Fake candidates 101Threat landscapePublished Mateusz Smoczyński

Who is behind fake candidates? The operator, the farm and the ChatGPT candidate

Three profiles account for most fake candidates in tech hiring: state-backed operators using stolen identities, laptop farms holding several jobs at once, and real people with AI-written CVs. What each wants and how each shows up.

Key takeaways
  • Most fake candidates in tech hiring fit one of three profiles: the operator (stolen identity, state-backed, wants access), the farm (real workers with borrowed documents, several jobs at once, wants salary) and the ChatGPT candidate (a real person with an AI-written CV, wants a job they are not qualified for).
  • The operator profile is not a rumour. It is a documented North Korean state programme with criminal cases, sentences and an estimated $250M to $600M a year in revenue. Since 2024 it has moved into Europe.
  • Each profile leaves different signals. Knowing who you are looking at makes the signals make sense.

“Who are these people?” is the question I get after every talk on fake candidates. It is a good question, because the answer changes how you read the signals. A VoIP number means something different on an AI-polished CV than on an application from a persona that does not exist.

This is the second post in our introductory series. The first explained what a fake candidate is. The third covers why the problem grew so fast and what to do from Monday.

Short version: three profiles.

Three profiles behind fake candidates: the operator, the farm, the ChatGPT candidate
The three profiles we use at Team Up when we discuss a flagged application. Most cases fit one of them.

1. The operator

Someone else’s identity. State-backed. Goal: access, and an insider from day one.

In 2022 the FBI, the US State Department and the Treasury issued a joint advisory about North Korean IT workers taking remote jobs at Western companies under false identities. It sounded exotic. By 2024 it had names. KnowBe4, a security awareness company, hired a software engineer who passed four video interviews and a background check. The laptop they shipped him started loading malware within minutes of being switched on. The engineer was a North Korean operator using a stolen American identity and an AI-modified stock photo.

Then came the criminal cases. In December 2024 the US Department of Justice charged 14 North Korean nationals with running a scheme that generated at least $88 million over six years through two front companies in China and Russia. The workers, called “IT warriors” internally, had monthly revenue targets of at least $10,000 each. When they got access to sensitive data, they used it for extortion. In 2025 the DOJ raided 29 laptop farms in 16 US states and, for the first time, charged the operators themselves rather than only their American helpers.

$250M to $600Mestimated yearly revenue of the North Korean IT worker programmeUN estimate, via Google Cloud, 2025
300+US companies infiltrated through one laptop farm in ArizonaUS DOJ, U.S. v. Chapman, 2025
12personas run by a single operator at the same time, in the US and EuropeGoogle Threat Intelligence Group, 2025

Why it matters for a recruiter in Europe: the operators moved. Google’s threat intelligence team reported in April 2025 that pressure from US law enforcement pushed the programme into the UK, Germany, Portugal and beyond, with fabricated European identities: diplomas from the University of Belgrade, addresses in Slovakia, claimed nationalities from Italy to Vietnam. One operator was actively applying to defence and government roles in Europe. Awareness here is lower than in the US. That is the point.

The operator’s toolkit, documented on camera by ANY.RUN in 2025 when researchers handed the Lazarus group a sandboxed “corporate laptop”: no malware. Remote desktop tools, an Astrill VPN, browser extensions that auto-fill job applications and generate interview answers in real time. Microsoft’s Jasper Sleet report adds AI face swaps on stolen ID documents, the same AI-generated portrait reused across personas, and voice-changing software on calls.

What the operator looks like in your pipeline: an inconsistent identity. The PDF is authored by a different name than the candidate. The LinkedIn profile is weeks old with a handful of connections. The diploma is from a university that does not fit the story. The phone number is VoIP. The file was last edited in a time zone eight hours from the claimed address. On the call: camera “not working”, a second person audible in the background, and a hard pause when you ask an unscripted question. The FBI’s own tip from the 2025 cases: ask them what they think of Kim Jong-un. Operators disconnect on the spot.

2. The farm

Real people. Someone else’s documents. Three to five full-time jobs at once. Goal: the salary.

The farm is the profile most people have never heard of, and it is the one that costs mid-sized companies the most money. The mechanics: a local facilitator (in the US, often an ordinary person renting out their identity and their spare room) receives company laptops for “employees” who were hired remotely. The facilitator plugs them in and installs remote-access software. The actual worker, somewhere else in the world, logs in and does the job. Or several jobs.

Christina Chapman ran one such farm from her home in Arizona. Over three years it served more than 300 US companies, including Fortune 500 firms, and generated $17 million. She was sentenced to over eight years in 2025. In the ANY.RUN investigation, the recruiter side of the scheme offered developers 35% of the salary to act as the face while “ghost developers” did the work.

The farm does not need a stolen identity every time. Sometimes it is a real person with real skills who is simply working three jobs and delivering a third of the output at each. The cost is not a breach. It is a salary paid for a person who is only partly there, plus the projects that quietly slip.

What the farm looks like in your pipeline: the same application, several times. Three candidates for one role sharing a phone number block. Identical skills sections under different names. Two full-time roles overlapping for months on the CV. A PDF author name that repeats across applicants. On the call: the candidate is great, and the person who shows up on the second call is not quite the same person.

One CV is nothing. Three CVs from the same pool are a farm.

