking in an interview-like setting
Possibly. Or, they work in a coding shop that has the "genius" of open cubicles for some collaboration. This is a red flag pointing to someone who is unethical, not that they are NorKs.
> Highly scripted answers with explicit preference for remote work, and little ability to deviate from the script.
Oh? Are you saying that the interview questions are not scripted questions?
> A mismatch between the name displayed on the resume or networking site, and the candidate’s command of English (e.g. Chris Smith...
I think if the name is "mismatch" this might be a thread to pull. How is the jump to NorK here? Why not Iranian or Russian?
Additionally, have you worked in some STEM research lab lately? Recently I was talking to some and I could not understand a single sentence. Not one. I had to ask them to write it down and I used my bad hearing as an excuse. Some of the lab workers' names would pass for North American. This was in an English speaking country.
Those cover letters are exactly what the recruiting industry is asking the plebeians to generate.
> Taken together, to me these details suggested fake identities.
Indeed it would make me discount the individual to some extent. Jumping to North Korean spy is a wee bit of a leap, at least for me.
> “100% Remote job only without travel”
Or, in general majority of job seekers no longer want to come to the office.
https://www.engage2excel.com/resource/1-2024-job-seeker-surv... (68% would leave job if forced to come in)
https://www.roberthalf.com/us/en/insights/research/remote-wo...
> I started informing candidates...
Why was the travel requirement not included in the initial job postings?
As a Chinese, OMFG & ROFL.
Of course, the fact that these people are being dumb enough to apply to a firm composed of former spies and that sells to the US intelligence community is what makes this particular case hilarious.
> They are often required to leave family members behind as collateral to prevent them from defecting while outside their home country.
In all seriousness though. Defectors from North Korea have been killed longer than you or I have been alive
But surely insignificant to the hundreds of millions in China, India, Indonesia etc.
Why DPRK when the alternatives are so much more numerous?
The entire population of DPRK is only 26mil, the entire country is half the size of the city Jakarta.
Most Americans probably outright lie on their CV, that tells you nothing.
If I had to guess, likely because the NK workers are highly motivated to succeed under threats of duress and threats involving their families/own life.
I dont think these employers are willingly hiring DPRK workers over other countries, likely more so that DPRK are more ruthless and aggressive with their application applying processes and have it dialed in pretty well using shared intel and techniques to improve their success rates. Afterall, it is a nation-state backed campaign so they have a lot of resources to put into it.
https://m.youtube.com/shorts/A8L4QjIHL4k
using 100s of millions of people out of their several Billion population.
How to differentiate between them and the few thousand DPRK emigrants do the same?
They're lying so they can get into your company and give their government access to your systems when convenient in the future.
The paycheck is barely scratching the surface of why they want to get into your company.
Because damn this article is being really overt with the racism which is pretty surprising since it's attached to a company blog. The implication that no one in the entire country of NK could be qualified for anything but the bare minimum for a junior is pretty insulting. I worked in a research lab with Chinese spies— really nice smart folks. I really can't imagine NK being so different as to not have any qualified people.
I'm sure there are plenty of North Koreans who are qualified (whether they are or aren't working for state intelligence), just as plenty of people working for Chinese intelligence are smart and qualified and decent people, like you mention, but we don't live in an era of utopian world peace where such things can just be overlooked when giving people access to sensitive systems, and we may not even in ten thousand years from now. We shouldn't expect Chinese tech companies to accept applicants working for CIA or NSA, either.