On 31 July, agencies from eleven countries including the UK, US, Japan and Australia issued a joint advisory with an unusually blunt message: North Korean operatives are systematically posing as remote IT contractors to win real work from real companies, using fake identities, AI-generated CVs, location-masking tools and third-party proxies to pass hiring checks. The income gets funnelled back to fund North Korea’s weapons programmes. For UK businesses that hire freelance developers, designers or IT support through platforms like Upwork, Fiverr or LinkedIn — which is most SMEs at some point — this isn’t a distant geopolitical story. It’s a live vetting problem.

The scheme isn’t new, but the scale and sophistication flagged in this joint alert is. Operatives are reportedly using AI tools to generate convincing portfolios, sit technical interviews with real-time coaching, and maintain multiple simultaneous contracts across different companies under different fake identities. Beyond the fraud itself, the advisory warns of a second, sharper risk: these are also insider-threat positions. Someone with genuine access to your codebase, customer data or admin credentials, working under a false identity, is a data exfiltration and extortion risk — not just a compliance headache.

Why small businesses are the easier target

Large enterprises typically run background checks, identity verification and sometimes in-person or video onboarding for contractors. Many SMEs, understandably pressed for time and budget, skip straight from a promising freelance profile to a signed contract and repo access. That gap is exactly what this scheme exploits — it doesn’t need to beat sophisticated defences, only the absence of any at all. If your business has hired remote developers in the last year without verifying a passport, running a video call, or checking that payment details match the name on the contract, it’s worth a second look at who actually has access to what.

What to actually check before the next hire

The advisory’s practical guidance boils down to a handful of checks any SME can run without hiring a security consultant. Insist on a live video interview — not just messaging — and watch for inconsistencies between the person on camera and their stated location or timezone activity patterns. Verify identity documents properly rather than accepting a scanned photo at face value. Be wary of requests to route payment to a different name or account than the contracted individual, or to use a company-provided laptop shipped to an address unrelated to the stated location. And scope access tightly from day one: a new contractor doesn’t need full repo or admin access before they’ve delivered anything. Smallprint has ready-to-use contractor agreement templates that build identity verification and access-scoping clauses in from the start, rather than trying to bolt them on after a problem surfaces.

If you’re already worried about an existing contract

If this advisory makes you want to check a contractor you’ve already onboarded, don’t panic-terminate before you’ve looked properly — that can tip off a bad actor and destroy evidence you’d need for a report. Instead, quietly review access logs, payment routing, and communication patterns first. KeepSafe continuously monitors for exposed credentials and unusual access activity, which is exactly the kind of early signal that separates a genuinely dodgy contractor from an over-cautious false alarm.

Don’t let this become an excuse to avoid remote talent

It’s worth being clear about what this advisory doesn’t say: it isn’t a reason to stop hiring remote contractors, or to treat every freelance developer as a suspect. The vast majority of remote IT talent, in the UK and internationally, is exactly who they say they are, and remote hiring remains one of the most effective ways for a small business to access skills it couldn’t otherwise afford locally. The advisory is a call for proportionate, basic verification — not a case for retreating to expensive local-only hiring that most SMEs can’t sustain anyway.

The takeaway

Remote hiring platforms have made it trivially easy to bring in skilled help from anywhere — which is also exactly what this scheme relies on. A five-minute video call and a proper identity check before granting access costs you almost nothing. Skipping it, on the evidence of this advisory, is now a documented and actively exploited risk rather than a theoretical one.