Team Up, analysis of 33 flagged applications, 2026

3. The ChatGPT candidate

A real person. A CV written by AI. Reads answers off a second screen. The most common profile by a wide margin.

This one is not a criminal. It is someone who wants the job, does not have the skills, and now has tools that let them look like they do. The CV matches the job ad keyword by keyword, because it was generated from the job ad. Achievements come with suspiciously precise numbers (“improved performance by 37.4%”). Every previous employer is a top brand. On the call, there is a four to six second pause before each answer while the answer is being generated. The eyes drift down and to the side. The answers are textbook: “we implemented microservices” instead of a story with people and mistakes in it. Ask a follow-up that is not in the script (“can you repeat the question?”) and you buy them time to generate the next answer.

In Greenhouse’s 2025 AI in Hiring survey of 4,136 hiring professionals, 91% said they had caught or suspected candidate fraud. Most of that is this profile, not North Korea.

The ChatGPT candidate is a hiring quality problem, not a security problem. But they crowd out honest candidates with messy, real CVs, they waste interview time at scale, and the same AI tooling is what the operator and the farm use. You cannot filter for one without learning to see the others.

What the ChatGPT candidate looks like in your pipeline: too good a match. Keyword stuffing, sometimes literally hidden as white text in the PDF so the ATS filter sees it and you do not. Pseudo-precise metrics. Generic, personality-free descriptions. Fine contact data, real LinkedIn, real person. The signals are in the document and in the interview, not in the identity.

Why the profiles matter

Because the response is different for each.

For the ChatGPT candidate, you adjust the interview: ask how, not what; ask for a story with a mistake in it; ask about a local detail that is not in the CV. For the farm, you look across applications, not within one: shared phone blocks, cloned skills, the same PDF author. For the operator, you verify identity before the offer, hard: document check, two phone references, and you treat camera-off on the second call as a stop sign.

At Team Up we run all three checks on every application, which is what candidate fraud detection means in practice, and TalentShield automates the parts that can be automated: document integrity, timeline consistency, identity and contact data, and cross-application patterns. Each signal comes with what we found, why it matters and how to verify it yourself. The tool never says which profile it thinks it is looking at. That is a human’s call, and it is a much easier call once you know the three faces on the other side.

Next in the series: why this is happening now, and a plan you can start on Monday without budget. And if you would rather see what the checks find on your own pipeline, book a demo.

See it in your ATSTalentShield runs candidate fraud detection inside Greenhouse, Teamtailor, Lever and any ATS with an API. Book a demo or talk to Mateusz.

Questions people ask

Are fake candidates really linked to North Korea?

A significant share of the most damaging cases are. The US Department of Justice, the FBI, Google's threat intelligence team and Microsoft have documented a state-run programme in which North Korean IT workers use stolen or borrowed identities to get remote jobs at Western companies. The UN estimates the programme earns North Korea between $250 million and $600 million a year. Since 2024 the operators have expanded into Europe.

What is a laptop farm?

A laptop farm is a home or office, usually in the country where the job is, where a local facilitator keeps company laptops sent to hired 'employees'. The facilitator switches them on, installs remote-access software and lets the real worker, often abroad, log in as if they were local. The Arizona farm in U.S. v. Chapman served more than 300 companies and generated $17 million.

What is a ChatGPT candidate?

A real person who used generative AI to write a CV that matches the job ad keyword by keyword, and who relies on AI or a helper during the interview. The tell is a four to six second pause before every answer, eyes drifting to a second screen, and generic answers with no personal detail. It is the most common profile we see.

Does this affect companies in Europe?

Yes. Google's threat intelligence team reported in 2025 that operators pushed out of the US by DOJ actions moved to the UK, Germany, Portugal and other European markets, using fabricated European identities, including diplomas from Belgrade and addresses in Slovakia. Awareness in Europe is lower than in the US, which is exactly why they moved.

Sources

  1. FBI IC3 public service announcements on North Korean IT workers (2024, 2025)
  2. US DOJ, U.S. v. Chapman (2025): Arizona laptop farm, 300+ companies, $17M
  3. US DOJ, December 2024: 14 North Koreans charged in $88M identity theft and extortion case
  4. Google Cloud / GTIG, April 2025: DPRK IT workers expanding in scope and scale
  5. Google Cloud, March 2025: The ultimate insider threat, North Korean IT workers
  6. Microsoft Threat Intelligence, June 2025: Jasper Sleet, North Korean remote IT workers' evolving tactics
  7. ANY.RUN, December 2025: How we caught Lazarus's IT workers scheme live on camera
  8. KnowBe4, July 2024: How a North Korean fake IT worker tried to infiltrate us
  9. Greenhouse, 2025 AI in Hiring Report (n=4,136)

Keep reading

Fake candidates 10127 September 2026

What is a fake candidate? A plain-language guide for recruiters

Fake candidates are not one thing. From AI-polished CVs to stolen identities run by state operators: what the term covers, how big the problem is, and why one signal never settles it.

Read →
Fake candidates 10127 September 2026

Why fake candidates are rising now, and what to do about it from Monday

Remote hiring, generative AI and industrial-scale fraud explain why fake candidates went from rare to routine. Here is the logic behind it and a three-step plan that costs nothing to start.

Read →

See it on your own pipeline.

Leave your email and the ATS you use. We come back within one business day to book a 30-minute demo, on your own applicants if you want. Just have questions? Talk to Mateusz, 30 minutes, no slides.

Book a demo