South African companies are among those targeted by North Korean IT workers who use fake profiles to land remote jobs, researchers at a Canadian cybersecurity company told News24.
Chris d’Eon and Adrian Cheek of Flare, a firm based in Montreal, said the workers created accounts on South African job boards. They said at least one South African company hired one of the workers.
“Out of 515 logs that I’ve been looking at, I found access credentials to five South African job platforms. So these are North Korean workers who have actually created profiles on the job platforms,” Cheek told News24.
Cheek said he could not name the South African company that hired a worker. He said there were probably more cases.
The evidence comes from an investigation by Flare and IBM X-Force, the threat intelligence team at IBM. The two groups released a technical report in March this year.
The analysts obtained chat logs from the workers, Google Translate records and internet search histories. D’Eon said the search histories showed South African companies were also being looked at.
According to the researchers, the main goal is to earn salaries for as long as possible. The money is then sent back to North Korea, which is under heavy sanctions.
Cheek said many target companies hold no secret information at all. He said one was a mattress firm and another was a coffee plantation.
D’Eon said most workers use fake profiles with false names and photos on sites such as LinkedIn and GitHub. He said they send hundreds of job applications each day.
Some workers go further and recruit local helpers who apply for jobs using their real details. The helpers then hand the jobs over. D’Eon said these helpers are usually offered 25% to 30% of the contract value.
D’Eon said he had not seen records of helpers recruited directly from South Africa. However, an NBC report cited Kudelski Security as finding developers in Iran, Syria and South Africa who accepted offers from North Korean workers.
US cybersecurity company KnowBe4, which has an office in South Africa, said it hired a North Korean worker by mistake in 2024. The person was hired for a remote software engineering role.
“He used a stolen US identity, an AI-enhanced photo, and got through four rounds of video interviews and standard background/reference checks,” Anna Collard of KnowBe4 told News24.
The company’s security team caught the worker minutes after a company laptop was sent to him. They found malware being loaded onto the device.
Collard said she did not know of a direct South African case. But she said the chance was high because many local telcos, fintechs and startups hire remote workers.
“I reckon the chance is pretty high that this is happening, perhaps with many not being aware of it,” she said.
In July, ministries from the US, Japan, Canada, Australia, South Korea and the UK issued a joint statement on the scheme. They said the income helps pay for North Korea’s nuclear weapons and missile programmes.
A sanctions monitoring group of 11 UN members released a report on North Korean workers abroad on 16 September 2026. North Korea’s state media outlet KCNA said that report was fabricated, according to Reuters.
Cheek said many firms have not updated their hiring steps for online recruitment. “What they’re up against, essentially, is an HR application process from an organisation that hasn’t changed for 30 years,” he said.
Source: this article is based on reporting by news24.com. Image: news24.com. Written with the help of AI and published by the Tzaneen Voice Technology desk. See our Editorial Standards.
Werner Jacobs covers technology for Tzaneen Voice. Werner reports on mobile networks, data prices, internet access, smartphones, apps, AI, cybersecurity and South African tech companies. Each story explains what a new product, price change or policy means for ordinary users in South Africa.