Excerpted from a Whiteford Law Blog by Lisa Brauner

Deepfakes have shifted from novelty to real risk for employers. Some identity fraud research indicates that overall deepfake and synthetic identity fraud attempts targeting organizations have surged globally. According to a report by GetReal Security, 41% of IT, cybersecurity, risk and fraud leaders say their company has hired and onboarded a fraudulent candidate.

Recent reports detail this growing trend of remote interviewees using synthetic video and voice to pass identity checks, while security researchers and training providers have documented cases of imposters attempting to infiltrate U.S. companies as “IT workers.” The FBI has warned of a rise in deepfake-enabled fraud in remote hiring, and high-profile incidents show how convincingly AI can simulate live presence, senior executives and credentialed professionals.

In addition to a public service announcement on December 19, 2025, warning about the rise in AI deepfake impersonation, on July 31, 2026, the U.S. State Department and FBI, together with multiple countries’ foreign affairs and other government offices, issued a joint alert to countries, U.S. businesses and other entities, notifying them that the North Korean government has deployed IT services workers to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.

According to the joint alert, “these workers seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft and theft of sensitive information.” North Korea is a sanctioned jurisdiction, of course, meaning that U.S. companies are prohibited from employing workers from North Korea.

Case in point: The cybersecurity awareness training company KnowBe4 — which trains companies on how to avoid getting hacked — hired a deep-fake job applicant as a software engineer. The fake job applicant used the stolen identity of a U.S. citizen when applying for the job, enhanced by AI, and had four video interviews while using AI-deepfake technology.

The fake job applicant was a North Korean government operative. Once hired, he requested to have his laptop shipped to an address that was, in fact, an “IT mule laptop farm.” He then used a VPN from North Korea or China and unsuccessfully attempted to hack into KnowBe4’s computer systems to plant malware, before his actions were discovered by KnowBe4.

What Should Employers Do Now?

Here are just a few practical suggestions to help mitigate the risk of deepfakes and when to call legal counsel.

For the full story, please click here.